ZDNET、13 AI プラットフォームのプライバシーリスクを調査し順位付け
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
ZDNET AI
Incogni が実施した13のAIプラットフォームに関するプライバシーリスク調査により、大手プラットフォームが最もデータを収集する傾向にあることが明らかになり、利用者は各サービスのデータ取り扱い方針を事前に確認する必要がある。
AI深層分析を開く2026年8月20日 21:27
AI深層分析
キーポイント
大手AIプラットフォームのプライバシーリスク
Incogni の新研究によると、規模の大きいAIプラットフォームは一般的に最もプライバシー侵害的な傾向にあることが示された。
例外となるプラットフォームの存在
全体的な傾向の中で、唯一例外となるプライバシー保護に優れたプラットフォームが1つ存在することが指摘されている。
利用前の情報確認の重要性
アカウント登録を行う前に、各AIオプションがデータをどのように処理するかを理解することが推奨される。
Incogniの2026年プライバシーランキング調査
データブロカー除去サービスであるIncogniが、ChatGPTを含む13のAIプラットフォームをプライバシーリスクに基づいて評価した。スコアは低いほど優れており、各ポイントがプライバシー侵害的な慣行やデータの扱いやすさを反映している。
調査で問われた3つの主要なプライバシー課題
ユーザーデータの処理方法(トレーニングへの利用や第三者共有)、プラットフォームの透明性(ポリシーの分かりやすさ)、および収集・共有される個人データの実態が問われた。
重要な引用
Incogni's new study of 13 AI platforms ranks them by privacy risk.
The largest AI platforms turn out to be the most privacy-invasive - with one exception.
The lower the score, the better, as each point added reflects the discovery of privacy-invasive practices, how easy data-sharing practices are to find and understand, and what happens to user data.
Some of the largest AI platforms appear to pose the greatest risk to user privacy, except for OpenAI's ChatGPT.
編集コメントを表示
編集コメント
この調査は、AIの利便性とプライバシーリスクのバランスを問う重要な示唆を与えている。大手プロバイダーが必ずしもユーザーデータ保護に優れているわけではないという事実は、利用者にとって極めて重要な判断材料となる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

*ZDNET をフォロー:* Google の優先ソースとして ZDNET.com を追加 してください。
ZDNET が注目するポイント
- Incogni が実施した 13 の AI プラットフォームに関する新調査では、プライバシーリスクの観点からランキングが付けられました。
- 規模の大きな AI プラットフォームは、ある例外を除き、最もプライバシーを侵害しやすい傾向にあることが判明しました。
- アカウント登録前に知っておくべき各サービスの概要はこちらです。
ChatGPT、Claude、Gemini といった生成 AI プラットフォームの利用は、私たちの生活や働き方を大きく変え続けています。しかし、その利便性を得ることで生じるプライバシーリスクは、許容できる範囲を超えているのでしょうか?
AI エンジンは、スマートフォンと同様に、多くの人の人生に壊滅的な影響を与えています。企業は AI 関連の開発に数十億ドルを投じており、「AI ファースト」のイメージを打ち出したいと願う組織がほとんどです。また、日々の情報検索や問い合わせにおいても、従来の検索手法に代わり、AI による引用が増加しています。
あわせて読む: ChatGPT、Gemini、Copilot、Claude との会話を非公開にする方法
私たちは現実世界での意思決定をする前に AI にアドバイスを求め、中には私生活や資産運用に関する助言を AI に求める人もいます。
(注記:ZDNET の親会社である Ziff Davis は、2025 年 4 月に OpenAI を提訴しました。同社は AI システムのトレーニングおよび運用において著作権を侵害したと主張しています。)
では、私たちが AI に提供しているデータは本当に安全なのでしょうか?また、現在の AI プラットフォームを開発する企業は、ユーザーのプライバシー保護を自らの責任として捉えているのでしょうか。これらの疑問を抱いたことがある方にとって、Incogni が発表した最新の調査結果が光を当てます。
Incogni「Gen AI および LLM のデータプライバシーランキング 2026」レポート
木曜日に発表された本レポートでは、データブローカー除去サービスを手掛ける Incogni が、13 の AI プラットフォームと、それらが消費者のプライバシーに与える潜在的なリスクを分析しています。
関連記事:AI によるサイバー攻撃が未来を支配する:企業の 43% がすでに被害に遭っている
「2026 年版生成 AI と LLM のデータプライバシーランキング」レポートでは、ChatGPT、Claude、Gemini、Grok、Vibe(旧 Le Chat)、Perplexity、Qwen、DeepSeek、Z.ai、Kimi、Meta AI、Pi、Copilot の各 AI プラットフォームが対象となりました。調査会社 Incogni によると、各 AI には「プライバシーリスクの度合い」に基づいてスコアが付けられています。スコアが低いほど評価が高く、加点されるごとに、ユーザーデータを侵害する行為が発見されたこと、データ共有の仕組みがどこまで分かりやすいか、そしてユーザーデータがどう扱われるかが明らかになっています。
この調査では、以下の 3 つのカテゴリーについて問いかけられています。
- ユーザーデータはどうなるのか? ユーザーの会話内容が学習プラットフォームに利用されるのか、オプトアウト(拒否)は可能なのか、プロンプトは第三者や他のシステムと共有されるのか?
