Paid commercial ChatGPT tiers, including ChatGPT Business, Enterprise, Edu, and Healthcare, include controls that reduce several enterprise data-handling risks, including excluding prompts from model training by default. Whether ChatGPT is safe for a particular business use still depends on the enterprise controls governing access, data sharing, and AI activity.
Those exclusions govern what OpenAI does with your data, not what your employees do with the tool. Whether a deployment is actually safe depends on the controls the enterprise puts around it, including who can access it, what data goes in, and whether security can see that activity at all.
On consumer accounts (Free, Go, Plus, Pro), default data sharing and stays on until the user switches it off in Data Controls. Nearly half of employees admit to breaking company policy, including pasting sensitive company information into free public tools like ChatGPT, and 57% say they hide that use and present AI-generated work as their own. Each unsanctioned prompt can place company data outside existing monitoring and retention controls, so as workforce AI adoption grows, enterprise controls need to cover that use.
This guide walks through what ChatGPT does with your data, the operational risks enterprises face, and a practical framework for making ChatGPT safe for business use.
Key takeaways
- The tier your employees are on decides what OpenAI does with their prompts. Paid commercial tiers keep prompts out of model training by default, while consumer accounts share them for training until someone turns the setting off.
- Those paid tiers carry the safeguards procurement and audit teams ask for, including SOC 2 Type 2 certification, single sign-on, encryption in transit and at rest, and audit-trail access through the Enterprise Compliance API.
- Shadow AI is usually the first place oversight fails. Nearly half of employees admit to using AI in ways that break company policy, and a domain-matched email doesn’t guarantee the account is governed.
- OpenAI’s controls govern its platform and services, while enterprises remain responsible for how employees and applications use AI, including the data they submit, the outputs they rely on, and their own governance and compliance obligations.
- Making ChatGPT safer for business use benefits from enterprise-side controls that complement provider safeguards. Depending on the environment, these can include AI discovery, intent-based policy enforcement, runtime protection of prompts and responses, governance of agent activity, and audit trails.
What ChatGPT actually does with your data
ChatGPT keeps your conversations, and on consumer plans it may use them to train future models. Paid business tiers exclude those conversations from training by default and hold them in a workspace your administrators control, so the subscription your employees sign into determines what happens to the data.
Training comes first because it is the difference employees create without meaning to. ChatGPT Business excludes conversations from training, and Enterprise, Edu, Healthcare, and Teachers tiers add administrative data controls on top of that. For API deployment, the API data policy has excluded training since March 1, 2023, without explicit opt-in consent. Consumer conversations are the exception, since they may be used to train OpenAI’s models by default.
Consumer plans are where most enterprise exposure sits. Employees on personal accounts, a core shadow AI scenario, are on consumer tiers where their inputs may be used to train future models, and the enterprise controls described below don’t cover that activity.
On eligible business tiers, those controls fall into four groups.
- Security and access. ChatGPT’s enterprise tiers include SOC 2 Type 2 certification, AES-256 encryption at rest, TLS 1.2+ in transit, SAML SSO, and Enterprise Key Management (EKM). Audit-trail access comes through the Enterprise Compliance API.
- Data residency and retention. Eligible tiers let you choose where conversation data is stored, which matters when local law restricts cross-border transfer. Residency options cover the U.S., Europe, UK, Japan, Canada, South Korea, Singapore, Australia, India, and UAE. Zero data retention (ZDR) goes further on eligible API endpoints, processing prompts without storing them at all.
- User lifecycle. SCIM-based automated user provisioning and deprovisioning is available on Enterprise, Edu, and Healthcare tiers. Deprovisioning is the control that determines whether access actually ends when someone leaves the company.
- Contractual coverage. OpenAI will sign a Business Associate Agreement for eligible tiers, though signing one starts the HIPAA work rather than finishing it. A Data Processing Addendum (DPA) is available for GDPR compliance.
Encryption, single sign-on, residency, provisioning, and contractual terms all govern activity inside OpenAI’s environment. You still need visibility into employee use, the data being shared, and activity that bypasses the enterprise tier.
