Selling AI, disclosing nothing

A company can market an AI product while telling customers almost nothing about how AI is used. That silence matters. Buyers may be sharing contracts, customer records, internal documents or proprietary work without knowing which models process the information, whether providers retain it or whether humans can review it.
In OrangeStealth’s monthly refresh dated 2026-09-28, 36.4% of the US B2B SaaS 5-50 population, representing n=397 within a sample of N=1092, marketed an AI product but published no AI usage or transparency page. This observation identifies a public disclosure gap. It does not prove that a company handles data unsafely, violates a contract or has suffered abuse.
What the missing page leaves unanswered
An AI transparency page gives buyers a stable place to understand how a product uses models and data. It can explain whether AI features are optional, which subprocessors support them, what information reaches a model provider, how long prompts and outputs are retained, and whether customer content is used for model training.
Everyone asks their AI vendor "do you train on my data?"Wrong question. "We don't train on it" and "we don't retain it" are completely different
Without that page, a buyer has to search privacy policies, terms, help articles and vendor lists for fragments of the answer. Those documents may have been written before the AI feature existed. They may describe general data processing without explaining the distinct path followed by a prompt, uploaded file or generated response.
The gap also creates work for the seller. Security questionnaires become harder to answer consistently. Sales teams may improvise explanations. Product documentation can drift away from contractual language. A change in model provider or retention behavior may reach the application before it reaches the documents customers rely on.
A hypothetical customer decision
Consider a hypothetical procurement team evaluating software that summarizes uploaded agreements. The product page promotes an AI assistant, but the site does not explain whether agreement text is retained by a model provider or used for training. The privacy policy names broad service-provider categories but does not connect them to the AI feature.
That is not evidence that the agreements are being misused. It is still a practical obstacle. The customer cannot complete a confident third-party risk review from the public material, so it must ask the vendor directly, delay approval or restrict what employees may upload.
Major companies are restricting Anthropic over data-retention fears!Nvidia limits @AnthropicAI models to less sensitive tasks. Booz Allen has barred its commercial model from proprietary cybersecurity
The vendor may have strong internal controls and contract terms. If those protections are not visible, buyers cannot distinguish them from controls that have not yet been defined.
How to close this
- Map the actual AI data path. Document what enters each AI feature, which provider receives it, where processing occurs, what is logged, how long information is retained and whether a human can access it. Verify the deployed configuration instead of relying only on a provider’s default terms.
- Publish a plain-language AI usage page. State which features use AI, whether they are optional, whether customer content is used for training and where buyers can find relevant subprocessors and contractual terms. Link it from the product, privacy and trust areas of the site.
- Make public statements match contracts and settings. Product, legal, security and sales teams should use the same reviewed answers. A promise that conflicts with a configured retention setting creates more risk than silence.
- Create a change trigger. Revisit the disclosure whenever the company adds a model, provider, input type or human-review process. Treat documentation as part of releasing the feature, not as cleanup after launch.
A public disclosure cannot prove that every internal control works, and its absence cannot prove that controls are missing. It can reveal whether a company has given prospective customers enough information to ask focused questions. OrangeStealth’s free public checker at https://orangestealth.com/check provides a quick external view, while an External Security Posture Assessment offers a broader passive review of publicly visible exposure.
Methodology
This research used passive, public-data-only observations from the US B2B SaaS 5-50 population in OrangeStealth’s monthly refresh dated 2026-09-28. The sample size was N=1092. Results were aggregated and k-anonymised, and no company is named. The finding records whether a site marketed an AI product while exposing no identifiable AI usage or transparency page. It does not inspect private systems, determine undisclosed internal practices or establish that abuse occurred.
If your product already uses AI, the next action is simple: compare what the live feature does with what a careful customer can learn from your public site, then close the gaps before that customer has to ask.