Study Reveals the LLM Privacy Policies That Take Over 20 Minutes to Read banner image
News

Study Reveals the LLM Privacy Policies That Take Over 20 Minutes to Read

15 September 2026
New data analysis by cyber security experts at Bridewell has found that it would take just under 20 minutes on average to go through the data privacy policy of the 20 most popular large language models (LLMs).

With an average of 4,603 words, these privacy policies are lengthy and contain jargon and technical language that make it difficult for the average person to read. 

The use of LLMs has increased dramatically since they were first introduced to the public in late 2023, with the launch of OpenAI’s ChatGPT. Now nearly three-quarters of the UK population admit to using AI at least once a month. 

Many are increasingly turning to the chat platforms for research, advice and inspiration - often sharing highly sensitive information, from their finances and medical history to sensitive work details. But how many people understand how that data is being used and processed? 

One survey revealed that 77 percent of employees admitted to pasting company information into AI or LLM tools. What’s more concerning is that 82 percent of those who had done so said they used a personal account for it. 

The analysis by Bridewell looks at the length of data privacy policies, average time to read, readability according to the Fleisch Reading Ease Score and the prevalence of technical and legal jargon to reveal which LLMs have a privacy policy that is most difficult for the average consumer to read and understand.  

The average Fleisch Reading Ease Score of the AI policies analysed is 40.2, which is difficult to read and best suited for university graduates, while a score over 60 is best suited for the general public.  

Of the 20 LLMs studied, it’s Meta's Muse Spark that has the longest data privacy policy. With over 14,000 words, it’d take the average reader nearly an hour to get through all the details.  Besides length, the policy also contains legal and technical jargon that the average reader may not fully grasp. 

Kimi K, by Moonshot AI, is the second most challenging AI policy to read; however, at 6,229 words, it’s less than half the length of Muse Spark’s privacy policy. It would take around 25 minutes to read the full privacy policy; however, its Flesch Reading Ease Score (28.1) is the worst in the study, indicating that the text is complex and difficult to read.  

Command by Cohere follows Kimi K, as one of the longest privacy policies to read, taking the average reader 27 minutes to get through. Its Flesch Reading Ease Score (37.6) also indicates that it’s difficult to read. 

The UK’s most popular LLM, Chat GPT, fares better in terms of its length, however, at 4,143 words, it would still take around 17 minutes to read through the full policy. Its Fleisch Reading Ease Score (43.6) is also more legible. However, the average sentence length and technical and legal jargon still make it challenging for the average user to fully understand. 

One report by the National Literacy Trust indicates that almost one in five (18%) adults in England have very low literacy skills. As LLMs continue to evolve and the services they offer expand, it’s likely that these policies will continue to get lengthier too, making it increasingly difficult for users to fully understand how their data is being used.  

Aside from length and legibility of these policies, it is whether or not users actually understand how their data is being processed and used, particularly if they’re sharing sensitive information.  

Of the 20 LLMs' privacy policies studied, 13 train their models using inputs and outputs. Each LLM offers its users varying degrees of control – while some LLMs offer the option to opt out of training, not all do.   

Chris Linnell, Associate Director of Data Privacy at Bridewell, said: “As LLMs become an increasingly large part of day-to-day life for many, it’s essential for users to fully understand how these tools use their data, and what they can do to protect their privacy. 

“When there is unclear understanding of how data is processed, particularly in professional settings, employees may be at risk of sharing highly sensitive or confidential information that may end up being used to train LLMs.  

“While some tools give users the option to opt out, the burden is on users to select this option. These policies assume people have read and understood them, which many haven't, especially when using personal accounts. 

“Enterprise AI agreements typically address this by explicitly barring tools from using inputs and outputs to train their models and giving organisations oversight of what information is being shared with LLMs. However, when employees use personal accounts for company work, there is a major risk. If client or company data is used in LLMs without a lawful basis, there are potential data protection breach concerns.  

None of this means AI shouldn’t be used, as it can be a valuable tool. But it’s essential for users to fully understand how their data is being processed by LLMs, and businesses need clear internal guidance on what can and can't be shared, and ideally proper enterprise accounts with the right protections in place.”

Speak with one of our consultants to see how Bridewell can support your organisation’s AI consulting efforts.
Bridewell logo Alternative text

Bridewell

Insights by Bridewell