Is it safe to use ChatGPT at work?

What OpenAI says about training and retention across ChatGPT plans, the Samsung case, and why the real risk is use without a policy or inventory. Five steps to use it with judgment.

Updated September 20, 2026 · 8 min read

The short answer: it depends on the plan and what you paste

Using ChatGPT at work can be acceptable or risky, and the difference is rarely the tool itself: it is the plan you use, the kind of data you paste into it, and whether the company knows it is being used at all. An absolute answer, in either direction, would be inaccurate.

That is why this guide does not hand down a verdict. It separates what OpenAI says publicly about each kind of plan from what is your company’s own decision, and shows where the risk usually appears in practice: employees on personal accounts, with no policy and no inventory.

A note on method. Terms of service change, and what follows reflects what OpenAI’s official pages said on the verification date shown in the sources. Before deciding anything, check the current terms; our table is a map, not a contract.

What can go wrong day to day

The most cited case is Samsung. In May 2023, TechCrunch reported that the company restricted the use of generative AI tools such as ChatGPT on company devices after sensitive internal data was sent to the platform in April of that year. The restriction even reached personal devices connected to the internal network.

The episode illustrates the typical pattern: nobody acted in bad faith. People with a real problem, such as debugging code, used the tool closest to hand. The incident does not prove that ChatGPT is unsafe; it shows that without a clear rule, data leaves the perimeter by the most convenient path.

69%

of cybersecurity leaders have evidence or suspect that employees use public generative AI at work, according to Gartner. The same source reports the forecast that more than 40% of organisations will suffer Shadow AI incidents by 2030.

Gartner, Previsão sobre incidentes de Shadow AI até 2030 (Infosecurity Magazine)

Free, Plus, Business and Enterprise: what changes

The question that weighs most is whether what you type can be used to train models. The table summarises what OpenAI’s pages indicate. It covers only what we can attribute to those pages; detailed retention, SSO, admin controls, DPA and BAA vary by plan and contract, and you should confirm them directly with OpenAI.

TopicChatGPT Free and Plus (individuals)ChatGPT Business, Enterprise and API
Training on your contentOpenAI says it may use content to improve its models.OpenAI says it does not train on inputs and outputs by default.
How to change itThe user can turn it off in the account's data controls.No action needed under the stated default; sharing data is opt-in.
DPA, BAA and configurable retentionOpenAI's business page describes these commitments for business customers, not for individual use.OpenAI says it offers a BAA to ChatGPT for Healthcare customers and to API customers in healthcare, supports signing a DPA, and lets qualifying organisations configure retention.

Sources for this table: the “How your data is used to improve model performance” page and the business data privacy page, both from OpenAI (links below, verified on September 20, 2026). If your context requires a BAA, a DPA or data residency, do not assume: ask for the document and read it.

Retention and the 2025 court order

In 2025, in the lawsuit brought by The New York Times, OpenAI was placed under a court order to preserve data, which affected retention of consumer and API content. OpenAI published an update saying that obligation ended on September 26, 2025.

According to the same update, the company returned to standard practice, in which deleted conversations and Temporary Chats are removed from its systems within 30 days. The NYT still maintains a demand over a specific set of data from April to September 2025. The status may change; read OpenAI’s page before citing it.

The lesson for a company is not about the lawsuit itself: what you type may stay stored for periods you do not control. Treat anything pasted into a personal account as if it could be retained.

The real risk is use without a policy

IBM’s 2025 breach study shows how this looks after an incident. The point is not the brand of the tool; it is the absence of governance around it.

63%

of the organisations that suffered a breach said they had no AI governance policies in place to manage AI or to prevent workers from using shadow AI.

IBM Security, Cost of a Data Breach Report 2025

USD 670,000

is what a high level of shadow AI added to the average breach cost, in the same study.

IBM Security, Cost of a Data Breach Report 2025

NIST’s Generative AI Profile (NIST AI 600-1) addresses this class of risk, including data leakage, as something to manage through process rather than a blanket ban. In practical terms: a written rule, an inventory of what is in use, and an owner for each decision.

Five steps to use it with judgment

This is our reading of a reasonable path, not text from any standard. The order matters: without knowing what is in use, any policy is out of date from day one.

  • 1. Discover real usage. See which AI tools show up in the company, personal accounts included. Start with the guide to Shadow AI.
  • 2. Classify the data. Define in writing what may never be pasted into an external tool: code, customer data, contracts, health data.
  • 3. Choose a plan with a contract. If ChatGPT is allowed, prefer a business plan and read the DPA before approving use.
  • 4. Publish the policy. Make the rule short and signable. See the AI usage policy template.
  • 5. Track and review. Usage changes every week; review the list of allowed tools and what was detected.

To see the tool’s entry in our public catalog, open ChatGPT in the AI tool catalog, or browse the full catalog.

Tangerin AI detects, from metadata, which AI tools are in use and tracks governance progress against frameworks such as the NIST AI RMF. It does not read the content of conversations and does not certify anyone. You can start a free trial or take the free assessment.

Frequently asked questions

Does ChatGPT use what I type to train its models?

It depends on the plan. According to OpenAI, for individual services such as free ChatGPT and Plus, content may be used to improve the models, and users can turn that off in data controls. For ChatGPT Business, Enterprise and the API, OpenAI says it does not train on your inputs and outputs by default. Check the current terms.

Can I paste source code or customer data into ChatGPT?

Only if your AI usage policy and the contract for your plan allow it. In 2023 Samsung restricted generative AI use after sensitive internal data, including source code, was submitted to ChatGPT, as reported by TechCrunch. A practical rule is to define in writing which categories of data never leave the company.

Is a personal account at work a problem?

It is the scenario that worries governance teams most: the company has no contract, cannot see the usage and does not control retention. Gartner reports that 69% of cybersecurity leaders have evidence or suspect that employees use public generative AI at work. The way out is an approved alternative plus a record of use.

Does ChatGPT Enterprise remove the risk?

It reduces part of it, because the contract and the admin controls change. It does not remove the human risk: someone can still use a personal account next to the corporate one. A paid plan protects what goes through it, not what happens outside it.

What does Tangerin AI do about ChatGPT?

It detects, from metadata, which AI tools (including ChatGPT) show up in use across the company, and tracks governance progress against frameworks such as the NIST AI RMF. It does not read the content of conversations and does not certify anyone.

Sources

Found it useful? Share it

LinkedInX

Instagram does not open links from outside the app — we copy it for you to paste in a story or bio.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.