OpenAI says it does not train its models on business data by default. New products including ChatGPT Work, Frontier, Company Knowledge, Presence and Secure MCP Tunnel make the rest of the data-governance picture more important.

TL;DR

OpenAI’s central enterprise promise is clear: by default, it does not use data from ChatGPT Business, Enterprise, Edu, Healthcare or the API to train its models. Business customers retain control of their inputs and outputs, while OpenAI encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher.

That promise does not mean every enterprise interaction is stateless or that no information is ever stored. Retention depends on the product, feature and API endpoint. Connected apps can create synchronized search indexes, API abuse-monitoring logs are normally retained for up to 30 days, and third-party MCP servers apply their own policies. OpenAI’s 2026 product strategy therefore rests on several separate controls: training exclusion, access permissions, retention settings, regional storage and inference, network boundaries, and auditability.

OpenAI has spent the past year moving from a protected workplace chatbot toward an operating layer for enterprise agents. Company Knowledge searches across internal applications. OpenAI Frontier assigns agents identities, permissions and boundaries. ChatGPT Work can act across files and applications for hours. OpenAI Presence puts voice and chat agents into customer and internal workflows. Secure MCP Tunnel connects those products to private or on-premises systems without publishing the internal server to the internet.

Enterprise data governance · July 2026

Inside OpenAI’s Enterprise Data Stack

What happens to company data when ChatGPT and AI agents search internal apps, run tools and work across private systems.

Vetted by thorstenmeyerai.com
No training
By default on business data

Applies to covered business products and the API; explicit opt-in can change the rule.

10
Data residency regions

Storage at rest for eligible Enterprise and Edu customers.

3
Inference regions

Europe, United States and UAE for eligible configurations.

Up to 30 days
Default API abuse-monitoring retention

Eligible customers can apply for Modified Abuse Monitoring or Zero Data Retention.

Oct 2025 Company Knowledge
Feb 2026 Frontier
May 2026 Secure MCP Tunnel
Jul 2026 Work + Presence

01 · Four separate questions

PBN-TEC Private Browser & Password Manager Software Portable

PBN-TEC Private Browser & Password Manager Software Portable

  • Secure Private Browsing: Protects your online activity on any device
  • All-in-One Privacy Toolkit: Includes private browser, anonymous browsing, and password manager
  • Portable USB Solution: Carry your privacy tools on a USB drive

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

“No training” is not “no storage”

A credible review separates model training, service processing, data retention and access control.

Training

Used to improve future models?

OpenAI says business data is not used for training by default. Explicitly shared feedback may be used when a customer opts in.

Default · Excluded

Processing

Handled to produce an answer?

Prompts, files and retrieved context must be processed for inference, safety checks and the requested tools to work.

Required for the service

Retention

Stored after processing?

The answer varies by plan, feature, endpoint, chat settings, synchronized index and approved data-retention control.

Configuration dependent

Access

Who can retrieve or act?

Workspace roles, app permissions, agent identity and tool policies determine what context is visible and what actions are allowed.

Permission controlled

02 · The new enterprise stack

Non-Invasive Data Governance Unleashed: Empowering People to Govern Data and AI

Non-Invasive Data Governance Unleashed: Empowering People to Govern Data and AI

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

From protected chat to governed agents

OpenAI’s recent products add internal search, agent identity, private connectivity and execution.

October 2025

Company Knowledge

Searches across connected apps, respects source permissions and returns citations to original material.

Retrieve

February 2026

OpenAI Frontier

Builds and manages AI coworkers with separate identities, explicit permissions, guardrails and feedback.

Govern

May 2026

Secure MCP Tunnel

Connects supported products to private or on-prem MCP servers without a public server endpoint.

Connect

July 2026

ChatGPT Work

Works across apps and files, runs multi-hour assignments and turns goals into finished deliverables.

Act

July 2026

OpenAI Presence

Deploys production voice and chat agents across customer-facing and internal operational workflows.

Operate

2026 control layer

Compliance + Review

Provides prompts and responses for oversight; auto-review can inspect important actions before execution.

