Just 2% of businesses report training an AI system on customer information, according to a 2025-2026 survey of 800 Canadian companies by the Office of the Privacy Commissioner of Canada, published in March 2026. That low number sits next to a much bigger one: 16% of businesses now use AI somewhere in their operations, nearly triple the 6% recorded in 2023, and separate research shows a far wider circle of companies feeding personal data into AI tools without ever formally training a model on it.

The distance between "AI touches personal data" and "AI is trained on personal data" is where most of the disclosure risk sits, and it is the question this page answers with numbers from five separate 2025 and 2026 studies.

Only 2 percent of businesses train AI models on customer data 2% of businesses train AIon customer data

How many businesses train AI on personal data?

Very few, by the most direct measurement available. The Office of the Privacy Commissioner of Canada surveyed 800 consumer-facing Canadian businesses by telephone between January 19 and February 25, 2026, and found that only 2% use customer information to train an AI system. The survey, conducted by Phoenix Strategic Perspectives and accurate to within 3.5 percentage points at a 95% confidence level, asked businesses directly rather than inferring the figure from a broader AI-adoption question.

That 2% figure looks small next to what consumers believe is happening. 81% of U.S. adults suspect companies are already using their personal data for undisclosed AI training, according to a December 2025 nationally representative survey of 1,017 consumers by Relyance AI and TrueDot.ai. The same survey found 82% see losing control of their data to AI as a serious personal threat, and 84% said they would abandon or restrict a company entirely over AI data opacity, with 57% saying they would stop using the service outright.

What consumers believe vs what businesses report (2025-2026) Consumers who suspect undisclosed AI training81%Businesses that say they train AI on customer data2%

Figure 1: Consumers assume AI training on their data is common; few businesses say it is. Sources: Relyance AI and TrueDot.ai Consumer AI Trust Survey (December 2025); Office of the Privacy Commissioner of Canada, 2025-2026 business survey (March 2026).

The gap between an 81% suspicion rate and a 2% admission rate is not proof that businesses are hiding widespread AI training. It is a sign that most companies have not said anything at all, and silence reads as guilt to a consumer base already primed to expect the worst.

How is training AI different from just using AI near personal data?

Training a model on customer data is one narrow step inside a much wider pipeline, and most of the personal-data exposure happens earlier in that pipeline, not at the training stage. A business can use AI, feed it personal data as input, and never touch model training at all, which is exactly what the numbers below show happening at scale.

Cisco's 2025 Data Privacy Benchmark Study, based on 2,600 privacy and security professionals surveyed across 12 countries in late 2024, found that 46% admit to inputting employee data or other non-public information into GenAI tools despite well-documented concerns about privacy and confidentiality inside their own organizations. DataGrail's 2026 Privacy and AI Trends Report, which tracked AI activity across 2,400 business software systems, found that 32.8% of those AI systems participate in at least one high-risk activity, meaning they process sensitive personal information or power an automated decision about a person.

Figure 2: Most AI use touches personal data somewhere in the pipeline; very few businesses go all the way to training a model on it. Sources: Office of the Privacy Commissioner of Canada (2026); Cisco 2025 Data Privacy Benchmark Study; DataGrail 2026 Privacy and AI Trends Report.

Any business whose AI tools touch customer records now has a disclosure question to answer, whether or not a model ever gets trained on that data. The most direct place to answer it is the privacy policy itself: a privacy policy generator built to cover AI-related processing can add that disclosure without a full rewrite of an existing policy.

How fast is business AI adoption growing?

Business AI adoption in Canada nearly tripled in three years. The Office of the Privacy Commissioner of Canada's survey found 16% of businesses using AI for operations in the 2025-2026 wave, up from 6% in a 2023 wave using the same methodology.

AI use among Canadian businesses nearly tripled since 2023 6% 16% 2023 2026 share of Canadian businessesusing AI, OPC Canada survey
Share of Canadian businesses using AI for operations 05101520%2023202616%

Figure 3: Business AI adoption in Canada nearly tripled in three years. Source: Office of the Privacy Commissioner of Canada, 2025-2026 business survey.

