Back to AI Tools
ChatGPT Work
Risk Overview
Minimal Risk
2.7
/10
Code Generation
·
Text Generation
·
Conversational AI
·
Image Generation
·
AI Agents
·
Top Risks
EU AI Act compliance gap (training data transparency); data residency and BAA available on Enterprise tier only, not Business; IP indemnification excluded for Business tier; multi-cloud sub-processor footprint (Azure, AWS, CoreWeave, Google Cloud)
Mitigations
Use Enterprise tier for regulated or sensitive workloads; sign DPA and subscribe to sub-processor change notifications; for HIPAA use: Enterprise + BAA required (baa@openai.com); Business tier adequate for general productivity with non-regulated data; monitor EU AI Act enforcement developments
Get started
Is your team using
ChatGPT Work
safely?
Highest Risk Categories
The highest-scoring risk categories identified in this assessment.
Legal Terms
EU AI Act enforcement active Aug 2, 2026 — OpenAI's compliance statement omitted training data transparency chapter (enforcement gap). FedRAMP Moderate (Enterprise, March 2025) is positive for regulated use. Florida AG criminal investigation (April 2026) targets consumer safety but creates reputational exposure. GDPR DPA and SCCs in place; OpenAI Ireland Ltd. as EU processor.
5
/10
Data Retention
Enterprise: configurable retention with 90-day minimum floor (adjustable in 30-day increments). Business tier: no configurable retention window — significant gap for regulated industries. ZDR available via API. Deleted conversations purged within 30 days. NY Times data preservation order expired Sept 26, 2025.
3
/10
Data Sovereignty
Data residency in 10 regions (Enterprise only; Business has no residency controls). EU entity: OpenAI Ireland Ltd. In-region GPU inference available for Enterprise/API (US or EU). Enterprise Key Management (EKM) allows customer-controlled encryption keys. Business tier: US-primary processing, no regional options.
3
/10
Unlock the complete assessment
Run a free assessment to access the full AI tool risk analysis.
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue
Reference Documentation
Official documentation and policies referenced as part of this assessment.
Terms of Service
https://openai.com/policies/business-terms/
Privacy Policy
https://openai.com/policies/privacy-policy/
End User License Agreement (EULA)
https://openai.com/policies/data-processing-addendum/