TL;DR: 35% of tested iOS apps failed to disclose collected data, 97% lacked required third-party SDK privacy manifests, and 18% of 183,000 mobile apps used AI, creating hidden data-flow, consent, and compliance risk across mobile ecosystems, according to NowSecure. The governance gap is not visibility alone but accountability for what apps, SDKs, and AI endpoints actually transmit.
NHIMG editorial — based on content published by NowSecure: mobile app privacy risk, AI data flows, and privacy governance findings
By the numbers:
- 35% of the iOS apps failed to disclose the data they collected.
- 18% (33,396 apps) use artificial intelligence and 3,541 send data to AI endpoints.
Questions worth separating out
Q: How should security teams govern mobile apps that now include AI features?
A: Treat AI-enabled app functions as separate governed paths, not as ordinary code changes.
Q: Why do mobile privacy disclosures fail to reduce risk on their own?
A: Disclosures describe intent, but they do not prove runtime behaviour.
Q: What breaks when mobile apps request more permissions than they need?
A: Excess permissions create persistent access to sensitive device functions and files, which expands collection beyond the user’s expectations and the organisation’s approved use case.
Practitioner guidance
- Inventory mobile apps, SDKs, and AI endpoints as governed data recipients Create a live inventory that ties each mobile app to its third-party SDKs, backend services, trackers, and AI endpoints.
- Map dangerous permissions to explicit business justification Require owners to document why an app needs camera, microphone, location, storage, or messaging access, then compare that justification to actual runtime behaviour.
- Validate privacy disclosures against runtime network flows Do not rely on app-store declarations alone.
What's in the full report
NowSecure's full article covers the operational detail this post intentionally leaves for the source:
- The mobile app privacy testing workflow used across more than 4 million public apps.
- The specific privacy and compliance checks used to flag missing manifests, disclosures, and unsafe SDK behaviour.
- The detailed breakdown of mobile app privacy risk across iOS, Android, and AI-connected endpoints.
- The vendor's automated privacy governance capabilities for teams that need implementation detail.
👉 Read NowSecure's analysis of mobile app privacy risk and AI data exposure →
Mobile app privacy risk blind spots: are your controls keeping up?
Explore further
Mobile privacy blind spots are now an identity governance problem as much as a disclosure problem. The article shows that apps, SDKs, and AI endpoints are all participating in decisions about sensitive data flow, yet most enterprises still govern them separately. That gap matters because identity governance is not only about people and service accounts, but also about who or what is authorised to receive data. The practitioner conclusion is straightforward: mobile privacy controls must be tied to access governance, not left in a separate privacy workflow.
A question worth separating out:
Q: Which teams are accountable when a mobile app shares personal data with third parties?
A: Accountability is shared, but ownership must be explicit. Product, privacy, security, and app governance teams all need a defined approval and evidence chain. If third-party sharing is not reviewed and logged, the enterprise remains responsible for the disclosure and its regulatory consequences.
👉 Read our full editorial: Mobile app privacy risk is now a governance problem, not just a compliance one