• Nosotros
  • Publicidad
  • Trabaja con nosotros
  • Contactos
domingo, agosto 23, 2026
  • Login
No Result
View All Result
NEWSLETTER
Despertar Matinal
  • Titulares del Día
    • All
    • En Portada
    Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

    Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

    Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

    Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

    Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

    Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

    “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

    “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

    Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

    Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

    Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

    Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

    Banreservas avanza 15 posiciones en el ranking de los 1,000 bancos más importantes del mundo

    Banreservas respaldará con financiamiento a inversionistas de dos nuevos proyectos residenciales en Punta Bergantín

    J.P. Morgan expresa intención de expandir inversiones en República Dominicana luego de encuentro con Valdez Albizu

    J.P. Morgan expresa intención de expandir inversiones en República Dominicana luego de encuentro con Valdez Albizu

    Suprema ratifica condena de 20 años a Argenis Contreras por crimen contra Yuniol Ramírez

    Suprema ratifica condena de 20 años a Argenis Contreras por crimen contra Yuniol Ramírez

    Trending Tags

    • Mundo
      • All
      • América Latina
      • Conflictos Internacionales
      • Estados Unidos
      • Europa
      • Geopolítica
      • Haití
      • Medio Oriente
      Franco Colapinto no ocultó su bronca por las sanciones recibidas en el GP de Países Bajos: "Les hace falta criterio"

      Franco Colapinto no ocultó su bronca por las sanciones recibidas en el GP de Países Bajos: «Les hace falta criterio»

      El etíope Yomif Kejelcha ganó la Media Maratón de Buenos Aires y marcó un nuevo récord mundial

      El etíope Yomif Kejelcha ganó la Media Maratón de Buenos Aires y marcó un nuevo récord mundial

      Florida implementó la enseñanza obligatoria de la “Historia del Comunismo” en las escuelas

      Florida implementó la enseñanza obligatoria de la “Historia del Comunismo” en las escuelas

      Un robot humanoide chino destrozó el récord mundial de Usain Bolt en los 100 metros

      Un robot humanoide chino destrozó el récord mundial de Usain Bolt en los 100 metros

      Javier Milei defendió el rumbo económico y anticipó la batalla electoral de 2027: “Voy a ir por la reelección”

      Javier Milei defendió el rumbo económico y anticipó la batalla electoral de 2027: “Voy a ir por la reelección”

      Descubren la estrella más rápida de la Vía Láctea: viaja a 25.000 kilómetros por segundo

      Descubren la estrella más rápida de la Vía Láctea: viaja a 25.000 kilómetros por segundo

      Los idiotas útiles no sobreviven a su utilidad

      Los idiotas útiles no sobreviven a su utilidad

      Por qué es momento de comprar oro y plata

      Por qué es momento de comprar oro y plata

      La candidata respaldada por China tomó la delantera en la carrera por la ONU

      La candidata respaldada por China tomó la delantera en la carrera por la ONU

      Trending Tags

      • Nacionales
        • All
        • Bávaro Punta Cana
        • Educación
        • Gobierno
        • Infraestructura
        • Justicia
        • Obras Públicas
        • Opinión
        • Provincias
        • Seguridad Ciudadana
        • semana santa 2026
        • Sociedad
        • Transporte
        Especialista revela la diabetes aumenta a un 17% y afecta alrededor de dos millones de dominicanos

        Especialista revela la diabetes aumenta a un 17% y afecta alrededor de dos millones de dominicanos

        Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

        Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

        Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

        Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

        Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

        Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

        “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

        “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

        Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

        Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

        CMD exalta a Jorge Asjana David como Maestro de la Medicina...

        CMD exalta a Jorge Asjana David como Maestro de la Medicina…

        Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

        Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

        Conani escucha planteamientos de varias instituciones sobre el proceso de reforma de la Ley 136-03

        Conani escucha planteamientos de varias instituciones sobre el proceso de reforma de la Ley 136-03

        Trending Tags

        • Política
          • All
          • Congreso
          • Opinión Política
          • Partidos Políticos
          • Poder Municipal
          • Transparencia y Corrupción
          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

          Advierte año escolar iniciará con problemas de fondo ante un...

          Advierte año escolar iniciará con problemas de fondo ante un…

          Entérese quienes se integraron al proyecto presidencial de...

          Entérese quienes se integraron al proyecto presidencial de…

          FP pide interpelar al ministro de Educación Luis Miguel De Camps por dificultades previo al inicio del año escolar

          FP pide interpelar al ministro de Educación Luis Miguel De Camps por dificultades previo al inicio del año escolar

          Colombia Alcántara será moderadora del XIX congreso...

          Colombia Alcántara será moderadora del XIX congreso…

          Milton Morrison reafirma alianza con Abinader y anuncia nueva...

          Milton Morrison reafirma alianza con Abinader y anuncia nueva…

          Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

          Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

          Trending Tags

          • Deportes
            • All
            • Atletas Dominicanos
            • Béisbol
            DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

            Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

            30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

            Buffalo recibe a Montreal para abrir la segunda ronda

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

            Trending Tags

            • Economía
              • All
              • Combustibles
              • Energía
              • Indicadores Económicos
              • Sector Energético
              • Turismo
              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

              Aventúrate RD 2026

              Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

              El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

              El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

              Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

              Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

              Trending Tags

              • Ciencia
                • All
                • Energía
                • Innovación
                • Investigación Científica
                • Salud y Medicina
                • Tecnología Médica
                Thousands struggling without power in Gary, Indiana 12 days after severe storms

                Thousands struggling without power in Gary, Indiana 12 days after severe storms

                France links rise in drownings to prolonged heatwaves

                France links rise in drownings to prolonged heatwaves

                DR Congo and M23 rebels agree roadmap for peace talks

                DR Congo and M23 rebels agree roadmap for peace talks

                Wicker Man director's sons complete their late father's film trilogy

                Wicker Man director’s sons complete their late father’s film trilogy

                Erling Haaland haircut: Zlatan Ibrahimovic, Jack Grealish & Noel Gallagher shocked