Four ChatGPT risks that stay with your organization
Once ChatGPT is in employee hands, four operational risks tend to surface. They are shadow AI that escapes security oversight, prompt injection and account compromise, evolving A tier upgrade alone does not address the full enterprise governance problem. Organizations may still need controls around employee usage, runtime activity, data handling, and compliance that operate outside the model provider’s environment. Each risk below comes with the controls that reduce it.
1. Shadow AI hides employee AI use from security teams
Shadow AI is employee use of AI tools outside approved or governed enterprise workflows. With ChatGPT, one example is an employee using a personal consumer-tier account for work activity, potentially placing corporate data outside the organization’s intended governance controls.
Samsung is the case most security teams remember. In April 2023, engineers at Samsung’s semiconductor division pasted proprietary source code and confidential meeting notes into ChatGPT. The company banned generative AI on company-issued devices soon after and went on to build its own internal tool, Samsung Gauss.
The reason this keeps happening is that policy arrives after the behavior. Sixty-eight percent of organizations have leaked data through employees sharing sensitive information with AI tools, while only 23% have an AI security policy in place. A corporate email address is no guarantee either, because an employee can sign into a personal ChatGPT license with a domain-matched address and stay outside enterprise controls entirely.
Discovery is what changes the picture, since a policy can only govern the tools you already know your workforce is using.
2. Prompt injection and stolen credentials turn ChatGPT against its user
Two attacks put an outsider in control of an employee’s ChatGPT session. Prompt injection hides instructions inside content the model reads, so ChatGPT acts on an attacker’s intent instead of the user’s. Credential theft skips the model entirely and takes the account itself.
Injection has topped the OWASP Top 10 for LLM applications in both the 2023–2024 and 2025 editions. The hidden instructions don’t have to be human-readable, so they can sit in a web page, a document, or an image the model processes.
The ZombieAgent attack shows what that looks like in practice. Researchers turned ChatGPT into a persistent tool that exfiltrated a victim’s inbox and address book with no interaction from the victim at all.
Model-provider defenses are one part of the control stack, but enterprises also need to manage how AI is accessed and used within their own environment. Prompt injection and credential compromise can therefore require controls beyond the model itself. OpenAI has said injection is unlikely to ever be fully solved and that agent mode in ChatGPT Atlas expands the threat surface. On the credential side, infostealers had captured 300,000 ChatGPT logins by February 2026. One stolen login exposes conversation history, connected services, and everything an employee has already shared with the model.
Both problems can surface during live AI use, making runtime controls an important part of a broader security strategy alongside identity, access, and provider-side protections.
3. AI regulations set deployment obligations
AI regulations now split obligations between the companies that build models and the companies that deploy them. As a deployer, what you increasingly have to produce is evidence that your own policies are enforced.
Italy’s data protection authority showed how that scrutiny arrives. It fined OpenAI €15 million in November 2024, and the Court of Rome annulled the penalty in March 2026, but the case put a national regulator inside the question of how a general-purpose model handles personal data.
The binding obligations are already live. Under the EU AI Act, GPAI rules and penalty provisions became applicable on August 2, 2025, with full Commission enforcement powers over model providers following on August 2, 2026. Financial institutions have a second layer, since DORA requires third-party ICT risk management, incident reporting, and resilience testing for the vendors they depend on. In the U.S., the NIST AI Risk Management Framework and its Generative AI Profile give teams a common structure for documenting all of it.
What these regimes have in common is that they ask for records, not intentions, which means enforcement has to be logged as it happens.
4. ChatGPT hallucinations create business liability
A hallucination is a confident but fabricated or inaccurate output, and organizations deploying AI can face business, regulatory, or legal exposure when those outputs are relied upon.
The Air Canada ruling in February 2024 settled the question. A tribunal rejected the airline’s argument that its chatbot was a separate legal entity, holding the company to a bereavement fare policy the bot had invented.
This is not an isolated category of error. The Hallucination Database maintained by Damien Charlotin tracks 1,922 cases across more than 30 countries through August 2026, with 1,313 in the United States alone. Suing the model provider instead is difficult, as Walters v. OpenAI showed when a Georgia court granted OpenAI summary judgment in May 2025 and raised the plaintiff’s burden against AI companies. Organizations deploying AI should assume responsibility for validating outputs used in consequential business processes and should account for potential legal and operational exposure.