- AI プラットフォームは透明性があるか? データおよびプライバシーポリシーは、見つけやすく理解しやすいものになっているか?
- プラットフォーム上のデータはどうなるのか? どのような個人データが収集され、その出所はどこなのか、また共有される場合はどこへ送られるのか?
プラットフォームが大きくなるほどリスクも高まる——ただし例外あり
一般的に、規模の大きな AI プラットフォームはユーザープライバシーにとって最大のリスクとなる傾向がありますが、OpenAI の ChatGPT はその例外です。Gemini と Meta AI は最も高いリスクスコアを獲得した一方、Vibe、ChatGPT、Pi は Incogni の評価において、最も低い(つまり最も安全な)リスクスコアを記録しました。
*Incogni*
以下に、各 AI モデルの総合的なパフォーマンスを、リスクが低い順から高い順にランキング形式でまとめます。
- Mistral AI の Vibe(旧 Le Chat): プライバシーポリシーがわかりやすく、モバイルアプリもプライバシーに配慮しています。収集する情報は公開ソースからのものに限られ、ユーザーとの会話内容は「最小限」の第三者としか共有されません。
- OpenAI の ChatGPT: 明確でシンプルなプライバシーポリシー、FAQ、リソースが用意されています。モデル学習用のデータ収集を拒否する手続きも簡単で、セキュリティやマーケティング目的でデータが収集・共有される可能性があることも明記されています。
- Inflection AI の Pi: プライバシーポリシーは複雑で、EU 在住ユーザーについては GDPR 対応として別扱いとなっています。企業・商業・研究パートナーとデータを共有する可能性がありますが、アプリ自体はプライバシーに配慮した設計です。
- Perplexity AI: 読みやすいが詳細には欠けるプライバシーポリシーを採用しています。モデル学習からの拒否手続きは見つけやすく有効化できますが、ユーザーデータは企業グループ内や関連会社と共有される可能性があります。
Alibaba の Qwen
プライバシーポリシーは、個人データを分析プロバイダーや検索エンジンプロバイダー、その他のサードパーティサービスと共有するなどのデータ使用目的を説明していますが、具体的にどのユーザー情報が誰と共有されるのかは明確ではありません。Incogni によると、ユーザーの会話記録がトレーニングに利用されているかどうかを判断することも困難です。これは「モデルの改善および他の目的」のためにユーザー入力が保存されるという記述があるだけで、それ以上の詳細がないためです。
DeepSeek
DeepSeek はオープンウェイトモデルを通じて、ユーザーデータをローカルネットワーク内に保持することを可能にしています。ただし研究者らは、ホスト版のモデルではプライバシーへの懸念が「より深刻になる」と指摘しています。DeepSeek では、不正確な個人情報が見つかった場合や、その訂正・削除を希望する場合は問い合わせが可能です。また、AI モデルのトレーニング方法についても詳細な情報を提供しています。
Z.ai
Z.ai もオープンウェイトモデルを提供していますが、ホスト版では同様にプライバシー上の懸念が生じます。Z.ai のプライバシーポリシーは妥当なものですが、詳細に欠け、AI モデルのトレーニングに関する記述には曖昧さが残っています。
- Google の Gemini: Google は既存のサービスから膨大なデータを収集しており、Gemini も同様に「部分的な」プライバシーポリシーを採用しています。これは基本方針が一般ポリシーに依存しているため、「具体的な質問への回答を得ることが難しい」という課題があります。
- Anthropic の Claude: Anthropic は包括的なプライバシーポリシーとデータ関連のリソースを備えており、原則としてユーザーデータを AI 学習に使用しないとしています。ただし最新のポリシー(2026 年 7 月版)では、ユーザーがオプトアウトする必要があると示唆されています。同組織は、匿名化・集約されたユーザーデータを用いた研究発表を行う可能性があります。
- xAI の Grok: 企業グループの構成員や関連団体にはユーザーデータが提供される可能性があり、モデルは Grok データだけでなく、公開されている X(旧 Twitter)上の会話も学習対象としています。
- Moonshot AI の Kimi: プライバシー保護サービス「Incogni」によると、中国系企業傘下の Kimi は評価されたプラットフォームの中でユーザーデータ取り扱いにおいて最も大きなプライバシーリスクを有すると指摘されています。また、同アプリはユーザー追跡にデータを利用しており、AI モデル学習へのオプトアウトも困難です。
Meta: 調査対象の中で最も「データ欲求が激しい」とされるモデルですが、同社が「トレーニングはプライベートな会話のみで行われ、グループチャットでは行わない」と主張しているものの、プライバシーポリシーの範囲が広すぎるため、その実態を完全に検証するのは困難です。
Microsoft の Copilot: このアプリは第三者広告主とデータを共有しており、プライバシーポリシーも必要以上に広範であるため、透明性に問題があります。また、Incogni によると、個人データはデータブローカーから購入されているとのことです。
どの AI がデータプライバシーに最も優れているか?