                Erling Haaland haircut: Zlatan Ibrahimovic, Jack Grealish & Noel Gallagher shocked

                Dozens of co-ordinated arson attacks hit southern Thailand

                Dozens of co-ordinated arson attacks hit southern Thailand

                Zelensky has 'questions to answer' on corruption, Mykhailo Fedorov tells BBC

                Zelensky has ‘questions to answer’ on corruption, Mykhailo Fedorov tells BBC

                Sydney Marathon medal wrongly features Munich stadium

                Sydney Marathon laughs off medal error

                Swedish sword attack victim was 17-year-old girl, police say

                Swedish sword attack victim was 17-year-old girl, police say

                Trending Tags

                • Tecnología
                  • All
                  • Aplicaciones
                  • Inteligencia Artificial
                  China pospone abruptamente el lanzamiento de la ambiciosa misión lunar Chang'e-7

                  China pospone abruptamente el lanzamiento de la ambiciosa misión lunar Chang’e-7

                  Las empresas que ganan con agentes de IA están limitando cuánto pueden hacer los agentes solos

                  Las empresas que ganan con agentes de IA están limitando cuánto pueden hacer los agentes solos

                  Robots humanoides chinos baten récords humanos en 100 m de velocidad y salto de altura en juegos de robots de Beijing

                  Robots humanoides chinos baten récords humanos en 100 m de velocidad y salto de altura en juegos de robots de Beijing

                  Se acerca un eclipse lunar casi total con América en posición privilegiada

                  Se acerca un eclipse lunar casi total con América en posición privilegiada

                  Uber multada con casi mil millones de dólares por reguladores holandeses por suspensiones automáticas de cuentas

                  Uber multada con casi mil millones de dólares por reguladores holandeses por suspensiones automáticas de cuentas

                  Nvidia descubre que las matemáticas lineales simples pueden reemplazar las costosas transferencias de modelos de IA

                  Nvidia descubre que las matemáticas lineales simples pueden reemplazar las costosas transferencias de modelos de IA

                  Las escuelas están comenzando a enseñar conocimientos sobre inteligencia artificial. Para muchos, eso significa ayudar a los niños a ver los defectos de los chatbots.

                  Las escuelas están comenzando a enseñar conocimientos sobre inteligencia artificial. Para muchos, eso significa ayudar a los niños a ver los defectos de los chatbots.

                  Slack wants to drag AI coding out of the terminal and into the group chat

                  Slack wants to drag AI coding out of the terminal and into the group chat

                  Harvard acuerda un acuerdo de 53 millones de dólares por partes de cuerpos robadas y vendidas por un ex gerente de la morgue

                  Harvard acuerda un acuerdo de 53 millones de dólares por partes de cuerpos robadas y vendidas por un ex gerente de la morgue

                  Trending Tags

                  • Entretenimiento
                    • All
                    • Cine y Series
                    • Cultura Digital
                    • Cultura Popular
                    • Gastronomía
                    • Música
                    La compositora de Motown, Janie Bradford Hobbs, muere en Los Ángeles después de una enfermedad a los 87 años

                    La compositora de Motown, Janie Bradford Hobbs, muere en Los Ángeles después de una enfermedad a los 87 años

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    China investiga a un comediante que alteró la letra de una canción revolucionaria en el escenario

                    El príncipe Harry y otras seis personas conocerán el costo inicial del caso fallido del Daily Mail

                    El príncipe Harry y otras seis personas conocerán el costo inicial del caso fallido del Daily Mail

                    Los fiscales volverán a juzgar a Yung Filly por tres cargos de violación en Australia

                    Los fiscales volverán a juzgar a Yung Filly por tres cargos de violación en Australia

                    El jurado escucha a 'Keffe D' decir que su sobrino disparó fatalmente a Tupac Shakur en un tiroteo desde un vehículo en 1996

                    El jurado escucha a ‘Keffe D’ decir que su sobrino disparó fatalmente a Tupac Shakur en un tiroteo desde un vehículo en 1996

                    Una pregunta surge sobre el regreso de Harry al Reino Unido. ¿Podrá reconstruir su relación con el príncipe William?

                    Una pregunta surge sobre el regreso de Harry al Reino Unido. ¿Podrá reconstruir su relación con el príncipe William?

                    Pulitzers y la Asociación Estadounidense de Bibliotecas lanzan la exposición itinerante 'Pulitzer on the Road'

                    Pulitzers y la Asociación Estadounidense de Bibliotecas lanzan la exposición itinerante ‘Pulitzer on the Road’

                    Después de perder a un amigo y escribir 'Say So', Dan + Shay regresan con la autobiográfica 'Young'

                    Después de perder a un amigo y escribir ‘Say So’, Dan + Shay regresan con la autobiográfica ‘Young’

                    30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                    El Centro Kennedy dice a la corte que no intentará restaurar el nombre de Trump en el edificio antes del 8 de septiembre

                    Trending Tags

                    • Titulares del Día
                      • All
                      • En Portada
                      Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

                      Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

                      Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

                      Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

                      Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

                      Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

                      “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

                      “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

                      Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

                      Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

                      Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

                      Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

                      Banreservas avanza 15 posiciones en el ranking de los 1,000 bancos más importantes del mundo

                      Banreservas respaldará con financiamiento a inversionistas de dos nuevos proyectos residenciales en Punta Bergantín

                      J.P. Morgan expresa intención de expandir inversiones en República Dominicana luego de encuentro con Valdez Albizu

