Blog

Is ChatGPT secure for business?

Is ChatGPT secure for business? Data training, encryption, plan-by-plan protections, compliance, and the real security risks businesses face in 2026.

Phos Team ·
AI Strategy

ChatGPT is not secure for business by default. It can be made secure, but only with the right plan, the right configuration, and clear policies for your team.

The most dangerous assumption a business can make is that because everyone is using it, it must be safe.

Key takeaways

  • Free and Plus plans are not appropriate for business use: Data may be used to train OpenAI’s models by default. There are no admin controls, no SSO, and no compliance documentation available.
  • The Business plan is the minimum security baseline: No training on your data by default, SAML SSO, admin controls, and centralized visibility. $20/user/month (annual).
  • 34.8% of employee ChatGPT inputs contain sensitive data: Q4 2025 research, up from 11% in 2023. Most employees do not realize they are sharing sensitive information.
  • The biggest risk is not the AI, it is the data employees put into it: Customer records, financial data, internal strategy, source code, and confidential contracts all go in regularly.
  • EU AI Act high-risk provisions take effect August 2, 2026: Businesses using AI for high-risk use cases face conformity assessment obligations.
  • Enterprise adds the controls regulated industries need: HIPAA BAA, data residency (US and EU), audit logs, and advanced RBAC are Enterprise-only.

The core security question: what happens to your data?

When an employee types a prompt into ChatGPT, where does that information go, who can see it, and can it end up influencing the model’s responses to other users? The answer depends entirely on which plan they are using.

OpenAI’s data handling works differently across its plan tiers. The distinction matters because most employees who use ChatGPT at work are using personal Plus or Free accounts, not company-managed Business accounts.

What happens on Free and Plus plans:

  • Conversations may be used to train future versions of OpenAI’s models by default
  • Users can opt out individually, but there is no way to enforce this across a team
  • No admin visibility into what employees are entering
  • No SSO: each person manages their own account
  • No compliance documentation available for these plans

What happens on Business and Enterprise plans:

  • Conversations and uploaded files are excluded from model training by default, no settings required
  • Workspace admins can see usage, manage users, and set permissions
  • SAML SSO integrates with your identity provider
  • Compliance documentation (SOC 2 Type II report, ISO certifications) is available

If your team is using personal ChatGPT accounts for work, they are likely inputting company data into a system with no training exclusion, no admin oversight, and no compliance protection.


Security comparison by plan

FeatureFreePlus ($20/mo)Business ($20/seat/mo annual)Enterprise (custom)
Data used for trainingYes (default)Yes (opt-out available)No (default)No (default)
Admin controlsNoNoYesYes
SAML SSONoNoYesYes
Centralized billing and user managementNoNoYesYes
SOC 2 Type II documentationNoNoYesYes
HIPAA BAANoNoNoYes
Data residency (US and EU)NoNoNoYes
Audit logsNoNoNoYes
Workspace Agents governanceNoNoBasicAdvanced RBAC

The minimum for business use is the Business plan. It is the cheapest tier where your data is excluded from model training by default and where an admin can actually see and govern how the tool is being used across the team.


OpenAI’s security certifications

OpenAI holds the following certifications, verifiable at trust.openai.com:

  • SOC 2 Type II
  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • CSA STAR

These certifications apply to Business and Enterprise plans, not Free or Plus accounts.

Always verify current certification scope at trust.openai.com before making procurement decisions, as coverage changes frequently.

Encryption: OpenAI encrypts data in transit using TLS and at rest using AES-256.


The real risks businesses face in 2026

Security certifications address infrastructure risks. The risks that actually affect most businesses come from how employees use the tool, not from OpenAI’s server configuration.

Risk 1: Sensitive data in prompts

34.8% of employee ChatGPT inputs contain sensitive data, up from 11% in 2023. The most common categories:

  • Customer personally identifiable information (names, emails, contact details)
  • Financial data (revenue figures, pricing, deal terms)
  • Internal strategy documents and competitive plans
  • Source code and technical architecture
  • Legal documents and contracts
  • HR data (performance reviews, compensation, employee records)

Most employees sharing this data are not aware of the privacy implications. They are solving a work problem quickly, and the fastest path is to paste in the full context.

Mitigation: Acceptable use policy covering what categories of data cannot go into ChatGPT. Business plan admin visibility to monitor and enforce. Training for all employees before deployment, not after.

Risk 2: Employees using personal accounts for work

When employees use personal Free or Plus accounts for work tasks, the company has no visibility, no training exclusion guarantee, and no way to enforce any policy.

This is shadow AI: AI use happening in your organization right now, outside any governance structure.

The solution is not to ban ChatGPT. Banning drives usage underground.

The solution is to provide a managed Business plan account and a clear policy that personal AI accounts should not be used for work tasks involving company data.

Risk 3: Workspace Agents and MCP integrations

Workspace Agents (GA July 6, 2026) connect ChatGPT to Slack, Google Drive, SharePoint, Salesforce, and 60+ other tools. Each connection expands the data surface ChatGPT can access.

An agent that can read your Google Drive can potentially surface files shared too broadly. An agent connected to your CRM can access customer records.

The security posture of your ChatGPT deployment is now partly a function of how well your underlying SaaS permissions are configured.

Before deploying Workspace Agents, audit which files in your connected systems are overshared. Data that should not reach ChatGPT should not be accessible to the accounts ChatGPT connects with.

Risk 4: File uploads containing more than intended

ChatGPT allows file uploads on Plus and higher plans. Employees uploading a spreadsheet may not realize the document contains additional tabs, hidden columns, or metadata beyond what they intended to share.