Canada's 16% figure is narrower than global enterprise numbers because the OPC survey covers consumer-facing small and mid-sized businesses specifically, not every large multinational. For the wider governance and breach picture behind AI adoption at bigger organizations, see our AI and privacy statistics for 2026, which covers Cisco's global 90% figure for privacy-program expansion and the governance gaps that come with it.

How do the different AI-and-personal-data studies compare?

Every study below measures a different population and a different question, and reading the numbers side by side shows exactly where the funnel narrows from broad AI use down to training on customer data.

MetricPopulation measuredShareSource
Businesses training AI on customer dataCanadian consumer-facing businesses (n=800)2%OPC Canada, 2026
Businesses using AI for any operationCanadian consumer-facing businesses (n=800)16%OPC Canada, 2026
Privacy and security pros who fed employee data into GenAI toolsIT, security, and privacy professionals (n=2,600)46%Cisco 2025 Data Privacy Benchmark Study
AI systems handling sensitive data or automated decisionsBusiness software systems tracked (n=2,400)32.8%DataGrail 2026 Privacy and AI Trends Report

None of these figures contradict each other. They describe different points on the same pipeline: general AI use, personal data entering AI tools, AI systems classified as high-risk, and the narrow final step of training a model directly on customer records.

What do businesses use AI for most?

Document work leads by a wide margin. Among Canadian businesses that use AI, 45% use it for research and document drafting, 24% for marketing, 18% for text or data analysis, and 15% for customer service or chatbot functions, per the OPC Canada 2025-2026 survey. Businesses could select more than one use case, so the shares do not add up to 100%.

What AI-using Canadian businesses use it for (2026) Research and document drafting45%Marketing24%Text or data analysis18%Customer service or chatbots15%

Figure 4: Businesses can select more than one use, so shares do not sum to 100%. Source: Office of the Privacy Commissioner of Canada, 2025-2026 business survey.

Customer service and chatbot use, at 15%, is the use case most likely to put personal data directly in front of a model in real time, since it typically means the AI tool is reading live customer messages, account details, or order history to generate a response. That is a smaller share than document drafting, but it is the use case with the most direct line to a customer's personal data.

How much personal data shows up inside AI conversations?

Personal data is the most common type of sensitive information that ends up inside an AI conversation, by a wide margin. LayerX Security's State of AI Usage Report 2026 found personal data present in 5.81% of all monitored AI conversations, versus 0.96% for financial data and 0.94% for IT and security data.

Sensitive data types found inside monitored AI conversations (2026) 92.29%5.81%0.96%0.94%No sensitive data detected92.29%Personal data (PII)5.81%Financial data0.96%IT and security data0.94%

Figure 5: When sensitive data does appear in an AI conversation, it is personal data roughly six times more often than financial or IT data. Source: LayerX Security, State of AI Usage Report 2026.

The vast majority of AI conversations, 92.29% by LayerX's count, do not contain any of these three sensitive data types at all. The exposure that does happen concentrates heavily on personal data rather than financial records or technical credentials, which tracks with the OPC Canada finding that customer service and chatbot use, the AI application most likely to see live personal data, is already a top-four business use case.

How has AI-and-personal-data risk changed since 2023?

Adoption, admissions, and consumer suspicion have all climbed together over the same three-year window, even though each study measures a different slice of the problem.

Figure 6: Adoption, admissions, and consumer suspicion have all risen together since 2023. Sources: Office of the Privacy Commissioner of Canada; Cisco 2025 Data Privacy Benchmark Study; Relyance AI and TrueDot.ai; DataGrail 2026 Privacy and AI Trends Report; LayerX Security State of AI Usage Report 2026.

None of these studies point to a slowdown. Adoption is growing, the share of professionals admitting to inputting personal data into AI tools is already close to half, and consumer suspicion is running well ahead of what businesses currently disclose.