Incogni の結果やランキングは、Vibe、ChatGPT、Meta、Copilot のいずれが自動的にあなたにとって最良または最悪の選択肢であるかを意味するものではありません。例えば、一度大規模言語モデルのトレーニングに使用されたデータをユーザーが取り戻せるプラットフォームはなく、過去のデータ利用に対する撤回や同意の取り消しを遡って行うことも不可能です。
したがって、これらのプライバシー重視スコアは、各 AI モデルがどこで優れているか、またどこを改善する必要があるかの指標として捉えるべきです。セキュリティとプライバシーに関する新たな懸念事項は週ごとに次々と現れています。Claude のチャットが誤って Google によってインデックス化された事例も、最近起きた数多くのインシデントの一つに過ぎません。今日市場にあるどの AI モデルであっても、あなたのプライバシーが完全に保証されるわけではありません。
また、Google の AI は Workspace でデフォルト設定でビジネスデータにアクセス可能 - 手動で無効化しない限り。
大規模言語モデル(LLM)を利用する際は、データの収集・処理方針が透明なサービスを選ぶことが重要です。また、共有する情報にも細心の注意を払う必要があります。例えば、財務諸表を AI の学習に利用されることに抵抗があるなら、決して提出しないことです。この考え方は、これからのすべての会話に応用してください。
「LLM に入力した情報はすべて、第三者のサービスに提供されたものとして扱うべきです」と、情報セキュリティ管理会社の Incogni の情報セキュリティマネージャーであるミゲル・フォルネス氏は ZDNET に語っています。「パスワードや金融情報の詳細、機密性の高い業務データ、医療記録、個人を特定できる情報を共有するのは避けましょう。可能な限り名前や他の識別子を削除してください。より機密性の高いタスクを行う場合は、モバイルアプリよりも Web ブラウザ版の利用を検討し、プロバイダーのプライバシーポリシーに注意を払い、必要に応じてデータを端末内に保持できるローカル実行型のモデルを使用することも検討してください。」
原文を表示

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET's key takeaways
- Incogni's new study of 13 AI platforms ranks them by privacy risk.
- The largest AI platforms turn out to be the most privacy-invasive - with one exception.
- Here's what to know about each option before signing up for an account.
The use of generative AI platforms such as ChatGPT, Claude, and Gemini continues to change how we live and work. But do the privacy risks outweigh the convenience?
AI engines have had a cataclysmic impact on many of our lives, comparable to that of smartphones. Businesses are pouring billions of dollars into AI-related developments; it seems like almost every organization wants to project an "AI-first" image, and even in our daily queries and quests for information, AI citations are replacing the older methods we used to search.
Also: How to keep your conversations with ChatGPT, Gemini, Copilot, or Claude private
We're asking AI for advice before making real-world decisions, and some of us are even seeking out recommendations on our personal lives and finances.
*(Disclosure: Ziff Davis, ZDNET's parent company, filed an April 2025 lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.)*
But how safe is the data we feed into our AI companions, and do the organizations developing today's AI platforms consider user privacy to be their responsibility? If you've ever asked these questions, new research from Incogni sheds some light on them.
Incogni's Gen AI and LLM Data Privacy Ranking 2026 report
Published on Thursday, data broker removal service Incogni's new research analyzes 13 AI platforms and the potential risks they pose to consumer privacy.
Also: AI cybersecurity attacks are the future: 43% of companies have already experienced it
The "Gen AI and LLM Data Privacy Ranking 2026" report looks at these AI platforms: ChatGPT, Claude, Gemini, Grok, Vibe (formerly Le Chat), Perplexity, Qwen, DeepSeek, Z.ai, Kimi, Meta AI, Pi, and Copilot. In the study, each AI has been assigned a score "based on the privacy risks they pose," Incogni says. The lower the score, the better, as each point added reflects the discovery of privacy-invasive practices, how easy data-sharing practices are to find and understand, and what happens to user data.
