Back to AI Tools
OpenAI
Risk Overview
Minimal Risk
3.3
/10
Model API
·
Embeddings
·
Image Generation
·
Top Risks
Mandatory arbitration with class action waiver limits user legal recourse. CLOUD Act exposure as US entity. Assistants API and GPT Actions enable agentic file, browser, and API access. Fine-tuning data retained until manually deleted.
Mitigations
Request ZDR for eligible endpoints. Sign enterprise DPA for GDPR coverage. Use EU data residency where available. Restrict agentic tool permissions to minimum necessary. Review and exercise 30-day arbitration opt-out.
Get started
Is your team using
OpenAI
safely?
Highest Risk Categories
The highest-scoring risk categories identified in this assessment.
Legal Terms
Mandatory binding arbitration with class action waiver for US users. 30-day opt-out window available. Arbitration conducted under AAA rules. Liability cap in place. Standard US tech boilerplate but unfavorable to users.
7
/10
Data Sovereignty
US-incorporated company, subject to CLOUD Act. Offers EU-based data residency options for enterprise. GDPR DPA available. No clear data-processing outside CLOUD Act exposure. Standard US cloud risk.
4
/10
3rd-Party Sharing
Data shared with sub-processors for service delivery (standard). No ad/marketing data sales. API inputs/outputs are not shared with third parties for their own use. Business DPA covers enterprise customers.
3
/10
Unlock the complete assessment
Run a free assessment to access the full AI tool risk analysis.
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue
Reference Documentation
Official documentation and policies referenced as part of this assessment.
Terms of Service
https://openai.com/policies/service-terms/
Privacy Policy
https://openai.com/policies/row-privacy-policy/