Skip to content
AZGARD
security

Is ChatGPT safe for company data in the US? The account decides

Is ChatGPT safe for company data? The account tier sets training, retention and whether a BAA is on offer. A US boundary for what may cross.

Angus McDonald · 25 Aug 2026 · 14 min read

written for United States ● also for Australia, United Kingdom, Canada, New Zealand

Is ChatGPT safe for company data in the US? The account decides

ChatGPT is safe for company data on the tier you are contracted on, and unsafe on the one nobody bought. The same model behaves as three different products depending on the account reaching it: a personal consumer account on free, Plus or Pro, a paid business subscription, or a contracted workspace or API under a signed agreement. The Azgard AI Data Boundary matches four classes of company data to those three tiers. The tier decides the answer.

Why "is ChatGPT safe for company data" is the wrong question

The question "is ChatGPT safe for company data" treats safety as a property of the model. It is a property of the account. One model reached through three accounts produces three different sets of published facts about training, retention, human review, admin visibility, and whether the vendor will sign a processor agreement.

The Azgard AI Data Boundary rests on one fact: the model does not decide what happens to your data, the account does. Name the tier you are on, read three lines of that tier's published terms - training, retention, human review - and match them against the most sensitive class of data you intend to paste. If you cannot name the tier, you are on the consumer one.

The commonest AI account in a US small business is somebody's personal Plus subscription they expensed, and its owner would tell you they are on a paid plan.

The three AI account tiers, and what each one's published terms say about your data

AI account tiers come in three shapes, and the vendors' published terms split along the same lines. The rows below are OpenAI's.

The BAA row is the fact most US buyers get wrong. The paid business subscription gets you out of training but not into HIPAA, and only the contracted tier can be covered.

What separates a consumer account from a contracted one is a clause, not a setting. OpenAI's Services Agreement, section 4.2: "OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use." Microsoft says the same of Microsoft 365 Copilot, that prompts and responses are not used to train foundation models, then in the same document that admins can search and retain them through Purview. Contracted does not mean invisible. It leaves the conversations visible to your own administrators instead of to a training pipeline.

Claude splits along the same seam. Anthropic may use consumer chats to improve the model where you allow it, while business data on a commercial plan sits under zero data retention, which Anthropic scopes to eligible APIs, Commercial organization API keys and Claude Code on Enterprise plans.

The Azgard AI Data Boundary: which class of data may cross which tier

The Azgard AI Data Boundary is a grid: four classes of company data down the side, three account tiers across the top, and one question in every cell. May this cross?

Azgard AI Data Boundary: class of company dataPersonal consumer accountPaid business subscriptionContracted workspace or API
Public or already published: website copy, brochures, published pricesCrossesCrossesCrosses
Internal operational: drafts, process notes, job data carrying no personal informationDoes not crossCrossesCrosses
Personal information about customers or staffDoes not crossCrosses with the data processing agreement in forceCrosses
Client-confidential or regulated: PHI, GLBA customer information, matters under bar rules, or anything you hold under an NDADoes not crossRegulated: does not cross, no BAA on this tier. Confidential under contract: crosses only if that contract allows a service providerCrosses once the sector agreement is signed, or where the contract allows it

The fourth class, client-confidential or regulated data, carries two sources of obligation over the same material, and they behave differently. A statutory duty waits for the sector agreement, because no setting and no subscription can consent on a regulator's behalf. A contractual duty is governed by what the contract permits: there is no BAA to ask for, the answer sits in a document you already signed, and where that document allows a subcontracted processor under confidentiality, a business tier's data processing agreement can satisfy it. So a marketing agency under NDA and a dental practice holding PHI share a row and get different answers. Read the NDA before assuming either one, and if you cannot tell which you are, assume the stricter.

The personal-information row has a lawful side door. HHS guidance on cloud computing says a vendor receiving only information de-identified in accordance with the Privacy Rule is not a business associate, so stripping identifiers first changes the data's class and moves it left across the boundary legitimately. Most of the value a small business gets from AI sits in the internal-operational row anyway, which is the row a Company Brain is built from.