                      J.P. Morgan expresa intención de expandir inversiones en República Dominicana luego de encuentro con Valdez Albizu

                      Suprema ratifica condena de 20 años a Argenis Contreras por crimen contra Yuniol Ramírez

                      Suprema ratifica condena de 20 años a Argenis Contreras por crimen contra Yuniol Ramírez

                      Trending Tags

                      • Mundo
                        • All
                        • América Latina
                        • Conflictos Internacionales
                        • Estados Unidos
                        • Europa
                        • Geopolítica
                        • Haití
                        • Medio Oriente
                        Franco Colapinto no ocultó su bronca por las sanciones recibidas en el GP de Países Bajos: "Les hace falta criterio"

                        Franco Colapinto no ocultó su bronca por las sanciones recibidas en el GP de Países Bajos: «Les hace falta criterio»

                        El etíope Yomif Kejelcha ganó la Media Maratón de Buenos Aires y marcó un nuevo récord mundial

                        El etíope Yomif Kejelcha ganó la Media Maratón de Buenos Aires y marcó un nuevo récord mundial

                        Florida implementó la enseñanza obligatoria de la “Historia del Comunismo” en las escuelas

                        Florida implementó la enseñanza obligatoria de la “Historia del Comunismo” en las escuelas

                        Un robot humanoide chino destrozó el récord mundial de Usain Bolt en los 100 metros

                        Un robot humanoide chino destrozó el récord mundial de Usain Bolt en los 100 metros

                        Javier Milei defendió el rumbo económico y anticipó la batalla electoral de 2027: “Voy a ir por la reelección”

                        Javier Milei defendió el rumbo económico y anticipó la batalla electoral de 2027: “Voy a ir por la reelección”

                        Descubren la estrella más rápida de la Vía Láctea: viaja a 25.000 kilómetros por segundo

                        Descubren la estrella más rápida de la Vía Láctea: viaja a 25.000 kilómetros por segundo

                        Los idiotas útiles no sobreviven a su utilidad

                        Los idiotas útiles no sobreviven a su utilidad

                        Por qué es momento de comprar oro y plata

                        Por qué es momento de comprar oro y plata

                        La candidata respaldada por China tomó la delantera en la carrera por la ONU

                        La candidata respaldada por China tomó la delantera en la carrera por la ONU

                        Trending Tags

                        • Nacionales
                          • All
                          • Bávaro Punta Cana
                          • Educación
                          • Gobierno
                          • Infraestructura
                          • Justicia
                          • Obras Públicas
                          • Opinión
                          • Provincias
                          • Seguridad Ciudadana
                          • semana santa 2026
                          • Sociedad
                          • Transporte
                          Especialista revela la diabetes aumenta a un 17% y afecta alrededor de dos millones de dominicanos

                          Especialista revela la diabetes aumenta a un 17% y afecta alrededor de dos millones de dominicanos

                          Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

                          Roberto Casaá: Acusación de ADP sobre libros de historia es temeraria, deshonesta y luce que no los han leído

                          Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

                          Director del SNS designa nuevos directores en hospitales Padre Billini, Galván, Jaime Mota y Vicente Noble

                          Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

                          Leonel asegura PRM no pudo mantener programa de 24 horas de energía: “El pueblo se cansó”

                          “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

                          “En Los Alcarrizos lo que se respira es Leonel”, afirma vicealcaldesa que dejó el PRM para ingresar a la FP

                          Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

                          Desde Jimaní, el presidente Abinader convoca a toda la comunidad educativa a iniciar el lunes el año escolar

                          CMD exalta a Jorge Asjana David como Maestro de la Medicina...

                          CMD exalta a Jorge Asjana David como Maestro de la Medicina…

                          Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

                          Johnny Pujols: PRM va en picada y el PLD fortalece su estructura territorial con miras a 2028

                          Conani escucha planteamientos de varias instituciones sobre el proceso de reforma de la Ley 136-03

                          Conani escucha planteamientos de varias instituciones sobre el proceso de reforma de la Ley 136-03

                          Trending Tags

                          • Política
                            • All
                            • Congreso
                            • Opinión Política
                            • Partidos Políticos
                            • Poder Municipal
                            • Transparencia y Corrupción
                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Vicealcaldesa de Los Alcarrizos abandona el PRM y se juramenta en la Fuerza del Pueblo junto a más de 300 dirigentes

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Leonel afirma PRM no pudo mantener 24 horas de electricidad y la gente está cansada de apagones

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Johnny Pujols afirma PLD fortalece su estructura territorial mientras PRM va en picada

                            Advierte año escolar iniciará con problemas de fondo ante un...

                            Advierte año escolar iniciará con problemas de fondo ante un…

                            Entérese quienes se integraron al proyecto presidencial de...

                            Entérese quienes se integraron al proyecto presidencial de…

                            FP pide interpelar al ministro de Educación Luis Miguel De Camps por dificultades previo al inicio del año escolar

                            FP pide interpelar al ministro de Educación Luis Miguel De Camps por dificultades previo al inicio del año escolar

                            Colombia Alcántara será moderadora del XIX congreso...

                            Colombia Alcántara será moderadora del XIX congreso…

                            Milton Morrison reafirma alianza con Abinader y anuncia nueva...

