Trending Topics

LLM privacy policies take almost 20 minutes to read, Bridewell finds
Privacy policies for the 20 most popular large language models (LLMs) take almost 20 minutes to read on average, with technical and legal language making them difficult for users to understand, according to an analysis by cybersecurity firm Bridewell.
The analysis, which used Claude, found the policies averaged 4,603 words and had an average Flesch reading ease score of 40.2, a level considered difficult to read and more suited to university graduates. Meanwhile, a score over 60 is considered more accessible to the general public.
The analysis found Meta’s Muse Spark had the longest privacy policy in the analysis, with more than 14,000 words. Bridewell estimates it would take the average reader almost an hour to read the policy in full.
Moonshot AI’s Kimi K came up as the second most difficult policy to read, the study found. Although, its 6,229-word policy was less than half the length of Muse Spark’s, it had the lowest Flesch reading ease score in the study of 28.1, indicating that the text is complex and difficult to read.
The analysis also looked at the UK’s most popular LLM, ChatGPT. Bridewell said it had a shorter policy than the other LLMs analysed, but users would still need about 17 minutes to read its 4,143 words, and had a Flesch reading ease score of 43.6.
Privacy and security risks
Bridewell data privacy associate director Chris Linnell said the readability of privacy policies was particularly important as people increasingly use LLMs to handle sensitive information.
“As LLMs become an increasingly large part of day-to-day life for many, it’s essential for users to fully understand how these tools use their data, and what they can do to protect their privacy,” he said.
Bridewell’s analysis also found that 13 of the 20 LLMs studied use user inputs and outputs to train their models. The level of control available to users varies between services, with some providing an option to opt out of training.
“When there is unclear understanding of how data is processed, particularly in professional settings, employees may be at risk of sharing highly sensitive or confidential information that may end up being used to train LLMs.”
Personal usage, enterprise-level issues
The issue is compounded when employees use personal accounts for work purposes, according to Linnell. He warned that using personal accounts for company work could create data protection risks if client or company information is submitted to an LLM without a lawful basis.
“While some tools give users the option to opt out, the burden is on users to select this option,” he said. “These policies assume people have read and understood them, which many haven’t, especially when using personal accounts.”
Linnell said enterprise agreements could provide organisations with greater control over how employee data is handled by AI tools.
“Enterprise AI agreements typically address this by explicitly barring tools from using inputs and outputs to train their models and giving organisations oversight of what information is being shared with LLMs,” he said.