Mitigation: Before uploading any file, strip it to the minimum data needed for the task. Never upload raw CRM exports, full financial statements, or HR files. Work from copies with sensitive fields removed.

Risk 5: Confidential output that becomes a prompt

ChatGPT outputs can contain confidential information that employees paste into other tools, email to colleagues, or store in systems with different security properties.

The confidentiality of a ChatGPT session does not follow the output.


HIPAA and regulated industries

HIPAA: A Business Associate Agreement (BAA) is available only on the Enterprise plan. The Business plan does not include a BAA. Healthcare organizations handling protected health information (PHI) must use the Enterprise plan with an explicitly activated BAA, not the Business plan.

Several ChatGPT features are excluded from HIPAA BAA scope even on Enterprise: Desktop remote mode, Web, Code Review, Computer Use, Remote Control.

Verify the current exclusion list with OpenAI before making compliance decisions.

Alternative HIPAA path: Claude models on AWS Bedrock are covered under the AWS BAA, which is a HIPAA-eligible service. Data stays in AWS infrastructure. For healthcare organizations already on AWS, this is often the simpler path.

GDPR: For EU-facing operations, assess whether employee use of ChatGPT for tasks involving personal data of EU residents requires a DPIA. Data processing agreements with OpenAI are available for Business and Enterprise customers.

EU AI Act: High-risk AI system requirements take effect August 2, 2026. If your business uses ChatGPT for HR screening, credit assessment, or other Annex III high-risk use cases, conformity assessment obligations apply. Maximum fines reach 7% of global annual revenue for the most serious violations.


What to do if employees are already using ChatGPT personally for work

This is the most common situation: the governance question arrives after widespread informal adoption has already happened.

Step 1: Audit which AI tools are in use and on which plan. Check with IT on browser extensions, API integrations, and third-party tools that may be connecting to OpenAI’s API without direct employee awareness.

Step 2: Set up a Business plan account before issuing any policy. Give employees a governed alternative before asking them to stop using personal accounts. Prohibition without a replacement does not work.

Step 3: Issue a clear, short acceptable use policy. Cover: what data categories cannot go into ChatGPT (customer PII, financial data, source code, legal documents), which account to use (the company Business account), and what approval process exists for new AI tool integrations.

Step 4: Run a 30-minute team session. Not a compliance lecture. A practical walkthrough of which tasks are appropriate for ChatGPT and which are not, with examples relevant to each team’s actual work.

Step 5: Assign an owner. Someone in IT or operations should own AI tool governance, review new tool requests, and monitor for shadow usage.


The short answer

ChatGPT on a Free or Plus account is not secure for business use involving sensitive data.

ChatGPT on a Business or Enterprise plan, with a proper acceptable use policy and team training, is appropriate for the large majority of knowledge work tasks.

The risk is not in ChatGPT’s infrastructure. OpenAI’s security certifications and encryption are solid.

The risk is in what your team puts into it and whether you have any visibility or control over that.



Need help building a secure ChatGPT deployment for your business?

Getting the plan right is the easy part.

Building the governance layer, the acceptable use policy, the team training, and the ongoing oversight that keeps AI use safe as your operations evolve is where most companies need help.

Phos AI Labs is an embedded AI consulting firm for mid-market businesses.

We identify the right AI problems, build the strategy, handle implementation, and train your team until AI is how the business actually runs.

  • Strategy before systems: We establish which AI tools belong in which workflows before any deployment begins.
  • AI Foundations that hold: We install the operating context, decision rules, and configuration standards your team runs on for years.
  • Real team training: We build fluency and safe usage habits inside your actual workflows, not in generic compliance sessions.
  • Private AI Workspace: We design a company-wide AI environment with security and governance built around your existing stack.
  • AI-Native Operations design: We rebuild the workflows that matter most with security built in from the start.
  • Honest judgment, every time: We tell you when ChatGPT is appropriate for a use case and when it is not.
  • We stay until it compounds: We are not done when the policy document is delivered. We are done when the team runs it reliably.

400+ engagements. Clients include Zapier, Coca-Cola, Medtronic, Sotheby’s, Dataiku, and American Express.

If you want your ChatGPT deployment to be genuinely secure, talk to the team at Phos AI Labs.


FAQs

Is ChatGPT safe to use at work?

On Business or Enterprise, yes, for most knowledge work tasks. On a Free or Plus account, no for sensitive company data.

Conversations may be used for model training, and there are no admin controls.

Does ChatGPT store my business data?

On Business and Enterprise plans, conversations are excluded from model training by default. Retention settings are configurable on Enterprise.

On Free and Plus plans, data handling defaults are less protective.

Is ChatGPT HIPAA compliant?

Only on the Enterprise plan with an explicitly activated BAA. The Business plan does not include a HIPAA BAA.

Healthcare organizations handling PHI must use Enterprise and activate the BAA through a Primary Owner account.

What certifications does OpenAI hold?

SOC 2 Type II, ISO/IEC 27001, ISO 27017, ISO 27018, ISO 27701, and CSA STAR.

These apply to Business and Enterprise plans, not Free or Plus. Verify current scope at trust.openai.com before procurement decisions.

What is the biggest ChatGPT security risk for businesses?

Employees inputting sensitive data into personal Free or Plus accounts with no admin oversight and no training exclusion guarantee.

34.8% of employee ChatGPT inputs contain sensitive data, and most employees do not realize the risk.

Does the EU AI Act affect how businesses can use ChatGPT?

Yes. High-risk AI system requirements took full effect August 2, 2026. Businesses using ChatGPT for high-risk use cases face conformity assessment obligations.

GDPR data processing agreements are available for Business and Enterprise customers.

Related articles

The fastest way to know whether we're the right fit, is a conversation.

STEP 1/2 · ABOUT YOU