The CPG Industry Is Sitting on a Contract That Says No to AI
Every major CPG brand pays six figures a year for the data that runs their category strategy. Most of them are also, technically, not allowed to run AI on it.
That is not a hypothetical compliance risk. It is written into the license.
The landscape: CPG is racing into AI everywhere except here
CPG is not an industry hesitating on AI. By most measures, it is moving faster than almost anyone else. According to Vention's 2026 tracking, 89% of retail and CPG companies are actively using AI technologies or running pilot projects, and 51% of those companies apply AI across six or more use cases already. NVIDIA's State of AI in Retail and CPG report puts CPG's agentic AI adoption rate at 47%, second only to telecommunications industry-wide.
And yet Deloitte's 2026 executive survey of 200 CPG and retail leaders found a sharp say-do gap sitting underneath that activity: 75% call AI a top strategic priority, but only 16.5% can actually quantify a return on it. Adoption outside IT never exceeds 36%. CPG's AI investment, per Deloitte, remains largely operational rather than converting into measurable revenue growth, in contrast to retail, where it increasingly does. Governance lags further still: Vention's data shows only about 20% of organizations have a mature framework for managing AI agents at all.
Category management, the function that decides what stays on shelf, what gets more facing, and what gets cut, sits close to the center of that gap. It is one of the most data-intensive, highest-stakes functions in a CPG business, and it is also one of the least AI-enabled, for a reason that rarely gets named directly.
How category management actually works today
Category managers run on syndicated retail data from three providers: NielsenIQ, Circana, and SPINS. Retailers report point-of-sale scan data to these providers, who aggregate it across thousands of stores, normalize it into a shared structure, and resell access as a subscription. A single brand's license typically runs $75,000 to $500,000 or more a year, depending on categories and channels covered.
What that money buys is a weekly picture of units sold, dollar sales, and price, broken out by retailer, geography, and time. What it does not buy is speed. The data lands on a four-week cycle. By the time it reaches an analyst, competitors have often already changed prices, run a promotion, or shifted shelf position.
Turning that data into an actual category review is still largely manual. Analysts pull syndicated exports, reconcile them against retailer-specific portals that use different product hierarchies and calendars, rebuild the result in Excel, and present it in PowerPoint. Industry sources describing this workflow consistently land on the same range: a full category review takes four to six weeks. One documented example, a trade marketing team working across 33 retail channels, found they were spending up to 60% of their total time just harmonizing data across sources, before any actual analysis began.
The result, as one industry description puts it plainly: when a retailer asks why a brand deserves more shelf space, the honest answer is often a story, not a number.
The part almost nobody outside the category talks about
Here is the detail that changes the shape of this problem entirely. NielsenIQ's own license terms state directly that AI use "alongside NIQ Services or Content" is prohibited, and that any GenAI tool that does touch the data must run in a secure, private, enterprise-grade environment that prevents data leakage and maintains confidentiality. Circana's terms similarly restrict the data to internal use and prohibit external redistribution.
This is not a vague privacy concern. It is a specific, written contractual term attached to a license that can cost a brand half a million dollars a year. A category manager who pastes a NielsenIQ export into a general AI tool to speed up an analysis is not taking a fuzzy reputational risk. They may be in direct breach of the agreement that gives their company access to the data at all.
That single fact helps explain Deloitte's say-do gap more precisely than a generic governance problem would. Category teams are not failing to quantify AI's ROI because they lack ambition. Many are structurally blocked from using AI on the one dataset their entire function is built around, unless it runs somewhere that cannot leak the data by design.
The people carrying this problem across multiple clients at once
Not every category manager works inside a single brand. A meaningful share of this work is done by category captains and category management consultancies, firms that manage category strategy across several CPG brands' data simultaneously, each brand's data under its own separate license, its own separate restrictions.
That is a familiar shape. It is the same structural problem a fractional CFO faces managing several clients' financials, or an underwriter reviewing submissions across multiple insureds: real, valuable, sensitive data, held under real contractual obligations, with a growing expectation that AI should be part of the workflow, and no clean way to do it without either ignoring the restriction or giving up on AI entirely.
How teams are actually handling this today
In practice, category teams are taking one of three paths right now, and it's worth being precise about each rather than treating them as interchangeable.
The first is the informal one: someone pastes an export into ChatGPT or Claude directly because the deadline is real and the restriction feels abstract. This is common, and it is the scenario NielsenIQ's and Circana's terms are written to prohibit outright.
