Skip to main content
A magnifying glass held against a computer screen enlarges lines of code.
Analyst Insights

5 key data-privacy metrics revealed as ‘spicy’ Musk lawsuit drops

While experts begin to ponder whether Elon Musk’s new legal battle over sexualized deepfakes will urge more action on data privacy, we deep-dive into ISACA’s latest report on the subject, highlighting five charts with some brutal and (yes) bright spots.

Data Privacy Week started off with a bang Monday when the European Union announced it was launching an investigation into Elon Musk’s X over the possible dissemination of illegal content, fueled by public outcry after millions of sexualized, deepfake images of real women and girls created by xAI’s Grok chatbot flooded the internet.

The probe—which follows a similar investigation recently begun by British media regulator Ofcom—will technically examine whether X broke transparency and content moderation rules under the EU’s Digital Services Act, but it also strikes at the heart of data privacy in arguably its most intimate form: the right to not be seen naked.

It’s a powerful metaphor, as AI’s infiltration of the digital landscape now allows enterprises to collect and analyze personal data at unprecedented scale. That has put increasing pressure on privacy professionals, who are already overstressed and—in the past year—significantly understaffed, as a new ISACA survey revealed this month. It also leaves consumers and enterprise leaders having to grapple with the risks of AI tools and models baring their personal data—be it our bank, health, or location info, purchasing history, and now our bodies (or in the case of Grok, someone else’s body with our head tacked on top).

The problem of data protection isn’t new, but it’s been hard to grasp, and most consumers have just thrown up their hands when they hear of the ways stolen data winds up on black market sites to be bought and sold by criminal cyber gangs. Grok’s “spicy mode,” an explicit-content setting that enables anyone to create pornographic images of you, your spouse, or your kid, and put them on everyone’s phone, presents the dangers in a glaring, graphic new light. And it prompts a question: Will this move the needle, urging consumers and enterprise leaders to take data privacy more seriously?

National Cybersecurity Alliance executive director Lisa Plaggemier sounded hopeful yesterday in a webinar to mark the start of Data Privacy Week, an international effort to bring attention to digital privacy concerns. “Every day we generate enormous amounts of data—our locations, our habits, our conversations, our faces”—and here she raised her eyebrows and gave a slight smile to the camera—"our voices,” she said. Whether the issue is data that’s collected carelessly, stored indefinitely, or used in ways we never intended, she thinks the view on privacy is changing. “[It’s] no longer just about secrecy—it’s about agency.”

Others aren’t so sure.

“While I hope enterprises that deploy direct-to-consumer AI systems, like Grok, begin to think more about privacy, I don’t know that those leveraging AI in other ways will [do so],” says Safia Kazi, a privacy expert and principal research analyst at ISACA, a leading global IT certification and training nonprofit dedicated to promoting digital trust. “They may feel that because they don’t offer image generation, they are immune from people abusing their AI systems,” she said.

[Listen also: ISACA’s Safia Kazi discussed the wave of fines and PR damage coming to brands in our podcast episode, “Why it pays to take data privacy seriously”]

ISACA, formerly known as the Information Systems Audit and Control Association, issues a new “State of Privacy” report annually. The group has tracked slight dips in privacy staff size, but a one-third drop in 2025—from a median of eight staffers to five—got their attention. It’s by far the greatest decline in their six years of running the survey, Kazi noted.

Kazi actually sat down with Focal Point last week to discuss key findings in the report, which in the fall surveyed more than 1,800 data privacy officers (DPOs) and other data protection leaders from around the globe. We asked her to focus on these five key charts.

Key takeaways

1. Boards support privacy—but for the wrong reason

Board view of privacy programs: Do you think your board of directors views your enterprise’s privacy program as:

Source: ISACA 2026 State of Privacy

A slight majority of respondents (56%) said their board of directors adequately prioritized privacy, but when Kazi looks at the specific motivations that drive boards’ privacy programs—41% say compliance is the driving factor, the strongest motivator by far—she sees a problem.

Compliance as your end-all be-all goal is a really bad goal.
Safia Kazi, principal research analyst-privacy, ISACA

Compliance as your end-all be-all goal is a really bad goal,” she said. Compliance is tricky, because the rules vary from region to region and frequently change. Trying to anchor an organization’s privacy policy to such fluctuating guideposts is like trying to moor your boat to a moving dock.

