Methodology

The AI Trustworthiness Ranking 2026 evaluates 500 consumer-facing AI companies on publicly verifiable trust signals. Each company receives an Overall Trust Score from 0–100, calculated from four weighted pillars. Companies scoring 75+ are designated AI Trustworthiness Leaders 2026.

Scoring Formula

Overall = (0.35 × Public Perception) + (0.35 × Data Privacy) + (0.20 × Security) + (0.10 × Organizational Transparency)

Each pillar is scored 0–100 independently before weighting. Weights reflect how much each pillar impacts an end user's ability to trust an AI provider.

Pillar 1 — Public Perception (35%)

Public perception data was collected for each company from Trustpilot and G2. For each platform, we recorded the full star distribution and the total review count. Companies present on only one platform were scored from that platform alone.

Calculation:

1. Each platform's star distribution is converted to an average rating on the 1–5 scale.

2. Where a company appears on both platforms, the two averages are combined and weighted by review count, so every individual review counts equally regardless of which site it came from.

3. Adjusting for review volume. A 5-star rating from three reviews is much weaker evidence than a 4.5-star rating from three thousand. Each company's score is therefore blended with the sample average, weighted by how many reviews it has: companies with few reviews sit close to the average, while companies with thousands keep their own rating almost entirely. The median review count across the sample is 89.5

Pillar 2 — Data Privacy (35%)

Four privacy-policy disclosures are scored Clear / Vague / Missing, translating to scores of 1 / 0.5 / 0. The pillar score is the average × 100.

Data collected: Whether the policy lists the specific categories of personal data the company collects (e.g., account info, prompts, uploaded files, device data, location). "Clear" requires named categories; "we collect information you provide" alone is "Vague."

Model-training use & opt-out: Whether the company uses customer inputs (prompts, conversations, uploaded content) to train or fine-tune its own AI models — and, if so, whether users can opt out without deleting their account or paying for a higher tier. "Clear" requires both an explicit answer and, where training occurs, a working opt-out.

Third-party sharing: Whether the policy names the categories of recipients with whom data is shared or sold (sub-processors, advertisers, model providers like OpenAI/Anthropic, analytics vendors). "Clear" requires named categories or named partners. Generic "trusted partners" wording is "Vague."

Data retention: Whether the company clearly explains how long personal data is retained and/or how users can delete it. "Clear" requires either specific retention periods for at least some categories of data (e.g., "payment records are retained for seven years") or a clear deletion mechanism (e.g., deleting data through account settings or by contacting support). Policies stating only that data is retained "as long as necessary" without further detail are scored "Vague." Policies that do not address data retention or deletion at all are scored "Missing."

Pillar 3 — Security (20%)

Three checks, weighted: trust/security page 50 points, bug bounty or CVD programme - 25, ISO/IEC 27001 or SOC 2 Type II certifications - 25.

Trust or security page (50): Whether the company publishes a dedicated page documenting its security practices — typically a trust centre, security overview, or compliance page setting out infrastructure security, data handling, and certifications.

Bug bounty or coordinated vulnerability disclosure (CVD) program (25): Whether the company publishes a way for outside security researchers to report vulnerabilities safely. Accepted: programs on HackerOne, Bugcrowd, Intigriti, YesWeHack, or a self-hosted policy with defined scope and a reporting channel (e.g., /security.txt or a dedicated page).

ISO/IEC 27001 or SOC 2 Type II (25): Whether the company holds a current information-security certification.

Pillar 4 — Organizational Transparency (10%)

Three checks scored Yes / Partial / No. The pillar score is the average × 100.

Legal entity & jurisdiction: Whether the company publicly identifies the registered legal entity operating the product (e.g., "Acme AI Inc., Delaware, USA") in a place a normal user can find, typically the Terms of Service, Privacy Policy, or website footer. A brand name without a registered entity is "No"; an entity name without country/state is "Partial."

Physical address: Whether a physical business address is published.

Working contact channel: Whether the company provides at least one functioning, non-automated way for a user to reach a human, such as a support email, a contact form that produces a real reply, or a published phone number. A chatbot-only widget is "No."

Data Sources & Verification

Each finding is sourced from a public document (privacy policy or security pages, review platforms, etc.).

Companies can submit corrections via the Claim / Correct a Profile form. Full re-evaluation is annual.

Analysis is carried out through an automated flow and verified by a human before being published.

Limitations

Disclosure ≠ practice: There’s no guarantee that companies adhere to what is outlined in their privacy policies or other pages.

Security measurement limitations: Strong security may exist without an ISO 27001 or SOC 2 Type II certification.

Point-in-time snapshot: We evaluate companies approximately every 12 months, and during that time, certificates can expire, policies can change, and public perception can begin to shift.