Observe

The strategic shift

More context → more useful agents → more governance required

Search Reason Act Audit

03 · Connected data flow

BUFFALO LinkStation 210 2TB 1-Bay NAS Network Attached Storage with HDD Hard Drives Included NAS Storage that Works as Home Cloud or Network Storage Device for Home

BUFFALO LinkStation 210 2TB 1-Bay NAS Network Attached Storage with HDD Hard Drives Included NAS Storage that Works as Home Cloud or Network Storage Device for Home

  • Centralized Storage with RAID: RAID-enabled NAS for backup and storage
  • Easy Network Connection: Connect to router for shared device access
  • Compatible with Windows and macOS: Supports Windows and older macOS versions

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Permissions travel with the user

ChatGPT should retrieve only what the authenticated user or agent identity may already access.

1

Identity

User or AI coworker

2

Permission

Role + source ACLs

3

Retrieval

Apps + private tools

4

AI inference

Answer, artifact or action

Where new state can appear

Chat history

Conversations, files, memory and custom GPT content follow workspace retention settings.

Policy controlled

Synced index

App data with sync can be indexed to accelerate answers. Region support must be checked.

App dependent

API state

Abuse logs, stored responses, files and containers have endpoint-specific lifecycles.

Endpoint dependent

Third parties

Remote MCP servers and other tools apply their own retention and security policies.

Separate processor

04 · Location controls

AI Workflow Automation for Bloggers: Build a Simple Content System to Research, Write, Optimize, and Repurpose Posts Faster with AI and No-Code Tools (AI Toolkit for Bloggers 2026 Book 8)

AI Workflow Automation for Bloggers: Build a Simple Content System to Research, Write, Optimize, and Repurpose Posts Faster with AI and No-Code Tools (AI Toolkit for Bloggers 2026 Book 8)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Storage residency ≠ inference residency

The region used to save covered content can differ from the region where GPU inference runs.

Data residency · Storage at rest

10 regions
  • Europe (EEA + Switzerland)
  • India
  • United States
  • Japan
  • United Kingdom
  • Singapore
  • Canada
  • South Korea
  • Australia
  • United Arab Emirates
Covered content
Chats · files · memory · custom GPTs · analysis artifacts · image inputs and outputs

Inference residency · GPU execution

3 regions
  • Europe
  • United States
  • United Arab Emirates
Requires data residency in the same region and applies only to supported features and eligible customers.
Scope must be verified

05 · Claims vs. operational reality

What each control actually answers

Control
What it means
What it does not prove
No training by default
Covered business inputs and outputs are not used to train models unless explicitly shared.
That nothing is processed, retained or reviewed under every circumstance.
Source permissions
ChatGPT should see only content the user or agent identity may already access.
That existing group permissions are appropriately narrow or current.
Zero Data Retention
Approved API customers can exclude content from abuse logs on eligible capabilities.
That every endpoint, feature or third-party service is stateless.
Data residency
Covered customer content is stored at rest in the configured region.
That all metadata or GPU execution also remains inside that region.
Compliance logs
Prompts and agent responses can be exported for oversight and investigation.
That one log contains every file, tool call and action in a run.

06 · Enterprise buyer checklist

Govern the workflow, not only the model

For every deployment, record the complete chain of access, state and accountability.

  • Product, model and exact enabled features
  • Retention setting for every endpoint
  • Connected sources and synchronized indexes
  • Storage region and inference region
  • User or agent identity and allowed actions
  • Third-party processors and audit coverage
The decision rule Higher-impact actions require narrower permissions, stronger approvals and fuller logs.
Source basis

OpenAI Enterprise Privacy · API Data Controls · ChatGPT Residency · Company Knowledge · Frontier · ChatGPT Work · Presence · API Changelog · reviewed 30 July 2026

Each step increases the value of the system because the model can see more context and take more useful actions. It also changes the governance problem. Security teams are no longer reviewing only what an employee pastes into a chat box. They must decide which repositories can be connected, whose credentials an agent may use, what actions it may take, where temporary state is created, and which events appear in compliance logs.

The useful way to evaluate OpenAI’s enterprise data posture is therefore not to ask one question—“Do you train on our data?”—but six: What is used for training? What is retained? Where is it stored? Where is inference performed? Who can retrieve it? And what can administrators reconstruct afterward?

At a glance

REPORT

WHEN: OpenAI documentation and product releases reviewed through 30 July 2026.

THE DEVELOPMENT: OpenAI has expanded its enterprise offering from protected chat into a governed agent stack that can search, retrieve and act across internal systems.

“No training” is the first layer, not the whole answer

OpenAI’s enterprise privacy commitment covers inputs and outputs from ChatGPT Business, Enterprise, Healthcare, Edu, Teachers and the API Platform. OpenAI says it does not train its models on that business data by default. If a customer explicitly opts in—for example through a feedback mechanism—the shared material may be used to improve models.