                            Milton Morrison reafirma alianza con Abinader y anuncia nueva…

                            Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

                            Empresarios de Hato Mayor expresan respaldo a Leonel Fernández y fortalecen proyecto político rumbo a 2028

                            Trending Tags

                            • Deportes
                              • All
                              • Atletas Dominicanos
                              • Béisbol
                              DR Open Kiteboarding Championship reúne atletas de 15 países y reafirma a Cabarete como capital del kitesurf del Caribe

                              Cabarete se corona como capital histórica del kitesurf con el DR Open Championship 2026

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              El impulso olímpico del billar recibe un impulso de los dos campeones mundiales consecutivos de China

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              La reboteadora líder de todos los tiempos de la WNBA, Tina Charles, se retira del baloncesto

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Sabalenka pide boicot si los jugadores no obtienen una mayor parte de los ingresos del Grand Slam

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Los 76ers tienen un cambio breve y luego una noche larga con una derrota aplastante en el Juego 1

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Ex empleado de Stefon Diggs subirá al estrado por segundo día en el juicio por agresión a un jugador de la NFL

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              Kansas City es la sede central de la Copa del Mundo y alberga a Inglaterra, Argentina y Holanda, además de 6 partidos.

                              30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                              Buffalo recibe a Montreal para abrir la segunda ronda

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Judge quiere una nueva tradición del Bronx: “¡Los Yankees ganan!” de Sterling. antes de la canción de Sinatra

                              Trending Tags

                              • Economía
                                • All
                                • Combustibles
                                • Energía
                                • Indicadores Económicos
                                • Sector Energético
                                • Turismo
                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aerodom anuncia nuevas rutas aéreas, pero la pregunta de fondo es quién fiscaliza la concesión

                                Aventúrate RD 2026

                                Aventúrate RD 2026 revela agenda oficial y consolida el turismo de aventura dominicano

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                WTTC: Una inversión de más de un billón de dólares en viajes y turismo es una muestra de confianza en el futuro del sector

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Una semana para crear en Samaná: Atelier Yubarta busca conectar arte, naturaleza y turismo en Cayo Levantado Resort

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Meta RD 2036: el plan turístico que el Gobierno aplaude sin fiscalización

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                Viva Resorts impulsa el turismo interno en República Dominicana con jornada exclusiva en Bayahibe

                                El ministerio de Turismo cierra con éxito festival gastronómico “Saborea el Paraíso” en Sánchez, Samaná

                                El Ministerio de Turismo celebra un exitoso cierre del festival gastronómico «Saborea el Paraíso» en Sánchez, Samaná

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                El Consejo Mundial de Viajes y Turismo (WTTC) informa la incorporación de Piñero como miembro global

                                Más allá del comercio: los efectos del arancel estadounidense sobre el turismo dominicano

                                Arancel de EE.UU. pone a prueba al turismo dominicano y al silencio oficial del gobierno

                                Trending Tags

                                • Ciencia
                                  • All
                                  • Energía
                                  • Innovación
                                  • Investigación Científica
                                  • Salud y Medicina
                                  • Tecnología Médica
                                  Thousands struggling without power in Gary, Indiana 12 days after severe storms

                                  Thousands struggling without power in Gary, Indiana 12 days after severe storms

                                  France links rise in drownings to prolonged heatwaves

                                  France links rise in drownings to prolonged heatwaves

                                  DR Congo and M23 rebels agree roadmap for peace talks

                                  DR Congo and M23 rebels agree roadmap for peace talks

                                  Wicker Man director's sons complete their late father's film trilogy

                                  Wicker Man director’s sons complete their late father’s film trilogy

                                  Erling Haaland haircut: Zlatan Ibrahimovic, Jack Grealish & Noel Gallagher shocked

                                  Erling Haaland haircut: Zlatan Ibrahimovic, Jack Grealish & Noel Gallagher shocked

                                  Dozens of co-ordinated arson attacks hit southern Thailand

                                  Dozens of co-ordinated arson attacks hit southern Thailand

                                  Zelensky has 'questions to answer' on corruption, Mykhailo Fedorov tells BBC

                                  Zelensky has ‘questions to answer’ on corruption, Mykhailo Fedorov tells BBC

                                  Sydney Marathon medal wrongly features Munich stadium

                                  Sydney Marathon laughs off medal error

                                  Swedish sword attack victim was 17-year-old girl, police say

                                  Swedish sword attack victim was 17-year-old girl, police say

                                  Trending Tags

                                  • Tecnología
                                    • All
                                    • Aplicaciones
                                    • Inteligencia Artificial
                                    China pospone abruptamente el lanzamiento de la ambiciosa misión lunar Chang'e-7

                                    China pospone abruptamente el lanzamiento de la ambiciosa misión lunar Chang’e-7

                                    Las empresas que ganan con agentes de IA están limitando cuánto pueden hacer los agentes solos

                                    Las empresas que ganan con agentes de IA están limitando cuánto pueden hacer los agentes solos

                                    Robots humanoides chinos baten récords humanos en 100 m de velocidad y salto de altura en juegos de robots de Beijing

                                    Robots humanoides chinos baten récords humanos en 100 m de velocidad y salto de altura en juegos de robots de Beijing

                                    Se acerca un eclipse lunar casi total con América en posición privilegiada

                                    Se acerca un eclipse lunar casi total con América en posición privilegiada

                                    Uber multada con casi mil millones de dólares por reguladores holandeses por suspensiones automáticas de cuentas

                                    Uber multada con casi mil millones de dólares por reguladores holandeses por suspensiones automáticas de cuentas

                                    Nvidia descubre que las matemáticas lineales simples pueden reemplazar las costosas transferencias de modelos de IA

                                    Nvidia descubre que las matemáticas lineales simples pueden reemplazar las costosas transferencias de modelos de IA

                                    Las escuelas están comenzando a enseñar conocimientos sobre inteligencia artificial. Para muchos, eso significa ayudar a los niños a ver los defectos de los chatbots.

                                    Las escuelas están comenzando a enseñar conocimientos sobre inteligencia artificial. Para muchos, eso significa ayudar a los niños a ver los defectos de los chatbots.

