NEWS
Verax AI Risk Assessment is live. See what's exposed
OpenAI
OpenAI
 
Risk Overview
Minimal Risk
3.3
/10
Model API
·
Embeddings
·
Image Generation
·
Top Risks

Mandatory arbitration with class action waiver limits user legal recourse. CLOUD Act exposure as US entity. Assistants API and GPT Actions enable agentic file, browser, and API access. Fine-tuning data retained until manually deleted.

Mitigations

Request ZDR for eligible endpoints. Sign enterprise DPA for GDPR coverage. Use EU data residency where available. Restrict agentic tool permissions to minimum necessary. Review and exercise 30-day arbitration opt-out.

Get started
Is your team using 
OpenAI
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Legal Terms

Mandatory binding arbitration with class action waiver for US users. 30-day opt-out window available. Arbitration conducted under AAA rules. Liability cap in place. Standard US tech boilerplate but unfavorable to users.
7
/10

Data Sovereignty

US-incorporated company, subject to CLOUD Act. Offers EU-based data residency options for enterprise. GDPR DPA available. No clear data-processing outside CLOUD Act exposure. Standard US cloud risk.
4
/10

3rd-Party Sharing

Data shared with sub-processors for service delivery (standard). No ad/marketing data sales. API inputs/outputs are not shared with third parties for their own use. Business DPA covers enterprise customers.
3
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.