AI Has Figured Your Customers Out — But Now They're Starting to Fear You
A 2024 PRISMA review in Cogent Business & Management identifies four AI marketing risks—cyberattacks, health data abuse, gray-zone sharing, information fabrication—and four solutions: data insurance, RFID/HITAM, multilateral security, and policy and ethics frameworks.
A couple of days ago, a friend who runs an e-commerce business complained to me.
He said they'd plugged in an AI marketing system. Three weeks in, the customer profiles it produced were scary-accurate — which user had been browsing what, what time of day they were most likely to place an order, what they were still hesitating over. The system handed all of it to him on a plate.
When he said this, his eyes were lit up.
After he finished, I asked him one question: do your customers know you're holding all this?
He froze.
That image, to me, is a question every corner of the marketing world is going to have to sit down and think seriously about in 2026. AI has pushed "understanding the customer" to a precision that was simply impossible before — but at the same time, it has quietly stepped over a line you were never supposed to cross.
That line is called data security and privacy.
First, Let's Do the Math: What Is AI Marketing Really Trading Away for Efficiency?
The core move of AI marketing, stripped bare, comes down to one thing: feed it massive amounts of customer data, and it helps you segment more precisely, target more accurately, and sell more.
Customer segmentation, predicting who's about to buy, real-time chat recommendations, personalized ad placement — these used to be done by hand, by grinders. Now AI slices them up for you in seconds.
Sounds beautiful, right?
But think about it — the more accurate the AI, the more customer data you're holding, and the finer and more sensitive that data becomes. Browsing histories, spending habits, location trails, even health data — that whole universe coming off the smartwatch — all of it gets fed in.
More data, stronger AI. But that sentence runs in reverse too: more data, the heavier the fallout when something goes wrong.
In 2024, a study published in Cogent Business & Management laid this out in painstaking detail. It isn't some clickbait article from a media outlet — it's a systematic literature review done to the PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) standard, scanning a full decade of relevant research from 2014 to 2024.
The conclusions it reaches are worth every person using AI for marketing sitting down and reading carefully.
Four Troubles That'll Keep You Up at Night
The study sorts the privacy and security risks of AI marketing into four big categories. Let me walk you through them one by one.
The first: cyberattacks.
Phishing emails, credential stuffing, breaching marketing databases — these aren't new words, but AI has cranked their lethality up a notch. What's stored in a marketing database? Customers' financial information, browsing histories, spending preferences. The moment that database is exfiltrated and the data changes hands on the black market, your customers' trust in you flatlines with it.
The second: the abuse of health data.
This is the one most easily overlooked — and the most sensitive.
Fitness trackers and health-monitoring devices are collecting your heart rate, your sleep, your movement trails twenty-four hours a day. This data was supposed to help you manage your own body. But the moment it flows into a marketing system, it gets turned into precision advertising — repeatedly pushing coupons for high-sodium foods at someone with a tendency toward high blood pressure.
This isn't "precision marketing" anymore. This is exploitation.
Identity theft, insurance fraud, medical scams — they can all slip in through this crack.
The third: the gray zone of data sharing.
Data partnerships are in fashion right now — Company A and Company B swap customer profiles and call it "building an ecosystem together."
Sounds very modern.
But have you ever thought about it — once your data walks out Company A's door and into Company B's system, you have absolutely no idea who it'll be passed on to next, where it'll be used, or what kind of people will see it. That line of tiny print in the consent terms that nobody finishes reading is the only lock on that door.
The fourth: information fabrication.
AI doesn't just analyze data — it can also manufacture data.
Fake reviews, fake word-of-mouth, fake user experiences, looking exactly like the real thing. One forged five-star review can hoist a terrible product up to the sky; one fabricated "personal experience" can drive a competitor straight into the ground.
Consumers get misled, the market gets distorted, and the businesses playing it straight end up taking the hit.

How Does This Bill Come Due on the Company's Head?
These four troubles sound like "technical problems" or "compliance problems."
But there's one line in the study that left a deep impression on me: these concerns aren't just about stepping on some regulation — they strike directly at the company's economic ledger.
How do they strike?
Customers stop trusting you, and the repeat-purchase rate slides downhill. Regulators drop fines that routinely run into the tens of millions. Once brand reputation is broken, you couldn't buy it back with ten times the money. Investors take one look at your chaotic data governance and they don't dare put their money in either.