                                    Slack wants to drag AI coding out of the terminal and into the group chat

                                    Slack wants to drag AI coding out of the terminal and into the group chat

                                    Harvard acuerda un acuerdo de 53 millones de dólares por partes de cuerpos robadas y vendidas por un ex gerente de la morgue

                                    Harvard acuerda un acuerdo de 53 millones de dólares por partes de cuerpos robadas y vendidas por un ex gerente de la morgue

                                    Trending Tags

                                    • Entretenimiento
                                      • All
                                      • Cine y Series
                                      • Cultura Digital
                                      • Cultura Popular
                                      • Gastronomía
                                      • Música
                                      La compositora de Motown, Janie Bradford Hobbs, muere en Los Ángeles después de una enfermedad a los 87 años

                                      La compositora de Motown, Janie Bradford Hobbs, muere en Los Ángeles después de una enfermedad a los 87 años

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      China investiga a un comediante que alteró la letra de una canción revolucionaria en el escenario

                                      El príncipe Harry y otras seis personas conocerán el costo inicial del caso fallido del Daily Mail

                                      El príncipe Harry y otras seis personas conocerán el costo inicial del caso fallido del Daily Mail

                                      Los fiscales volverán a juzgar a Yung Filly por tres cargos de violación en Australia

                                      Los fiscales volverán a juzgar a Yung Filly por tres cargos de violación en Australia

                                      El jurado escucha a 'Keffe D' decir que su sobrino disparó fatalmente a Tupac Shakur en un tiroteo desde un vehículo en 1996

                                      El jurado escucha a ‘Keffe D’ decir que su sobrino disparó fatalmente a Tupac Shakur en un tiroteo desde un vehículo en 1996

                                      Una pregunta surge sobre el regreso de Harry al Reino Unido. ¿Podrá reconstruir su relación con el príncipe William?

                                      Una pregunta surge sobre el regreso de Harry al Reino Unido. ¿Podrá reconstruir su relación con el príncipe William?

                                      Pulitzers y la Asociación Estadounidense de Bibliotecas lanzan la exposición itinerante 'Pulitzer on the Road'

                                      Pulitzers y la Asociación Estadounidense de Bibliotecas lanzan la exposición itinerante ‘Pulitzer on the Road’

                                      Después de perder a un amigo y escribir 'Say So', Dan + Shay regresan con la autobiográfica 'Young'

                                      Después de perder a un amigo y escribir ‘Say So’, Dan + Shay regresan con la autobiográfica ‘Young’

                                      30 pasajeros son evacuados después de que un crucero encallara en un arrecife en Fiji

                                      El Centro Kennedy dice a la corte que no intentará restaurar el nombre de Trump en el edificio antes del 8 de septiembre

                                      Trending Tags

                                      No Result
                                      View All Result
                                      Despertar Matinal
                                      No Result
                                      View All Result

                                      DataGrail report finds your vendor may be sending data to AI models you never approved

                                      by — Redacción Despertar Matinal
                                      27 de mayo de 2026
                                      in Tecnología
                                      0
                                      DataGrail report finds your vendor may be sending data to AI models you never approved
                                      0
                                      SHARES
                                      14
                                      VIEWS
                                      Share on FacebookShare on Twitter

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      ¡No te pierdas las noticias destacadas!

                                      Suscríbete y recibe las historias más importantes del día.

                                      Al suscribirte aceptas nuestros términos y condiciones y política de privacidad.

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tours Colombia Todo el año Tours Colombia Todo el año Tours Colombia Todo el año

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado Tour Cayo Arena Día Feriado

                                      The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail’s Privacy and AI Trends Report 2026, released today.

                                      The San Francisco-based privacy platform analyzed 2,400 popular business software providers and found that 63.6% of vendors that prominently advertise AI capabilities do not disclose a third-party AI subprocessor in their legal documentation. The implication: the majority of companies purchasing AI-enabled software may be unknowingly exposing their customers’ data to AI models and pipelines they never reviewed, never approved, and may not even know exist.

                                      «All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,» DataGrail co-founder and CEO Daniel Barber told VentureBeat in an exclusive interview ahead of the report’s release. «The DPA should be the reliable document that teams use to evaluate AI risk, but based on that number, that’s not enough in 2026.»

                                      The finding drops into an enterprise landscape where organizations with high levels of shadow AI already experience average breach costs of $4.63 million — $670,000 more than those with low or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report. And it arrives in a year when U.S. states gave out $3.425 billion in privacy-related fines — more than the last five years combined — a trend Gartner expects to accelerate through 2028.

                                      How researchers uncovered the growing gap between AI vendor contracts and reality

                                      DataGrail’s methodology for arriving at the 63.6% figure goes well beyond reading contracts. The company’s research team cross-referenced DPA disclosures against product documentation, GitHub environments, API connections, and marketing materials for each of the 2,400 vendors in its tracking universe.

                                      Barber walked VentureBeat through the process: «We looked at the DPA as the baseline, but then what we also looked at is the GitHub environment, the API connections that a particular vendor has, the product documentation, the marketing documentation, and triangulate that information to discern — okay, so the DPA document says use OpenAI, but actually you’ve got these three AI subprocessors over here in your product documentation outlining features and functionality, but that is not reflected in your DPA.»

                                      When asked directly about how confident he was that these gaps represent actual shadow AI risk rather than vendors using proprietary technology, Barber was unequivocal. «Very confident, because we looked at the sample of the 2,400 systems, and we spent a substantial amount of time actually looking at product documentation, GitHub environments, looking at actual API connections, because we integrate with these systems as well, so we know how they process personal information. It is from primary research.»

                                      The disclosure gap matters because it undermines the entire chain of trust that privacy programs rely on. Consider a scenario Barber described: A company invests in an AI recruiting tool. The tool’s DPA lists Claude as its foundational model. The company dutifully performs a security review of Anthropic’s AI. But the recruiting tool also quietly uses OpenAI and Gemini behind the scenes — models the company never evaluated. 