The stronger, more stable option is privacy by design, a way of building privacy controls into the earliest stages of system or application development. “Then it’s a value-add,” she said, “something that potentially distinguishes you from your competitors and, in that way, becomes more integral to the enterprise overall.”

[Read also: The ultimate guide to IT risk and compliance management]

Signal, for example, has faced this challenge, as the private messaging service competes for market share, weighing possible new features that consumers get at Slack or other brands that offer messaging, things like search functions and the ability to take screenshots of text chains. In both cases, they decided the risks to privacy were too great, said Udbhav Tiwari, Signal’s vice president of strategy and global affairs, in a webinar hosted by the National Cybersecurity Alliance on Monday.

“At Signal, people have expectations of trust—you hope that Signal will do everything in its power to protect that message,” he said.

2. AI use for privacy—the pros and ‘pause’

Using AI for privacy tasks: What are your organization’s plans to use AI (such as machine learning) to perform any privacy-related tasks?

Source: ISACA 2026 State of Privacy

Like most of us, privacy pros are curious about how AI can enhance their job performance, with 38% noting their workplace plans to use AI (like bots and machine learning) for data privacy tasks in the coming year. That’s up from 36% in 2025 and 28% in 2024. And yet the number of orgs actually doing so is rather low (just 13%).

Data privacy is expanding into a complex ecosystem that many organizations are scrambling to understand and govern—and fear of the unknown can bring pause.
Melissa Bischoping, senior director of security and product design research, Tanium

Kazi finds this curious. She suspects respondents may be thinking of sanctioned uses of AI and forgetting about the rapid rise of shadow AI at the workplace. Or they may be cautious about using headliner forms of AI—think vibe-coding apps like Lovable and Claude—but forget about the “more mundane, less glitzy” types, like recommendation algorithms or systems that flag personally identifiable information (PII) collected from customers.

Or maybe, as some experts suggest, it’s simpler than that.

“As AI agents and workflows become an undeniable part of the modern enterprise, data privacy is expanding into a complex ecosystem that many organizations are scrambling to understand and govern—and fear of the unknown can bring pause,” said Melissa Bischoping, senior director of security and product design research at Tanium, a leading innovator in cybersecurity solutions and autonomous IT (and publisher of this magazine).

Yes, the spirit of innovation is fueling many technologists, driving them to build, adopt, and integrate agentic AI, she acknowledged. But privacy specialists have a unique perspective on data.

[Read also: Melissa Bischoping’s 7 ways to defend your software supply chain]

“While AI has given us unprecedented ability to execute sophisticated workflows at speed and scale, if ungoverned and unchecked, it can introduce unprecedented risk and loss of data at that same scale,” said Bischoping. And who better than a privacy specialist, whose prime focus is safeguarding data, to appreciate that?

No matter the reason for this reticence, AI use is no magic bullet.

“Having AI does not mean your board's going to prioritize privacy, and it won’t make it easier to do privacy by design,” she said. As a technological solution, AI certainly has its benefits, “but it's not going to give you more staff or more leadership buy-in.”

3. Privacy by design—one project at a time

Privacy by design frequency: How often does your enterprise practice privacy by design?

Source: ISACA 2026 State of Privacy

As enterprises explore AI’s possibilities, creating a host of new AI models, the practice of integrating privacy into the entire engineering process—aka privacy by design—is more important than ever. It’s the most reliable way to ensure data privacy, and in some cases may be required by applicable privacy laws and regulations. The EU’s AI Act, for one, promotes privacy by design initiatives.

Despite this, the number of respondents who say their organizations always or frequently practice privacy by design has been waning, from 63% in 2024 to 62% in 2025 down to 58% in this latest survey.

What accounts for the steady decline? Shrinking staff sizes, especially this year, seems “the most likely culprit,” said Kazi.

The survey finds—no surprise—that larger enterprises with bigger budgets are more likely to engage in this practice than small-to-midsize outfits. An interesting callout finds that close to half (41%) of those who currently use AI for privacy tasks always practice privacy by design. The ISACA report posits that a portion of this AI use may actually leverage privacy by design and can in turn help preserve privacy.

As for those struggling with funding or head count, the lack of necessary resources does not rule out such initiatives, Kazi assured. Her pro tip: Take it project by project.