The efficiency gains from AI marketing could end up wiped out, line by line, by these hidden costs.
That's why this can't wait any longer.
So What Do We Do? The Study Lays Out Four Paths
What's interesting about this review is that it doesn't just list problems — it also systematically lays out the solutions the academic world has proposed over the past decade. Boiled down, four paths.
The first: take out an "insurance policy" on customer data.
This is a fairly counterintuitive idea.
It's not a technical solution — it's a financial one. The idea is, the company buys an insurance policy on its customer data: once there's a leak, the customer can get a payout, and the company's financial risk gets dispersed along with it.
The clever part is this: in order to avoid paying out, the insurance company will turn around and force you to make your data security solid. One market-driven mechanism does more than a hundred slogans ever could.
The second: hard technical chops — RFID and HITAM.
RFID (radio-frequency identification) was originally used in logistics and supply chains. The study mentions that combining it with encryption and identity authentication can dramatically boost the data security of health-monitoring devices.
HITAM (Health Information Technology Acceptance Model) is, plainly, a model for studying whether users are willing to use these security technologies. No matter how advanced the tech is, if users can't figure it out or are afraid to use it, it adds up to zero. HITAM helps you build security features that people can actually pick up and are willing to trust.
The third: the boss has to step in personally — multilateral security mechanisms.
This is the one I most want to emphasize.
The study says plainly that top-management support and firm size are the two key variables determining whether data security can actually get off the ground.
Why?
Because data security is never just the IT department's business. It pulls in legal, product, operations, customer service — every department holds customer data of its own, and every department's security standards are different.
If the CEO doesn't personally call the shots and put this on the strategic agenda, the departments will just push responsibility back and forth, and the holes stay right where they are, with nobody owning up.
The so-called "multilateral security mechanism" means putting all the relevant departments' security needs on one table — assessing them together, setting standards together, carrying the responsibility together. How encryption gets done, who can access what, how often audits happen, who's on the hook when something blows up — all of it written out in black and white.
The bigger the company and the more data it holds, the more this mechanism has to be in place. Otherwise, scale isn't an advantage — it's a landmine.
The fourth: the rules have to be set — policy and regulatory frameworks.
GDPR, CCPA — you've probably heard these names. Europe's General Data Protection Regulation, California's consumer privacy law — both regulations that have kept the global tech industry on the ropes these past couple of years.
The study specifically points out that for cloud services, cashless payments, and cross-company data sharing, there have to be customized privacy policies — where data is stored, who can call it up, how long it's kept, how it gets anonymized — all of it nailed down in writing.
What's more interesting is that it also brings up an ethical framework. Mere compliance isn't enough; you have to talk ethics too. In industries like travel and hospitality that deal directly with consumers (B2C), whoever is transparent about their data practices, willing to take responsibility, and respectful of user consent can turn "trust" into a competitive moat.

A Choice You Can't Dodge
After finishing this study, I gathered up what was in my head and want to give you the plainest judgment I can.
In the AI marketing battle, the ones who win in the short term are the ones who know how to use AI; the ones who win in the long term are the ones who use AI without incidents.
Not having incidents doesn't depend on luck — it depends on whether you're willing, outside that efficiency line, to draw a second line for security and trust.
Where do you draw that line?
The study gives a checklist of five variables: relative advantage, technological readiness, top-management support, firm size, government regulation. Take these five, hold them up against your own company's current state, and score them one by one — you'll get a rough sense of where you stand.
There's no standard answer. Every company using AI for marketing is, sooner or later, going to have to turn in its own answer sheet.
Finally
My e-commerce friend, after hearing me talk through all of this, went silent for a moment.
Then he asked me: so what do I do now?
I said, go back and do one thing — take stock of exactly what customer data you're actually holding, where it's stored, who can see it, and whether there's any way it could leak. Audit it first.
If you can't even take stock of it, don't talk about AI.
A person who doesn't even know what they're holding in their hands has no right to talk about efficiency.
This study was published in 2024 in Cogent Business & Management. The method is solid, and the conclusions are restrained. It doesn't hand you a universal formula, but it lays the problems out clearly and paves the path the academic world has felt out over the past decade in a very practical way.
It belongs on the desk of every head of marketing.
As for how to draw that red line, it's different for every company. But this question — you can't leave it unanswered.