2026 Decision Intelligence Benchmark — Special AI Report
How data privacy leaders are adopting AI — or not — to achieve their business objectives
Table of ContentsData privacy leaders hold a contradiction that no other function in this benchmark holds quite the same way. On automation outlook, they rank 1st of the 11 functions surveyed — 19% expect 40% or more of the function's work to be automated within 24 months, more than double the 9% cross-functional average. On trust, the same group sits at the opposite end: public GenAI draws moderate or significant trust from just 8% of leaders, the lowest of any function on that category and 21 points below the 29% average, while company-owned AI trust (35%) ranks 10th of 11 and enterprise AI trust (46%) ranks 9th of 11.
That gap between ambitious automation expectations and trust runs through usage as well. Data privacy's team usage expectations for enterprise (65%) and company-owned AI (56%) both rank 4th of 11 functions, comfortably above their respective averages — but actual daily use tells a split story: enterprise AI use (46%) holds up well at 3rd of 11, while company-owned AI use (19%) falls to 10th of 11, the second-lowest in the benchmark. The function's strongest proficiency also sits in company-owned AI (71% rated competent or better, 2nd of 11), while public GenAI proficiency (50%) ranks 10th of 11 — a function that has built real fluency with the tools it controls, and has not yet extended that fluency, trust, or daily habit to the public tools used more commonly by other teams.
That tension shows up across every level of the team. Senior leaders report meaningfully higher dependence on AI and higher proficiency with company-owned AI than directors, while managers register the highest share of significant mistrust in public generative AI of any role level — a different pattern than many other functions in this benchmark, where seniority tracks with skepticism. The function is bracing for AI to take on more of the work — reviews, intake, documentation — while remaining, by a wide margin, the benchmark's most skeptical and least trusting of AI tools.
For the purposes of this report, and to better understand how leaders think about different kinds of AI, we grouped tools into three categories:
Data privacy leaders set their highest usage expectations for enterprise platform AI, not public tools. Reviewing expectations, actual use, and the gap between them — and how each compares with the other ten functions in this benchmark — shows where the function's AI expectations are running ahead of practice.
Data privacy leaders set their highest bar for enterprise platform AI: 65% expect their teams to use it daily, ranking 4th of 11 functions and five points above the 60% cross-functional average. Public GenAI expectations (57%) rank lower — 7th of 11, six points below the 63% average — while company-owned AI (56%) ranks 4th of 11, six points above its 50% average. Data privacy is part of a small minority: one of only three functions — alongside talent marketing and supply chain — where enterprise platform AI leads expected usage across our three categories.
In data privacy, senior leaders are setting the pace. Averaged across all three AI types, data privacy's expected-usage figure of 59% lands seventh of eleven functions, close to the 58% cross-functional average — squarely middle of the pack.
Actual use lands well below expectations in every category, and data privacy's standing relative to peers shifts sharply by type. Enterprise AI leads with 46% reporting daily use — 3rd of 11 functions, nine points above the 37% cross-functional average. Public GenAI sits at 33%, ranking 9th of 11 and 13 points below the 46% average. Company-owned AI trails at just 19%, the second-lowest of the 11 functions and seven points below the 26% average. Even the category with the most institutional backing — internally built AI — produces both the lowest daily habit in the function and one of the weakest showings in the benchmark.
Averaged across all three AI types, data privacy's actual-use figure of 33% ranks eighth of eleven functions, slightly below the 36% cross-functional average.
Every category shows a gap between expectation and practice, and the largest gap sits with the AI the organization owns outright. Company-owned AI shows a 37-point gap between 56% expected daily use and 19% actual. Enterprise AI shows the smallest gap, at 19 points, while public GenAI sits in between at 24 points.
The pattern inverts what shows up elsewhere in this benchmark series: The more control an organization has over an AI tool, the further actual use lags what leaders expect of it.
The gap here may represent a build problem. Data privacy leaders trust enterprise and company-owned tools more than public ones, yet actual use of the tools they trust most lags furthest behind. That combination points to workflow design as the missing piece, rather than skepticism. A function this exposed to AI claims from vendors knows the difference between a tool that exists and a tool that is actually load-bearing in daily work — and right now, the tools it owns are not yet load-bearing.
Data privacy leaders generally say losing AI would not be highly disruptive. But on the two-year horizon, automation expectations outpace every other function.
