OpenAI says it does not train its models on business data by default. New products including ChatGPT Work, Frontier, Company Knowledge, Presence and Secure MCP Tunnel make the rest of the data-governance picture more important.
TL;DR
OpenAI’s central enterprise promise is clear: by default, it does not use data from ChatGPT Business, Enterprise, Edu, Healthcare or the API to train its models. Business customers retain control of their inputs and outputs, while OpenAI encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher.
That promise does not mean every enterprise interaction is stateless or that no information is ever stored. Retention depends on the product, feature and API endpoint. Connected apps can create synchronized search indexes, API abuse-monitoring logs are normally retained for up to 30 days, and third-party MCP servers apply their own policies. OpenAI’s 2026 product strategy therefore rests on several separate controls: training exclusion, access permissions, retention settings, regional storage and inference, network boundaries, and auditability.
OpenAI has spent the past year moving from a protected workplace chatbot toward an operating layer for enterprise agents. Company Knowledge searches across internal applications. OpenAI Frontier assigns agents identities, permissions and boundaries. ChatGPT Work can act across files and applications for hours. OpenAI Presence puts voice and chat agents into customer and internal workflows. Secure MCP Tunnel connects those products to private or on-premises systems without publishing the internal server to the internet.
Enterprise data governance · July 2026
Inside OpenAI’s Enterprise Data Stack
What happens to company data when ChatGPT and AI agents search internal apps, run tools and work across private systems.
Applies to covered business products and the API; explicit opt-in can change the rule.
Storage at rest for eligible Enterprise and Edu customers.
Europe, United States and UAE for eligible configurations.
Eligible customers can apply for Modified Abuse Monitoring or Zero Data Retention.
01 · Four separate questions

PBN-TEC Private Browser & Password Manager Software Portable
- Secure Private Browsing: Protects your online activity on any device
- All-in-One Privacy Toolkit: Includes private browser, anonymous browsing, and password manager
- Portable USB Solution: Carry your privacy tools on a USB drive
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
“No training” is not “no storage”
A credible review separates model training, service processing, data retention and access control.
Training
Used to improve future models?
OpenAI says business data is not used for training by default. Explicitly shared feedback may be used when a customer opts in.
Default · ExcludedProcessing
Handled to produce an answer?
Prompts, files and retrieved context must be processed for inference, safety checks and the requested tools to work.
Required for the serviceRetention
Stored after processing?
The answer varies by plan, feature, endpoint, chat settings, synchronized index and approved data-retention control.
Configuration dependentAccess
Who can retrieve or act?
Workspace roles, app permissions, agent identity and tool policies determine what context is visible and what actions are allowed.
Permission controlled02 · The new enterprise stack

Non-Invasive Data Governance Unleashed: Empowering People to Govern Data and AI
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
From protected chat to governed agents
OpenAI’s recent products add internal search, agent identity, private connectivity and execution.
October 2025
Company Knowledge
Searches across connected apps, respects source permissions and returns citations to original material.
RetrieveFebruary 2026
OpenAI Frontier
Builds and manages AI coworkers with separate identities, explicit permissions, guardrails and feedback.
GovernMay 2026
Secure MCP Tunnel
Connects supported products to private or on-prem MCP servers without a public server endpoint.
ConnectJuly 2026
ChatGPT Work
Works across apps and files, runs multi-hour assignments and turns goals into finished deliverables.
ActJuly 2026
OpenAI Presence
Deploys production voice and chat agents across customer-facing and internal operational workflows.
Operate2026 control layer
Compliance + Review
Provides prompts and responses for oversight; auto-review can inspect important actions before execution.
ObserveThe strategic shift
More context → more useful agents → more governance required
03 · Connected data flow

BUFFALO LinkStation 210 2TB 1-Bay NAS Network Attached Storage with HDD Hard Drives Included NAS Storage that Works as Home Cloud or Network Storage Device for Home
- Centralized Storage with RAID: RAID-enabled NAS for backup and storage
- Easy Network Connection: Connect to router for shared device access
- Compatible with Windows and macOS: Supports Windows and older macOS versions
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Permissions travel with the user
ChatGPT should retrieve only what the authenticated user or agent identity may already access.