What actually happens to a prompt you paste into a consumer AI account

A prompt pasted into a consumer AI account may become training material. OpenAI's wording: "When you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models." It also persists. Anthropic keeps consumer chats you allow to improve Claude for up to five years, de-identified.

A consumer chat can also end up in front of someone who is not you. In the New York Times copyright litigation, OpenAI's page states the preservation obligation reached Free, Plus, Pro and Team subscribers and API customers without a zero-retention agreement, and did not reach ChatGPT Enterprise or Edu. A magistrate judge later ordered production of 20 million de-identified chat logs, affirmed by the district judge in early January 2026.

Read OpenAI's tier list carefully before drawing comfort from it. It names ChatGPT Team, which is the tier naming that page still uses, and it does not name ChatGPT Business anywhere, so a Business subscriber cannot read exclusion into it. Two dates then qualify how all of this interacted with OpenAI's ordinary 30-day deletion practice. OpenAI's update to that page says its obligations under the earlier retention order ended on 26 September 2025 and that it returned to standard practices. The production order affirmed in January 2026 concerns the April to September 2025 data already held, not anything pasted since.

A free user can switch training off in Data Controls, so the consumer tier is not unconditionally training on you. But that setting is one person's choice, nobody else in the company can see whether that employee flipped it, and OpenAI notes that even after opting out, feedback on a reply means "the entire conversation associated with that feedback may be used to train our models."

Shadow AI: your staff are already pasting company data into personal accounts

Shadow AI is the gap between the AI your business bought and the AI your staff use, and it cannot be counted from the inside. The Census Bureau's Business Trends and Outlook Survey found 19.8% of US businesses currently using AI as of its 3 May 2026 reference date, Finance and Insurance at 33.9%, firms of four or fewer employees below 20%. That survey asks the business, and a personal account leaves no admin console entry and no invoice line to ask about.

Be skeptical of anyone selling you a percentage here, Azgard included: the widely quoted shadow-AI figures come from opt-in panels commissioned by firms that sell the remedy. Ask everyone who touches customer data which AI account they used last week, and write down the tier. That count costs nothing, and unlike a national percentage it is about your company.

Client-confidential and regulated data: what the law where you operate requires

The United States has no comprehensive federal privacy law, so what governs your AI use is which sector you are in, and every sector's rule turns out to be a contract you can only sign on a contracted tier. A reader on a personal account fails all three at once. None of this is legal advice; your attorney is the person to run it past.

Health. Asking whether ChatGPT is HIPAA compliant asks about the wrong thing. An account is covered or it is not, and for ChatGPT that means Enterprise or Edu on a sales-managed account, the API, or the in-product route OpenAI offers eligible individual clinicians. HHS's Office for Civil Rights has said a covered entity using a cloud provider to maintain electronic PHI without a BAA is itself in violation of the HIPAA Rules, even where the provider stores only encrypted PHI and holds no key. That guidance was published in 2016 and predates generative AI, so treat it as the closest on-point guidance HHS has published, not as something HHS has said about AI. Its reasoning applies on its face: business associate status turns on maintaining PHI, which a vendor logging prompts does.

Financial. The GLBA Safeguards Rule catches firms that do not think of themselves as financial institutions. The FTC's guide names tax preparation firms, mortgage brokers, collection agencies and financial advisors, and requires that "your contracts must spell out your security expectations" for service providers. The exemption for institutions holding information on fewer than five thousand consumers does not cover that obligation, so a two-person CPA firm still owes it.

Professional. ABA Formal Opinion 512 turns on the self-learning character of the tool, which is the variable the tier controls. Because such tools' output "could lead directly or indirectly to the disclosure of information relating to the representation of a client," it holds, "a client's informed consent is required prior to inputting information relating to the representation into such a GAI tool." Do not over-read that: the same opinion says consent is not needed where no client information goes in, Texas Opinion 705 recommends rather than mandates, and no US bar has held that a no-training tier removes the requirement.