“Look at the data and figure out which particular projects would benefit the most from privacy by design,” she said. “Maybe your marketing team is working on a new newsletter—that’s probably less of a priority compared to a new customer database. So maybe that's where you focus your efforts, to maximize limited resources.”

4. The surprising upside of privacy budget cuts

Budget forecasts: How, if any, will your organization's privacy budget change in the next 12 months?

Source: ISACA 2026 State of Privacy

Anxiety over anticipated budget cuts has been on the rise for several years, with half of respondents expecting to see a slight or significant decrease in privacy funding over the coming year compared to 8% who shared that forecast in 2023. Similarly, expectations of greater funding have dropped off.

And yet the actual story is somewhat rosier.

“The fears are not lining up with what we're actually seeing,” Kazi said. Actual budget cuts are not as great as what people feared they’d be the year before. At the start of last year, for instance, 48% of respondents expected to see some or significant decreases in funding in 2025; in the current survey, only 12% experienced budget cuts in that year.

[Read also: What we’re seeing for 2026—11 cybersecurity predictions (and how to prepare)]

“It's hard to look at any news site and not see how major organizations are cutting back, so I understand where the anxiety is coming from,” said Kazi. Though she finds it curious that they don’t see the same level of fear about budget cuts among security leaders surveyed in their “State of Cybersecurity” report, released in the fall.

5. Privacy training tips—what to watch for

Privacy awareness training: When does your organization provide privacy training?

Source: ISACA 2026 State of Privacy

While 79% of respondents reported their organization provided privacy awareness training, the when varied, with the most common timeframes being annual testing (three-quarters) and training at hiring (more than half).

Privacy concepts, things like understanding consent and how to use data and what’s considered personal information [are] not really in the scope of security training.
Kazi

And most felt good about the training, which contrasts with a growing number of security researchers and chief information security officers, who are finding that traditional forms of staff security training just aren’t cutting it. In ISACA’s survey, 82% felt their privacy training had a strong or moderate positive impact on actual privacy awareness.

Security training is not the same as privacy training. Companies cannot have privacy without good security practices in place, but it's possible to do security well and not necessarily practice privacy, Kazi suggested.

“Let's say you have amazing security awareness training, and you have a marketing team who will never click on a phishing e-mail,” she said. “They know all the signs; you’re not going to trick them. But they don't necessarily know specific privacy concepts, things like understanding consent and how to use data and what’s considered personal information. That’s not really in the scope of security training.”

If an enterprise wants to combine security and privacy awareness training, that’s fine, she said, as long as they make sure privacy concepts are actually covered.

WEBINARS WORTH WATCHING

Data Privacy Week, an international effort to raise awareness of data protection issues, runs through Friday. To mark the annual event, the National Cybersecurity Alliance (NCA) is hosting a series of free webinars designed to help educate founders, business executives, public-sector leaders, and consumers. For more info, check out the following links.

  • Children’s privacy in a digital world (TUE, Jan 27, 2026, 2:30 p.m. EST)—Dr. Lorrie Cranor, director of the CyLab Security and Privacy Institute at Carnegie Mellon University, joins NCA executive director Lisa Plaggemier to discuss the unique privacy challenges—including age verification and school tools—facing kids, teens, parents, and educators as technology becomes woven into learning, communication, and self-expression.
  • Privacy law made simple (WED, Jan 28, 2026, 1:00 p.m. EST)—Justine Phillips, a data and privacy attorney at Baker McKenzie, will break down the current privacy law landscape in clear, practical terms, from your rights to access or delete personal data to the ways companies must handle and secure the data they collect. She’ll also explore new laws emerging across the country, and how to take advantage of protections already available.
  • Dynamic pricing: When algorithms set the cost (THU, Jan 29, 2026, 1:00 p.m. EST)—Experts will explore the growing new realm of dynamic pricing, from its fairness and transparency to the ways your personal data is now used to decide what you pay for airline tickets, ride-share fares, online shopping, and more.
  • The right to be forgotten: Deleting your online data (FRI, Jan 30, 2026, 1:00 p.m. EST)—Lawrence Gentilello, founder of the personal data removal platform Optery, and CalPrivacy executive director Tom Kemp explain the “right to be forgotten,” a legal concept that allows you to request the deletion of your data from websites, apps, and search engines. They’ll also outline simple steps to reduce your digital footprint and better protect your personal information.