Identity
User or AI coworker
Permission
Role + source ACLs
Retrieval
Apps + private tools
AI inference
Answer, artifact or action
Where new state can appear
Chat history
Conversations, files, memory and custom GPT content follow workspace retention settings.
Policy controlledSynced index
App data with sync can be indexed to accelerate answers. Region support must be checked.
App dependentAPI state
Abuse logs, stored responses, files and containers have endpoint-specific lifecycles.
Endpoint dependentThird parties
Remote MCP servers and other tools apply their own retention and security policies.
Separate processor04 · Location controls

AI Workflow Automation for Bloggers: Build a Simple Content System to Research, Write, Optimize, and Repurpose Posts Faster with AI and No-Code Tools (AI Toolkit for Bloggers 2026 Book 8)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Storage residency ≠ inference residency
The region used to save covered content can differ from the region where GPU inference runs.
Data residency · Storage at rest
- Europe (EEA + Switzerland)
- India
- United States
- Japan
- United Kingdom
- Singapore
- Canada
- South Korea
- Australia
- United Arab Emirates
Chats · files · memory · custom GPTs · analysis artifacts · image inputs and outputs
Inference residency · GPU execution
- Europe
- United States
- United Arab Emirates
05 · Claims vs. operational reality
What each control actually answers
06 · Enterprise buyer checklist
Govern the workflow, not only the model
For every deployment, record the complete chain of access, state and accountability.
- Product, model and exact enabled features
- Retention setting for every endpoint
- Connected sources and synchronized indexes
- Storage region and inference region
- User or agent identity and allowed actions
- Third-party processors and audit coverage
Each step increases the value of the system because the model can see more context and take more useful actions. It also changes the governance problem. Security teams are no longer reviewing only what an employee pastes into a chat box. They must decide which repositories can be connected, whose credentials an agent may use, what actions it may take, where temporary state is created, and which events appear in compliance logs.
The useful way to evaluate OpenAI’s enterprise data posture is therefore not to ask one question—“Do you train on our data?”—but six: What is used for training? What is retained? Where is it stored? Where is inference performed? Who can retrieve it? And what can administrators reconstruct afterward?
At a glance
REPORT
WHEN: OpenAI documentation and product releases reviewed through 30 July 2026.
THE DEVELOPMENT: OpenAI has expanded its enterprise offering from protected chat into a governed agent stack that can search, retrieve and act across internal systems.
“No training” is the first layer, not the whole answer
OpenAI’s enterprise privacy commitment covers inputs and outputs from ChatGPT Business, Enterprise, Healthcare, Edu, Teachers and the API Platform. OpenAI says it does not train its models on that business data by default. If a customer explicitly opts in—for example through a feedback mechanism—the shared material may be used to improve models.
That distinction matters because training, processing and storage are different operations. A model must process a prompt and any retrieved documents to answer a question. A service may also retain content to provide conversation history, persistent files, background execution, safety monitoring or synchronized search. None of those operations automatically means the material becomes training data.
OpenAI also says automated classifiers and safety systems may analyze submitted business data and create metadata about it. Its documentation describes human review on a service-by-service basis rather than promising that no human could ever review any business interaction. Enterprise buyers should treat “not used for training by default” as a strong contractual starting point, not as a substitute for reading the retention and safety terms for the exact product they deploy.
The product strategy now brings AI to the data
Company Knowledge, introduced in October 2025, marked an important shift. Instead of requiring an employee to collect material manually, ChatGPT can search across sources such as Slack, SharePoint, Google Drive and GitHub. Responses show citations and the source snippets used. OpenAI says existing company permissions remain authoritative, so a user should only retrieve material that the user is already allowed to see.
Frontier, announced in February 2026, extends the same idea from search to managed AI coworkers. Each agent receives its own identity, explicit permissions and guardrails. This is a more appropriate security model than treating an autonomous agent as an invisible extension of an administrator account, but its effectiveness depends on how narrowly each identity and permission set is configured.
Secure MCP Tunnel, released in May, addresses a separate boundary. It allows ChatGPT, Codex, the Responses API and AgentKit to connect to private or on-premises MCP servers through a customer-hosted tunnel client. The internal server does not need to expose a public endpoint. The feature reduces public attack surface; it does not remove the need to authenticate tools, restrict methods and audit every system reachable through the tunnel.