State privacy law. Around twenty states run comprehensive privacy laws, per the IAPP's tracker, and you need not know which one applies to know what they want. Virginia is the clean exemplar: Va. Code § 59.1-579(B) requires that "a contract between a controller and a processor shall govern the processor's data processing procedures," with a duty of confidentiality, deletion or return at the end of services, and written flow-down to subcontractors. States diverge on who is caught: Texas Business and Commerce Code § 541.002 exempts a business that qualifies as a small business under the SBA definition, though § 541.107 still bars even an exempt small business from selling sensitive personal data without prior consent.

For training and retention the fix really is a purchase and two settings. A BAA is not a setting, and a healthcare reader who assumes it is finds that out late. OpenAI's route is an email and a case-by-case review that can be declined, and Google's is an account-manager conversation plus an agreement Google states "is not subject to modification". That agreement covers only the products on Google's covered-products list. Sector agreements carry holes too: Anthropic's BAA does not apply to web search.

For a Chicagoland fabricator with no PHI, no customer financial data and nobody bound by bar rules, none of the statutory rules above bite, and one business subscription closes the internal-operational row they mostly live in. The moment that fabricator quotes on a customer's unreleased design, though, they are in the fourth class by the contractual route, and the governing document is their own NDA rather than anything in this section. Azgard's Chicago page is written for that reader, the New York one for the professional firms this section speaks to.

Do you need a private LLM, or is a contracted tier enough?

A private LLM is the wrong first purchase for almost every US small business, because US law asks for a contract rather than a location. HHS answered the offshore-storage question directly: a covered entity may use a cloud provider storing electronic PHI outside the United States provided it enters into a business associate agreement and weighs the geographic risk in its required risk analysis.

If you want the data to stay home, the US is the only one of the five markets Azgard serves where both storage and inference can sit in-country, per OpenAI's residency page. OpenAI offers residency to eligible API customers and new ChatGPT Enterprise or Edu workspaces, not to ChatGPT Business and not to any consumer account. Account data, billing records and anything handed to an external integration sit outside the region regardless.

Two limits on the tier argument itself. The tier settles the facts; what those facts make you legally is a separate assessment the contract does not decide. And a private model still runs on somebody's hardware under somebody's terms, so you have changed which contract you read, not escaped reading one.

How to move your team onto a safe tier in a week, without writing a policy first

Moving a team onto a safe AI tier takes about a week, and it comes before the policy rather than instead of it. The order matters because a policy takes a month and the exposure is live today.

  1. List the accounts. Every person, every tool, the tier by name. Anyone who cannot name their tier is on the consumer one.
  2. Buy one business tier and put everyone on it. One vendor is enough to start. Two settings on day one: training off, and a retention window an admin sets. If you handle patient records, client financial data or matters under bar rules, this tier is your floor rather than your finish: see step 5.
  3. Delete the personal-account history holding company data, before those accounts get closed.
  4. Draw the boundary on one page. Four data classes, what the company allows for each, pinned where people work.
  5. Then write the policy, and start the sector agreement if you need one.

HHS OCR, the FTC's business guidance center and your state bar all publish free plain-language guidance to write that policy against. A BAA conversation takes longer than a week, so open that one in week one rather than at the end of the month.

What Azgard does with a client's commercial data, and what it will not promise

Azgard builds inside the client's own accounts, on the client's own contracted tier, which is a constraint rather than a security feature. Apex Signage's quoting work runs on Apex's data in Apex's systems: quoting time fell from about three and a half hours to just over two hours per quote, on a system Apex's own staff operate. The supplier cost snapshot underneath it holds 15,758 rows of real pricing data, none of which left Apex's tenancy. Home Grown Electrical and Inner Game Basketball are the other two clients Azgard can name.

What Azgard will not promise: no SOC 2 report, no BAA of its own, and no assurance that a vendor's terms will not change next quarter. That last one is why the boundary is built on published terms you can re-read rather than on a vendor's reputation. Azgard is Sydney-based and delivers remotely with no US entity, no US office and no US staff, so the checks in how to choose an AI consultant apply here as much as anywhere. Ask them.

FAQ

tags: securitygovernancecompliancedata

Angus McDonald

Angus McDonald

Founder, Azgard

Builds and operates production AI systems for organisations that need results, not slide decks.