Three groups of questions are addressed by the study:
- What happens to user data? Are user conversations fed into training platforms, can users opt out, and are prompts shared with third parties or other systems?
- Are AI platforms transparent? Are data and privacy policies easy to find and understand?
- What happens to data on AI platforms? What personal data is gathered, where does it come from, and if it is shared, where does it go?
The larger the platform, the bigger the risk - with one exception
Some of the largest AI platforms appear to pose the greatest risk to user privacy, except for OpenAI's ChatGPT. Gemini and Meta AI received some of the highest risk scores, whereas Vibe, ChatGPT, and Pi achieved some of the best (and lowest) risk scores in Incogni's assessment.
*Incogni*
In summary, this is how each AI model performed overall, ranked from lowest to highest risk:
- Mistral AI's Vibe (fka, Le Chat): Easy-to-understand privacy policies, privacy-friendly mobile apps, information collected from public sources, and user conversations are only shared with a "minimal" number of third parties.
- OpenAI's ChatGPT: A clear, simple privacy policy, FAQs, and resources; opting out of data collection for model training is straightforward, and it is clearly stated that data is collected and may be shared for security or marketing purposes.
- Inflection AI's Pi: A complex privacy policy that handles EU users separately (for GDPR purposes), potentially shares user data with corporate, commercial, and research partners, but has a privacy-friendly app.
- Perplexity AI: An easy-to-follow but not very detailed privacy policy; opting out of model training is easy to find and enable, but Perplexity user data may be shared with corporate group members and affiliates.
- Alibaba's Qwen: Privacy policies describe what data is used and for what purposes, such as sharing personal data with analytics providers, search engine providers, and other third-party services, but it is less clear exactly what user information is shared and with whom. Incogni says it is also difficult to determine whether user conversations are used for training, as this isn't covered beyond a statement that user inputs are stored for "model improvement and other purposes."
- DeepSeek: DeepSeek allows user data to stay on local networks via open-weight models, but the researchers say privacy considerations become "more serious" on hosted versions of its models. DeepSeek allows users to reach out if they find inaccurate personal information and want it corrected or removed. DeepSeek provides detailed information on how its AI models are trained.
- Z.ai: Z.ai also offers open-weight models, but again, hosted versions have privacy implications. Z'ai's privacy policy is reasonable but not very detailed, and there is ambiguity surrounding AI model training.
- Google's Gemini: Google can already collect vast amounts of data from its other services, and Gemini has what the team calls a "partial" privacy policy that defaults to its general policy. As a result, "getting answers to specific questions can be a real challenge."
- Anthropic's Claude: Anthropic has an extensive privacy policy and data-related resources, and claims not to use user data for AI training by default, although its latest policy (July 2026) suggests users now have to opt out. The organization may publish research using aggregated, de-identified user data.
- xAI's Grok: Corporate group members and affiliated parties can receive user data, and its model is trained not only on Grok data but also on public X conversations.
- Moonshot AI's Kimi: Incogni said Chinese-owned Kimi "represented the greatest privacy risk among the platforms assessed" with regard to user data handling, and its app uses data to track users, according to the report. It's also difficult to opt out of AI model training.
- Meta: Considered the most "data-hungry" model in the sample, Meta's claims that training only takes place in "private conversations but not group chats" are difficult to verify due to a broad privacy policy.
- Microsoft's Copilot: The app shares data with third-party advertisers and has an overly broad privacy policy, creating transparency issues. Incogni also says that data is purchased from data brokers.
Which AI is the best for data privacy?
Incogni's results and rankings do not mean that Vibe, ChatGPT, Meta, or Copilot are automatically the best or worst options for you. For example, no platform allows users to retrieve their data once it has been used to train a large language model, and no retroactive removal or withdrawal of consent is possible.
Instead, you should look at these privacy-weighted scores as indicators of what some AI models are doing well, and what others need to improve. New security and privacy concerns are emerging week by week -- the accidental indexing of Claude chats being only one of many recent incidents -- and your privacy is not guaranteed with any AI model on the market today.
Also: Google's AI can see your business data by default in Workspace - unless you disable it
When you use any large language model, it's best to choose one with transparent data collection and handling policies, and be careful about what information you share with it. If the idea of your financial statements being used to train an AI isn't palatable, for example, then don't submit them -- and apply this concept to all of your future conversations.
"Treat anything you enter into an LLM as information you are giving to a third-party service," Incogni's information security manager Miguel Fornés told ZDNET. "Avoid sharing passwords, financial details, confidential work information, medical records, or other identifying information, and remove names or other identifiers where possible. For more sensitive tasks, consider using the web version rather than a mobile app, pay attention to the provider's privacy practices, and, where appropriate, use a locally run model that can keep data on-device."
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み