Catching a fabrication means reviewing an output before it reaches a customer or triggers an automated action.
How to make ChatGPT safe for business use
Because pre-deployment evaluations are limited and AI often behaves differently in production, effective AI risk management relies on enterprise-side controls that operate at runtime across the tiers and tools your workforce uses.
1. Discover AI usage before writing policies
Start with network-level discovery before drafting any AI-use policy, covering browsers, native apps, and IDEs. A policy built on an assumed inventory governs the tools you expected your workforce to use, not the ones they actually opened.
2. Enforce intent-based policies
Move beyond relying solely on keyword- and regex-based DLP by adding intent-based classification and more contextual policy controls. Depending on the implementation, responses can include:
- Allow legitimate use that fits policy and business purpose.
- Warn employees when a prompt approaches a policy boundary.
- Block clear violations before the prompt reaches the model.
- Route sensitive queries to approved models based on policy, or apply data-protection controls such as tokenization before sensitive data reaches the model.
Sensitive data tends to surface in ordinary requests rather than obvious violations, which is why classification has to read intent instead of matching keywords.
3. Inspect model outputs and agent actions at runtime
Apply runtime controls to prompts and responses where appropriate to detect policy violations, harmful or unwanted outputs, and AI-specific threats before downstream use. For agentic applications, additional controls may be required at the agent and tool-execution layer. OpenAI retains API inputs and outputs for up to 30 days, so enterprise-layer runtime inspection should operate independently of that window.
4. Set controls for AI agents
Agentic AI expands the governance surface beyond prompts and responses. Inventory agentic activity and, where the architecture permits, correlate agent activity with the human identity that initiated it. Organizations should also understand which tools and MCP servers agents can access and apply policy at those control points.
Agents also make indirect prompt injection more dangerous, because an agent can act on hidden instructions with no person reviewing the step. OWASP catalogues that pattern under prompt injection, cross-referenced with MITRE ATLAS entries AML.T0051.000 and AML.T0051.001.
5. Build audit infrastructure that proves compliance
You need evidence that your enterprise AI policy is enforced. Audit trails covering governed AI interactions and agent activity can provide evidence that enterprise policies are being applied. OpenAI’s Enterprise Compliance API covers activity within its supported environment; enterprise-side controls can extend auditability across additional sanctioned and unsanctioned AI use that falls within their deployment coverage.
How WitnessAI closes the ChatGPT visibility and control gap
OpenAI provides security controls for its platform, while enterprises remain responsible for governing how their workforce, applications, and agents use AI. WitnessAI is the confidence layer for enterprise AI, providing a unified AI security and governance platform that helps organizations observe, control, and protect AI activity across supported environments:
- Observe provides network-level discovery of AI activity across supported environments, including browsers, native applications, Windows Copilot, IDEs, and agentic surfaces such as ChatGPT.
- Control Control applies intent-based policies across supported human and agentic AI activity, with policy actions that can include allow, warn, block, and intelligent routing depending on the deployment and use case.
- Protect provides bidirectional runtime protection for supported AI interactions, including data-protection controls that can tokenize sensitive information before it reaches a model. For custom agentic applications, pre-execution and response protection can be integrated through lightweight APIs.
Consider a developer pasting proprietary source code into a personal ChatGPT account to debug a build issue. Keyword- or regex-based DLP may miss the risk when sensitive information is meaningful only in conversational or business context. An AI-native policy approach can evaluate the interaction’s intent and context alongside data-protection signals, then apply a policy response appropriate to the organization’s rules.
Turning ChatGPT from a governance question into a business capability
Enterprise AI adoption is accelerating whether governance infrastructure is ready or not. Doing that well means seeing which AI tools your workforce opened, applying policy while people work rather than after an incident, and holding evidence of both.
WitnessAI is the confidence layer for enterprise AI. Observe provides network-level visibility into supported AI activity, Control applies intent-based governance across human and agentic use, and Protect provides runtime security for models, applications, and agents through network integration or lightweight APIs, depending on the use case.
Start by inventorying the AI tools your workforce actually uses, then test intent-based policies against approved use cases before wider rollout. When you’re ready to see how discovery, policy enforcement, and runtime inspection come together across ChatGPT and every other AI tool your workforce touches, book a demo.