The second is category-specific AI analytics platforms. Tellius, for example, connects directly to NielsenIQ, Circana, and Numerator through pre-built connectors, and uses AI agents to automate root-cause analysis, promotional measurement, and pricing-gap identification, collapsing work that used to take weeks into a single conversation. Crisp holds official partner status in NielsenIQ's own Connect Partner Network. These are real, credible tools solving a real problem, and they're worth naming plainly rather than waving off. What none of their public materials address, as far as we can find, is the specific architectural question this piece is about: whether the model doing the analysis ever receives the underlying syndicated values in a readable form. That may be handled through a separately negotiated data agreement, or it may simply not be the question their product was built to answer. Either way, it's a different claim than the one this article is making, and worth knowing the difference before assuming any AI-powered category tool has already solved it.
The third path is enterprise AI platforms like ChatGPT Enterprise or Claude Enterprise, which add audit logs, admin controls, and contractual retention promises. Those are real improvements over the consumer version. They still mean the model reads the data in the clear to do the analysis. The safeguards sit on top of that fact, not underneath it. (That distinction, a promise not to look versus an inability to look, is the subject of The Two Perils of AI Risk.)
Where this actually gets solved
The fix is not a smarter model, and it is not a better dashboard sitting on top of the same restricted data. It is an architecture where the model doing the analysis never receives the syndicated data in a form that could leak, satisfying the exact language NielsenIQ's own terms require: a secure, private environment that prevents data leakage by design rather than by policy.
Nera's ChatApp is built specifically for this shape of problem: category and retail analytics teams asking natural-language questions of licensed syndicated data, encrypted the entire time a frontier model is working with it, so the underlying values are never exposed to the model or to Nera. We are already working with a CPG brand on exactly this, applying it to real category and retail performance questions rather than a demo.
One honest note on the legal side of this. Clauses like NielsenIQ's exist to guard against a specific risk: data leaking to, or through, a third-party system. An architecture where that exposure structurally cannot happen removes the underlying risk those clauses were written to prevent, which may make the approval conversation with a data provider more straightforward, since there is meaningfully less to negotiate protections around. That is not a guarantee of any particular outcome. Data providers evaluate these arrangements on their own terms, and any adjustment to how a license treats a specific architecture is theirs to make, not something a vendor can promise on their behalf. But it is a fair, honest case to bring into that conversation, not a workaround to avoid having it.
What this actually unlocks, concretely
Here is what changes in practice, not in the abstract.
Today, a question like "why did this SKU underperform in this region over the last four weeks" triggers a full review cycle: pull the syndicated export, reconcile it against retailer portals, rebuild it in Excel, and come back with an answer in four to six weeks, by which point the competitive picture has already moved. With the data encrypted and a model working over it directly, that same question gets asked in a conversation and answered against this week's data, not last month's.
The same shift applies to the recurring questions category teams field constantly: what happened to velocity after the last price change, where is the assortment opportunity gap against a named competitor, which SKUs are underperforming ACV-weighted distribution relative to category average. These are exactly the questions a four-to-six-week cycle was never built to answer quickly, and they're exactly the questions a chat interface over the same licensed data can answer same-day.
The 60% of analyst time currently spent reconciling data before any real analysis starts is time that goes back to the analysis itself, and it's a direct, addressable path toward closing Deloitte's 16.5% ROI-quantification gap, since the question stops being "can we prove this helped" and starts being "here is the number, asked and answered this week."
For a category captain managing several brands at once, that compounds. The same safe, fast workflow applies across every client relationship, without any one brand's data touching another's, and without any single client's license restrictions becoming a blocker to using AI at all.
If this is your world
If your team is licensing NielsenIQ, Circana, or SPINS data and has been avoiding AI because of what the license actually says, or worse, using it anyway and hoping nobody checks, that is exactly the problem we built this to solve. It is live today, on real category and retail data, not a roadmap promise. See how it works for CPG and brand teams, or get in touch.
Rami Akeela, Ph.D., is Founder and CEO of Nera Systems, a confidential AI infrastructure company. He holds PhDs in Electrical Engineering (Santa Clara University) and Computer Engineering (Lehigh University), and has spent 20+ years in engineering and applied research, including founding DZK, the first company to build an FPGA-accelerated, end-to-end zero-knowledge proof system. Nera Systems builds confidential AI infrastructure for organizations that can't afford for their most sensitive data to be exposed to a model, a vendor, or each other. Get in touch to see it on your own data.