The Bottom Line

Only 2% of businesses say they train AI directly on customer data, but that narrow figure describes the last and rarest step in a pipeline that already touches personal data far more broadly: 46% of privacy professionals admit feeding employee data into GenAI tools, close to a third of tracked AI systems handle sensitive data or automate a decision, and personal data turns up in nearly 6% of monitored AI conversations. Consumers already assume the worst, with 81% suspecting undisclosed AI training on their data, so the practical gap for most businesses is not training compliance, it is disclosure. Our AI and privacy statistics for 2026 covers the governance side of that same gap in more detail. A privacy policy that names how AI tools use personal data, even when no model is being trained, closes most of the distance between what a business does and what a consumer assumes it is doing. Formal governance is catching up unevenly: 68% of large US employers now report a written AI policy, yet just 8.5% of privacy policies actually disclose whether AI trains on customer data, so the gap sits on both the employee and the customer side of the same business.

Frequently Asked Questions

How many businesses train AI on customer data? Just 2% of businesses report training an AI system on customer information, according to the Office of the Privacy Commissioner of Canada's 2025-2026 survey of 800 Canadian companies, published in March 2026.

What percentage of companies use AI at all? 16% of Canadian businesses now use AI for some part of their operations, up from 6% in 2023, per the same OPC Canada survey. Stanford HAI's 2026 AI Index puts global enterprise AI adoption far higher, at 88%, reflecting a broader international sample of larger organizations rather than a contradiction of the Canadian figure.

How much personal data ends up inside AI tools? Personal data appears in 5.81% of all AI conversations tracked inside monitored enterprises, more than five times the rate of financial or IT-security data, according to LayerX Security's State of AI Usage Report 2026. Separately, 32.8% of AI systems tracked across 2,400 business platforms process sensitive personal information or power an automated decision, per DataGrail's 2026 Privacy and AI Trends Report.

Do consumers believe companies use their data to train AI? Yes. 81% of U.S. consumers suspect companies are already using their personal data for undisclosed AI training, according to a December 2025 survey of 1,017 adults by Relyance AI and TrueDot.ai, even though only 2% of businesses say they actually do it.

Where the Numbers Come From

  1. Office of the Privacy Commissioner of Canada. (2026). "2025-2026 Survey of Canadian Businesses on Privacy-Related Issues." Telephone survey of 800 businesses conducted by Phoenix Strategic Perspectives, January 19 to February 25, 2026. 2% train AI on customer data, 16% use AI for operations, up from 6% in 2023.
  2. Cisco. (2025). "2025 Data Privacy Benchmark Study." Survey of 2,600 privacy and security professionals across 12 countries, fielded fall 2024, published April 2, 2025. 46% admit inputting employee or non-public data into GenAI tools.
  3. DataGrail. (2026). "Privacy and AI Trends Report 2026." AI tracking across 2,400 business software systems plus a 5,000-site consent audit, published May 27, 2026. 32.8% of AI systems handle sensitive data or automate a decision.
  4. LayerX Security. (2026). "State of AI Usage Report 2026." Personal data present in 5.81% of monitored AI conversations, versus 0.96% financial and 0.94% IT and security data. LayerX does not publish a conversation-count sample size alongside this figure.
  5. Relyance AI and TrueDot.ai. (2025). "Consumer AI Trust Survey." Nationally representative survey of 1,017 U.S. consumers aged 18 and over, fielded December 2025, margin of error plus or minus 3.2 percentage points at a 95% confidence level. 81% suspect undisclosed AI training on their data.
  6. Stanford HAI. (2026). "The 2026 AI Index Report." 88% global enterprise AI adoption in at least one business function, cited here for scope comparison against the Canada-specific figures above.

Note: All figures verified as of August 2026. The OPC Canada, Cisco, DataGrail, LayerX, and Relyance AI figures each cover different survey populations and time windows, as noted throughout this page. This page is reviewed and its figures refreshed at least twice a year.