Privacy policies for large language models (LLMs) — the advanced AI systems that power chatbots and other AI tools — are often written in complex language that makes them difficult to understand. A recent study by cybersecurity firm Bridewell found that the average privacy policy for 20 popular LLMs is around 4,603 words long and takes about 20 minutes to read. However, the real challenge isn’t just the length but the complexity of the language used. Using a readability measure called the Flesch Reading Ease Score, the study found that these documents average a score of 40.2, which is well below the 60-point threshold considered easy to read. This means most people would struggle to fully understand what the policies are saying. One example of an especially lengthy policy is that of Meta’s Muse Spark, which has a privacy document of over 14,000 words — nearly an hour’s worth of reading. Bridewell’s research also found that 13 of the 20 LLMs use user inputs and outputs to train their models. While some of these systems allow users to opt out of having their data used for training, others do not. Even when an opt-out option is available, the process for doing so is often unclear or buried within the policy. Chris Linnell, Associate Director of Data Privacy at Bridewell, emphasized the importance of users understanding how their data is being handled by LLMs. He said that businesses need to have clear internal guidelines on what information can and cannot be shared with these AI systems. Employees, in particular, may unknowingly share sensitive or confidential data that could later be used to train LLMs, posing potential risks to privacy and security. The study highlights a growing concern as more people interact with AI-powered tools in both personal and professional settings. As the use of LLMs continues to expand, the need for more transparent and user-friendly privacy policies becomes increasingly important to protect individuals and organizations from unintended data exposure.