                                      Those undisclosed models then process thousands of resumes and execute automated hiring decisions. The company, without knowing it, has exposed sensitive personal information — home addresses, financial data, possibly Social Security numbers — to AI systems it never vetted, potentially violating FTC regulations on automated decision-making in employment. «How those vendors are evaluating and performing that automated decision making could be really disastrous for a business,» Barber said.

                                      Nearly a third of AI systems acknowledge at least one advanced privacy risk in their disclosures — but with most vendors failing to update their data processing agreements, the actual figure is almost certainly higher. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      One-third of AI systems also process sensitive data, and the true number is likely higher

                                      The disclosure gap alone would be concerning enough. But DataGrail’s report layers on another finding that makes the problem materially worse: 32.8% of AI systems that disclose AI capabilities also disclose at least one other high-risk activity, such as processing sensitive personal information or powering automated decision-making. Among AI systems with self-reported risk factors, 47.1% process personal data, 20.7% have the potential to power automated decision-making, 16.5% process sensitive data categories like health or financial information, and 7.5% process biometric data.

                                      The report argues these figures almost certainly undercount actual exposure, since they reflect only what vendors have formally disclosed. Vendors could underreport access to personal data, and the inherent flexibility of AI means even good-faith vendors might not predict riskier user applications of their tools.

                                      This has immediate regulatory implications. The CCPA’s new risk assessment requirement, effective January 1, 2026, requires businesses to conduct and document risk assessments for processing activities that present significant privacy risks — and will require submission to CalPrivacy by April 2028, with executive attestation under penalty of perjury. 

                                      Processing sensitive personal information with AI, or using AI for automated decision-making, are precisely the activities that trigger this obligation. The report finds that 42% of companies abandoned AI initiatives in 2025 with data privacy concerns cited as a primary obstacle — a statistic sourced to S&P Global research. Privacy teams that engage early with AI projects, Barber argues, can prevent that waste by ensuring safeguards are in place before launch, with AI risk assessments serving as the right starting point.

                                      Screenshot 2026-05-27 at 1.51.09 AM

                                      Gambling and consumer technology companies face the heaviest privacy assessment workloads, conducting roughly four times the annual reviews required in the entertainment industry. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Why consent management became 2025’s most punished privacy failure

                                      While shadow AI is still a newer category of threat, the report makes clear that traditional privacy challenges have not eased — they have intensified. Consent management was the busiest enforcement topic of 2025. California alone publicly reported $4.3 million in CCPA consent settlements, and 2025 saw over 1,400 class action wiretapping suits driven by private firms investigating tracking pixels and session replay software.

                                      Despite this enforcement wave, 63% of the 5,000 websites DataGrail audited still fail to comply with universal opt-out mechanisms such as the Global Privacy Control signal. While that figure represents an improvement from 75% non-compliance in 2023, the pace of improvement is slow relative to the acceleration in enforcement.

                                      Barber pointed to the case of Todd Snyder, the menswear retailer that the California Privacy Protection Agency fined $345,178 in May 2025, as evidence that enforcement is no longer reserved for big tech. «This is a business that has two or three stores across the U.S. They have 300 employees,» he said. «They run tight margins because they’re a consumer menswear clothing store.»

                                      The California Attorney General also reached a $2.75 million settlement with Disney over failures to honor opt-out signals, while the California Privacy Protection Agency has brought enforcement actions against PlayOn Sports and Ford — a pattern that demonstrates both the breadth and depth of regulatory activity. Among the trackers that fire even after a user sends a GPC signal, the report found that 27.1% come from Google Analytics and 43.8% are for targeted advertising via platforms like Meta and Microsoft.

                                      For users who do engage with consent banners, 48.3% click «Accept all,» while only 12.4% select «Essential only» and 2.3% customize their preferences. A full 37% simply exit the banner without making a selection. The practical takeaway: less than 15% of users make a conscious choice to opt out of tracking, which means consent banners present relatively low business risk when properly configured — but enormous regulatory risk when they are not.

                                      Screenshot 2026-05-27 at 1.49.50 AM

                                      Nearly half of users simply accept all cookies when a consent banner appears. Fewer than 15 percent actively choose to limit tracking — a pattern that makes proper banner configuration a high-stakes compliance question. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      Data deletion requests surge 567% as the cost of manual processing hits $1.5 million a year

                                      Data subject request volume hit an all-time high for the fifth consecutive year. Deletion requests have surged 567% since 2021 and now represent 87% of all data subject requests. Access requests, by contrast, have gradually declined as consumers skip visibility and reach straight for the delete button.

                                      The cost is staggering. For a mid-sized organization receiving 5 million annual web visitors, the report estimates manual DSR management now runs approximately $1.5 million per year, based on Gartner’s estimated cost of $1,524 per manual DSR. The average cost has climbed from $238,000 in 2021 to $1.51 million in 2025 — a trajectory that makes manual processing not just inefficient but, as the report argues, «irresponsible.»

                                      Barber emphasized that these numbers reflect verified human requests with bot and spam traffic excluded, and that data broker scenarios — which will see their own massive influx of requests under California’s Delete Act — are reported separately. «That is a natural increase,» Barber told VentureBeat. «If you’ve now got 20-plus U.S. states with privacy regulation, it’s unlikely that we see a federal bill passed, even though we’ve seen one proposed. And while we don’t see federal awareness and regulation, we do see at the state level over 20 states, and that may actually increase awareness for the consumer even more.»