Data privacy reports the lowest dependence on AI of any function in this benchmark except one. Just 16% of leaders say AI disappearing tomorrow would cause moderate or major disruption — well under the 28% cross-functional average. That reading is consistent with members' own description of the work as still fundamentally a human judgment call. Senior leaders predict 34% moderate-or-major disruption, compared with 17% of directors and 0% of managers.
The 24-month outlook tells a different story than today's dependence. 19% of data privacy leaders expect 40% or more of the function's work to become AI-powered within two years — the highest share of any function in the benchmark, with supply chain (18%) and L&D (15%) the next-closest functions.
That ambition is consistent with what data privacy leaders describe in practice: a team buried in volume — contract reviews, privacy impact assessments, intake requests — that could welcome real automation if vendors could deliver it. The bullishness on automation's horizon and the caution about dependence today represent an interesting conflict that is worth future exploration.
Members describe this gap directly: AI dependence is low today because nobody has shown this group automation that works at the volume they need. This points to skepticism from the vendor market. Data privacy leaders are willing bettors on automation's future; they may be waiting for a vendor to prove it.
Unlike most functions in this benchmark, data privacy's strongest proficiency sits in company-owned AI instead of the widely available public tools.
Data privacy breaks from the pattern this benchmark sees elsewhere, where public GenAI typically holds the strongest proficiency simply on account of easier access and longer time in the market. Here, company-owned AI leads: 71% of leaders rate their teams competent or better, second-highest among 11 functions. Conversely, public GenAI carries the highest "beginner" concentration of the three, at 50%.
That ordering is consistent with a function that has been deliberate about which AI environments it uses. Averaged across all three AI types, data privacy's proficiency figure of 60% ranks ninth of eleven functions, close to the 61% cross-functional average. When looking at the data by level, senior leaders report a higher aptitude among their teams than managers or directors.
Members note that privacy professionals often arrive from legal backgrounds already managing a steep technical learning curve — black-box algorithms were not on the law school syllabus. That context reframes the proficiency numbers: competence with company-owned AI at the senior level is not a given, it is the product of leaders who have had to build AI fluency on top of an already-demanding legal foundation. The question for this function is whether that fluency reaches the directors and managers.
Trust in this function runs almost entirely along category lines: public GenAI earns almost none, enterprise and company-owned tools earn considerably more.
This function trusts AI less than almost any other in the benchmark — near or at the bottom in all three categories. Public GenAI draws moderate or significant trust from just 8% of leaders — the lowest public-AI trust level of any function in the benchmark, 21 points below the 29% cross-functional average. Company-owned AI sits at 35%, ranking 10th of 11, fifteen points below its 50% average. Enterprise AI fares far better at 46%, though that still ranks 9th of 11 functions, four points below the 50% average.
Data privacy or security concerns lead mistrust drivers for public GenAI, cited by 88% of leaders — unsurprising for a function whose job is precisely those concerns for everyone else's tools. Inaccurate or hallucinated outputs follow closely at 81%, and misalignment with internal policy sits at 73%.
Threat to job security stays low across all three categories, never reaching 20% — though it's misalignment with internal policy, not job security, that becomes the least-cited concern as AI moves into enterprise and company-owned environments. That ordering matches what members describe directly: less concern about AI replacing them, more concern about whether the organization's own tools are governed well enough to use responsibly.
Members describe this group's mistrust less as fear and more as professional pattern recognition. They sit on the governance committees that review every AI use case the rest of the organization wants approved, which means they see the full breadth of hype, overpromising, and quiet under-delivery before anyone else does. The line privacy leaders keep returning to — that none of the privacy tools are great; they all promise more than they deliver — is the same lens this group applies to AI generally. Low trust here is informed skepticism from the people whose job is to find the gap between marketing and reality.
Compared with the other ten functions in this benchmark, data privacy expects the most automation of any group surveyed. However, trust and dependence are both near the bottom of the eleven functions.
Data privacy's position in this benchmark is unusual: The function that ranks first on automation ambition ranks near last on trust and dependence. Most functions surveyed pair high automation expectations with at least moderate trust in the tools meant to deliver it. Data privacy decouples the two — it is willing to bet on AI's future capability without yet extending much trust to AI's present capability, particularly in public form.
Where most functions build trust and dependence together as adoption deepens, data privacy's skepticism appears to be holding steady even as its automation expectations are solid — something that rewards vendors who can actually address data privacy and hallucination concerns.
For data privacy, trust and dependence have not moved together the way they do in most functions. It is the function most optimistic about automation and yet one of the functions least willing to extend trust to AI's current tools. That may be the function's real advantage — and leaders who convert it into reliable processes, with the right guardrails, can make it durable.