That distinction matters because training, processing and storage are different operations. A model must process a prompt and any retrieved documents to answer a question. A service may also retain content to provide conversation history, persistent files, background execution, safety monitoring or synchronized search. None of those operations automatically means the material becomes training data.

OpenAI also says automated classifiers and safety systems may analyze submitted business data and create metadata about it. Its documentation describes human review on a service-by-service basis rather than promising that no human could ever review any business interaction. Enterprise buyers should treat “not used for training by default” as a strong contractual starting point, not as a substitute for reading the retention and safety terms for the exact product they deploy.

The product strategy now brings AI to the data

Company Knowledge, introduced in October 2025, marked an important shift. Instead of requiring an employee to collect material manually, ChatGPT can search across sources such as Slack, SharePoint, Google Drive and GitHub. Responses show citations and the source snippets used. OpenAI says existing company permissions remain authoritative, so a user should only retrieve material that the user is already allowed to see.

Frontier, announced in February 2026, extends the same idea from search to managed AI coworkers. Each agent receives its own identity, explicit permissions and guardrails. This is a more appropriate security model than treating an autonomous agent as an invisible extension of an administrator account, but its effectiveness depends on how narrowly each identity and permission set is configured.

Secure MCP Tunnel, released in May, addresses a separate boundary. It allows ChatGPT, Codex, the Responses API and AgentKit to connect to private or on-premises MCP servers through a customer-hosted tunnel client. The internal server does not need to expose a public endpoint. The feature reduces public attack surface; it does not remove the need to authenticate tools, restrict methods and audit every system reachable through the tunnel.

ChatGPT Work and Presence push the model further into execution. Work can gather information from apps and files and continue complex assignments for hours. Presence supports production voice and chat agents in customer-facing and internal workflows. At this layer, data governance and action governance converge: the most consequential risk may be not what the agent reads, but what it can send, modify, approve or publish using that context.

Existing permissions help, but connected apps create new state

OpenAI says every user authenticates to connected applications and ChatGPT stays within that user’s existing permissions. Enterprise and Edu administrators can decide which apps are enabled and use role-based access controls to limit access. OAuth tokens are protected using audited key-management practices, while app conversations use restricted network access designed to keep traffic between OpenAI and the connected tools.

The important caveat is synchronization. OpenAI says chat and deep-research data from apps are processed transiently and are not indexed, while data from apps with sync is indexed to speed up answers. That index is operational state derived from an internal source. Its location and lifecycle must be evaluated alongside the original SharePoint, Drive or GitHub repository.

This is also why source permissions should be cleaned up before connecting an AI system. An agent that perfectly respects an overly broad “all employees” group will reproduce the organization’s existing access problem more efficiently. Permission-aware retrieval prevents new privilege escalation; it does not repair old privilege sprawl.

European residency separates storage from inference

OpenAI currently lists ten ChatGPT data-residency regions: Australia, Canada, Europe, India, Japan, Singapore, South Korea, the United Arab Emirates, the United Kingdom and the United States. For eligible new Enterprise and Edu workspaces, in-scope customer content—including conversations, files, custom GPTs, memory and data-analysis artifacts—can be stored at rest in the selected region.

Inference residency is narrower. As of 30 July 2026, OpenAI lists Europe, the United States and the United Arab Emirates as supported regions. Where enabled, GPU inference on covered customer content occurs in-region. This is a meaningful difference for European organizations: selecting European storage does not by itself prove that every model computation, system log or connected service remains in Europe.

The documentation also excludes account data, billing information, high-level usage statistics and certain operational metadata from the customer-content residency scope. New features are not automatically covered unless OpenAI adds them to the eligible list. Procurement teams should therefore document residency feature by feature, not rely on a workspace-level label alone.

API retention is an endpoint-level design decision

The API provides more control, but it also requires more careful architecture. OpenAI’s current data-control table says API data is not used for training. By default, abuse-monitoring logs for many endpoints may contain prompts and responses and are retained for up to 30 days, unless longer retention is legally required or reasonably necessary to protect the service or third parties.

Eligible customers can apply for Modified Abuse Monitoring or Zero Data Retention. Zero Data Retention excludes customer content from abuse-monitoring logs and forces store=false for the Responses and Chat Completions APIs. It is not a universal “nothing is stored” switch: some endpoints and capabilities are not eligible, some maintain application state until deletion, and temporary state can still exist while a hosted container or background task is active.