                                      He added a telling detail about how businesses are responding in practice: «99% of DataGrail customers do process that deletion» even for residents of states without privacy laws, «simply because it’s too hard at this point. Discerning and even communicating to the person, ‘Hey, you live in Montana, sorry, you’re just in an unfortunate state without regulation’ — you just can’t do that.» Data brokers felt the impact most acutely, with a 398% increase in deletion requests compared to 2024 and an average of over 2,000 deletion requests handled per month.

                                      Screenshot 2026-05-27 at 2.27.21 AM

                                      The cost of handling consumer privacy requests by hand has risen more than sixfold since 2021. (Source: DataGrail Privacy and AI Trends Report 2026)

                                      State regulators issued $3.4 billion in privacy fines last year, and both parties want more

                                      The regulatory landscape underpinning all of these trends has fundamentally shifted from education to punishment. Nearly half of U.S. states now have a comprehensive privacy law in effect, plus over 160 AI-specific laws. State legislatures enacted 145 AI-related laws in 2025 alone, with another thousand introduced or reworked. According to Gartner, over 50% of the U.S. population is now covered by a comprehensive state privacy law, with 24 additional states expected to pass laws within five years. States have also begun pooling their resources, with ten forming the Consortium of Privacy Regulators last year and pledging to coordinate investigations across state lines.

                                      Barber argued that privacy enforcement is fundamentally bipartisan, which insulates it from the shifting political winds of the current administration. «Privacy overall is a pretty bipartisan issue,» he said. «It’s easy to pass privacy regulation because constituents somewhat expect privacy in their day-to-day living. If you were flying on an airline and they said, ‘Okay, this seat, if you want your privacy, you’re going to have to pay $6 more,’ you’re like, ‘I’m going to go to another airline.’ It’s an expected part of a transaction at this stage.»

                                      He predicted that other states will replicate California’s enforcement model. «California has their enforcement division, CalPrivacy. That group has one task: to ensure enforcement of privacy throughout businesses. Is it likely that we see other states get funding and support to fund these types of groups? Highly likely. The enforcement fines — the actual payments — go back to us as constituents. That type of model, you could imagine, being very popular across the country.»

                                      Privacy teams are losing a third of their staff just as AI governance demands explode

                                      Perhaps the most paradoxical finding in the report is that privacy teams lost as much as 33% of their headcount last year, even as their workloads expanded across every metric the report tracks. Cisco data cited in the report shows that 90% of privacy programs expanded in 2025 due to AI, while only 12% of AI governance programs are considered mature. Meanwhile, 74% of privacy teams planned to apply AI to privacy-related tasks in 2026, according to ISACA’s State of Privacy 2026 survey.

                                      Barber sees this as part of a broader macroeconomic pattern rather than a sign that organizations do not value privacy. «It’s actually a fascinating macro trend, and probably one you’ve seen across all functions,» he said. «Businesses are driving more efficiency in all parts of the business. Privacy teams, five years ago, we would have said, ‘Well, there’s more regulation, the volume of deletions have increased 500%, we need more humans.’ It’s become clear that AI provides capabilities that can do the work for privacy individuals.» He drew an analogy: «They might have had a design team of 20 people five years ago, now they have a design team of five, courtesy of Claude Design or Gamma or whatever the tool may be. I think that’s what we’re seeing here as well.»

                                      DataGrail has positioned its own AI agent, Vera — launched in March 2026 — as part of the answer. Vera is embedded within DataGrail’s existing platform and aims to automate privacy workflows across multiple jurisdictions. The company was also named the first production-ready Model Context Protocol server for privacy, using the standard created by Anthropic to enable customers to launch DataGrail tools from whatever application they are already working in, whether Slack, email, or Claude.

                                      Can a vendor-produced report be trusted to diagnose the problems that vendor sells solutions for?

                                      DataGrail is, of course, a company that directly benefits from the problems its report identifies. The company has raised a total of $84.2 million over five rounds, with its largest being a $45 million Series C in October 2022 led by Third Point Ventures. Its platform addresses precisely the data mapping, DSR automation, consent management, and risk assessment challenges the report spotlights.

                                      Barber acknowledged the tension directly. «It’s a fair statement,» he said when asked about potential skepticism. «DataGrail doesn’t provide a service to keep DPAs up to date — that’s on a business to evaluate how they work with a vendor. What DataGrail does help to do is assessments, and automate those assessments using our AI agent, Vera, to assess that increased risk.»

                                      He argued that the more neutral reading of the data is structural: «This is evidence to show that the DPA unfortunately is not keeping up with technology and the speed at which technology is innovating. That’s both exciting but also we need to accept that’s where we are.» The methodology does lend some credibility to this claim. 

                                      The report draws on anonymized privacy operations data from hundreds of enterprise customers, the 2,400-system AI tracking database, and the 5,000-website consent audit — sources that are at least partially independent of DataGrail’s commercial interests. And the broader findings on enforcement spending, DSR volume trends, and regulatory expansion align closely with independently published data from Gartner, Cisco, and state enforcement agencies.

                                      The next frontier: agentic AI could spread unvetted data across entire organizations autonomously

                                      When asked about the most important trend that did not make it into the report, Barber pointed to a next-generation risk that extends the shadow AI problem into far more dangerous territory: agentic AI workflows. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025 — a pace of adoption that could rapidly outstrip the governance mechanisms companies are only now beginning to build.

                                      «Where we go next with this research is agent processing,» Barber said. «How are agents then leveraging that information? Because the downstream ramifications would be far more concerning for a business. One particular system is using shadow AI, the business has no idea that that’s happening, and then an agent is propagating that information across a whole bunch of other places. The guardrails of you and I checking the system will be lower than maybe what we’ve seen in the past with agentic workflows.»

                                      He framed the distinction in human terms: «The identity of an agent is different than a human. There is thought that goes into what am I about to use here, where did this information come from, how was it collected — that may not be considered in the same way for an agentic workflow. We need to solve the root of the problem, which is how are these businesses leveraging AI subprocessors. But this quickly becomes an agentic problem that could be far more concerning.»