External services remain separate data processors. OpenAI explicitly notes that information sent to a remote MCP server is subject to that server’s retention policy. A company can therefore configure OpenAI correctly and still lose control through an inadequately governed tool, connector or downstream API.

Audit coverage is useful but not yet total

OpenAI’s Compliance API and workspace analytics give administrators visibility across Chat, Work and Codex. The current ChatGPT Work administrator documentation says the Compliance Logs Platform provides user prompts and agent responses and retains records for 30 days. Organizations that require longer history are advised to export continuously to an e-discovery, DLP, SIEM or data-lake system.

The same documentation says the Compliance Logs Platform does not track files, actions or tool calls. Elsewhere OpenAI describes broader signals, including tool and agent activity, that may be available through workspace analytics and connected monitoring. Security teams should not assume one log source reconstructs every step of an agent run. They should test the actual event coverage before treating it as a forensic record.

Auto-review in ChatGPT Work adds a preventive control: OpenAI says advanced models can inspect important connected-tool and API actions before they happen to reduce unauthorized sharing of sensitive information. That is a useful additional layer, but model review is not a replacement for deterministic permissions, transaction limits and human approval on high-impact actions.

What enterprise buyers should require

A defensible deployment begins by classifying workloads rather than buying one plan for everything. Ordinary internal drafting, confidential document retrieval, regulated records and agents authorized to change production systems should not share the same permissions or retention assumptions.

For each workflow, buyers should record the OpenAI product, enabled tools, connected sources, agent identity, allowed actions, retention policy, storage region, inference region, external processors and available audit events. API teams should verify endpoint eligibility for Zero Data Retention rather than assuming it applies organization-wide. App owners should determine whether synchronization creates an index and where that index is stored.

Finally, the company should test the controls with real scenarios: a departed employee, a confidential folder with inherited permissions, an agent attempting to send data to an unapproved domain, a prompt-injection instruction inside a connected document, and a forensic review after an action. Governance is credible only when those tests produce the expected denial, approval or audit trail.

Key Questions

Does OpenAI train on company data?

For ChatGPT Business, Enterprise, Edu, Healthcare, Teachers and the API, OpenAI says business data is not used for model training by default. A customer can explicitly opt in to share selected data or feedback.

Does “no training” mean OpenAI stores nothing?

No. Storage and training are separate. Chat history, files, synchronized app indexes, application state and abuse-monitoring logs may be retained depending on the product, configuration and API endpoint.

Can OpenAI keep European company data in Europe?

Eligible new Enterprise and Edu workspaces can select European data residency for covered customer content. Eligible customers can also use European inference residency so covered GPU processing occurs in Europe. The scope does not include every category of system or account data.

What is the most important new security product?

For organizations connecting private infrastructure, Secure MCP Tunnel is particularly significant because it avoids exposing an internal MCP server publicly. For agent governance at enterprise scale, Frontier’s separate identities, permissions and boundaries are the more strategic layer.

What should companies verify before deploying ChatGPT Work or Frontier?

They should verify source permissions, agent identities, enabled tools, allowed actions, app-index behavior, retention settings, residency scope, downstream processors and the exact events captured by compliance and security logs.

Primary sources: OpenAI Enterprise Privacy, Business Data Privacy and Security, ChatGPT Data and Inference Residency, API Data Controls, Company Knowledge, OpenAI Frontier, ChatGPT Work, OpenAI Presence, OpenAI API Changelog.

You May Also Like

Deep Research: Why Businesses Must Become Agent-Readable and Agent-Writable

Research compiled: March 23, 2026For: Thorsten Meyer / ThorstenmeyerAI.com Executive Summary The…

The EU General‑Purpose AI Code of Practice: Competition and Customer Impacts Across Verticals

Overview of the EU AI Act and the voluntary Code of Practice…

OpenAI’s gpt‑oss‑120b and gpt‑oss‑20b push the frontier of open‑weight reasoning models

Introduction and context OpenAI recently released gpt‑oss‑120b and gpt‑oss‑20b, a pair of…

Market Impact of the FTC’s Updated Endorsement Guides & Rule Banning Fake Reviews (2023–2025)

Introduction The U.S. Federal Trade Commission (FTC) revised its Guides Concerning the…