                                      For the enterprise privacy and security leaders absorbing this report today, the uncomfortable truth is that the foundational documents and processes they have relied on to manage vendor risk for years are decomposing in real time. The DPA is breaking down as a reliable instrument. State enforcement is accelerating on a bipartisan basis. Privacy teams are shrinking even as their mandates expand. And the next wave of agentic AI systems threatens to distribute unvetted data processing across networks of autonomous agents that operate with even less human oversight than today’s tools.

                                      Five years ago, when DataGrail published its first trends report, deletion requests were a fraction of what they are today, only a handful of states had privacy laws on the books, and the phrase «shadow AI» did not exist. Every year since, the report has warned that the problem was getting worse. Every year, the data has proved it right. The companies that survive the next chapter will not be the ones with the biggest compliance teams or the thickest policy binders. They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data — and by 2027, autonomous agents may be deciding what to do with it.

                                      ● Canal oficial · Gratis
                                      ¡Recibe las noticias antes que nadie!
                                      Únete a nuestro canal de WhatsApp y mantente informado al instante, sin spam.
                                      Unirme ahora →
                                      ● Noticias al instante ● Cobertura nacional ● Periodismo real Despertar Matinal
                                      — Redacción Despertar Matinal

                                      — Redacción Despertar Matinal

                                      Programa radial que te conecta con la información desde temprano en la mañana.

                                      Next Post
                                      Reseña musical: En 'The Boys of Dungeon Lane' de Paul McCartney, un ex-Beatle recuerda

                                      Reseña musical: En 'The Boys of Dungeon Lane' de Paul McCartney, un ex-Beatle recuerda

                                      Deja una respuesta Cancelar la respuesta

                                      Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *

                                      Canal de WhatsApp

                                      WhatsApp logo WhatsApp

                                      Canal · Despertar Matinal

                                      Únete a nuestro
                                      Canal

                                      Seguir ahora

                                      El clima

                                      Canal de YouTube

                                      YouTube

                                      Canal · Despertar Matinal

                                      Mira nuestro
                                      Canal

                                      Ver ahora

                                      Escúchanos en Spotify

                                      Spotify

                                      Podcast · Despertar Matinal

                                      Escucha nuestro
                                      Podcast

                                      Escuchar ahora

                                      Noticias Populares

                                      • La candidata respaldada por China tomó la delantera en la carrera por la ONU

                                        La candidata respaldada por China tomó la delantera en la carrera por la ONU

                                        0 shares
                                        Share 0 Tweet 0
                                      • Los idiotas útiles no sobreviven a su utilidad

                                        0 shares
                                        Share 0 Tweet 0
                                      • Florida implementó la enseñanza obligatoria de la “Historia del Comunismo” en las escuelas

                                        0 shares
                                        Share 0 Tweet 0
                                      • Carney calls Trump’s fresh tariffs a ‘miscalculation’ after trade talks collapse

                                        0 shares
                                        Share 0 Tweet 0
                                      • Slavko Vinčić rompió el silencio tras la final del Mundial: su retiro, el VAR y el elogio a Lionel Messi

                                        0 shares
                                        Share 0 Tweet 0

                                      Medio digital independiente con análisis, opinión y periodismo responsable desde República Dominicana.

                                      Secciones populares

                                      • Política
                                      • Economía & Negocios
                                      • Justicia
                                      • Turismo
                                      • Tecnología
                                      • Entretenimiento
                                      • Mundo
                                      • Cine y Series
                                      • Música
                                      • Moda

                                      Contenido

                                      • Titulares del Día
                                      • Mundo
                                      • Nacionales
                                      • Política
                                      • Deportes
                                      • Economía & Negocios
                                      • Ciencia
                                      • Entretenimiento
                                      • Podcast
                                      • Opinión
                                      • Despertar Matinal TV
                                      • Editoriales

                                      Corporativo

                                      • Sobre nosotros
                                      • Publicidad
                                      • Sala de prensa
                                      • Contacto
                                      • Política de Privacidad
                                      • Eliminación de Datos

                                      Boletines

                                      Suscríbete a nuestro boletín
                                      Recibe las noticias más importantes cada mañana.

                                      • Nosotros
                                      • Publicidad
                                      • Trabaja con nosotros
                                      • Contactos

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      No Result
                                      View All Result
                                      • Home

                                      © 2025 Despertar Matinal. Aviso Legal - comunícate con nuestra redacción y obtén más información sobre Despertar Matinal..

                                      Welcome Back!

                                      Login to your account below

                                      Forgotten Password?

                                      Retrieve your password

                                      Please enter your username or email address to reset your password.

                                      Log In

                                      Desarrollado por
                                      ►
                                      Las cookies necesarias habilitan funciones esenciales del sitio como inicios de sesión seguros y ajustes de preferencias de consentimiento. No almacenan datos personales.
                                      Ninguno
                                      ►
                                      Las cookies funcionales soportan funciones como compartir contenido en redes sociales, recopilar comentarios y habilitar herramientas de terceros.
                                      Ninguno
                                      ►
                                      Las cookies analíticas rastrean las interacciones de los visitantes, proporcionando información sobre métricas como el número de visitantes, la tasa de rebote y las fuentes de tráfico.
                                      Ninguno
                                      ►
                                      Las cookies de publicidad ofrecen anuncios personalizados basados en tus visitas anteriores y analizan la efectividad de las campañas publicitarias.
                                      Ninguno
                                      ►
                                      Las cookies no clasificadas son aquellas que estamos en proceso de clasificar, junto con los proveedores de cookies individuales.
                                      Ninguno
                                      Desarrollado por