ChatGPT Work and Presence push the model further into execution. Work can gather information from apps and files and continue complex assignments for hours. Presence supports production voice and chat agents in customer-facing and internal workflows. At this layer, data governance and action governance converge: the most consequential risk may be not what the agent reads, but what it can send, modify, approve or publish using that context.
Existing permissions help, but connected apps create new state
OpenAI says every user authenticates to connected applications and ChatGPT stays within that user’s existing permissions. Enterprise and Edu administrators can decide which apps are enabled and use role-based access controls to limit access. OAuth tokens are protected using audited key-management practices, while app conversations use restricted network access designed to keep traffic between OpenAI and the connected tools.
The important caveat is synchronization. OpenAI says chat and deep-research data from apps are processed transiently and are not indexed, while data from apps with sync is indexed to speed up answers. That index is operational state derived from an internal source. Its location and lifecycle must be evaluated alongside the original SharePoint, Drive or GitHub repository.
This is also why source permissions should be cleaned up before connecting an AI system. An agent that perfectly respects an overly broad “all employees” group will reproduce the organization’s existing access problem more efficiently. Permission-aware retrieval prevents new privilege escalation; it does not repair old privilege sprawl.
European residency separates storage from inference
OpenAI currently lists ten ChatGPT data-residency regions: Australia, Canada, Europe, India, Japan, Singapore, South Korea, the United Arab Emirates, the United Kingdom and the United States. For eligible new Enterprise and Edu workspaces, in-scope customer content—including conversations, files, custom GPTs, memory and data-analysis artifacts—can be stored at rest in the selected region.
Inference residency is narrower. As of 30 July 2026, OpenAI lists Europe, the United States and the United Arab Emirates as supported regions. Where enabled, GPU inference on covered customer content occurs in-region. This is a meaningful difference for European organizations: selecting European storage does not by itself prove that every model computation, system log or connected service remains in Europe.
The documentation also excludes account data, billing information, high-level usage statistics and certain operational metadata from the customer-content residency scope. New features are not automatically covered unless OpenAI adds them to the eligible list. Procurement teams should therefore document residency feature by feature, not rely on a workspace-level label alone.
API retention is an endpoint-level design decision
The API provides more control, but it also requires more careful architecture. OpenAI’s current data-control table says API data is not used for training. By default, abuse-monitoring logs for many endpoints may contain prompts and responses and are retained for up to 30 days, unless longer retention is legally required or reasonably necessary to protect the service or third parties.
Eligible customers can apply for Modified Abuse Monitoring or Zero Data Retention. Zero Data Retention excludes customer content from abuse-monitoring logs and forces store=false for the Responses and Chat Completions APIs. It is not a universal “nothing is stored” switch: some endpoints and capabilities are not eligible, some maintain application state until deletion, and temporary state can still exist while a hosted container or background task is active.
External services remain separate data processors. OpenAI explicitly notes that information sent to a remote MCP server is subject to that server’s retention policy. A company can therefore configure OpenAI correctly and still lose control through an inadequately governed tool, connector or downstream API.
Audit coverage is useful but not yet total
OpenAI’s Compliance API and workspace analytics give administrators visibility across Chat, Work and Codex. The current ChatGPT Work administrator documentation says the Compliance Logs Platform provides user prompts and agent responses and retains records for 30 days. Organizations that require longer history are advised to export continuously to an e-discovery, DLP, SIEM or data-lake system.
The same documentation says the Compliance Logs Platform does not track files, actions or tool calls. Elsewhere OpenAI describes broader signals, including tool and agent activity, that may be available through workspace analytics and connected monitoring. Security teams should not assume one log source reconstructs every step of an agent run. They should test the actual event coverage before treating it as a forensic record.
Auto-review in ChatGPT Work adds a preventive control: OpenAI says advanced models can inspect important connected-tool and API actions before they happen to reduce unauthorized sharing of sensitive information. That is a useful additional layer, but model review is not a replacement for deterministic permissions, transaction limits and human approval on high-impact actions.
What enterprise buyers should require
A defensible deployment begins by classifying workloads rather than buying one plan for everything. Ordinary internal drafting, confidential document retrieval, regulated records and agents authorized to change production systems should not share the same permissions or retention assumptions.
For each workflow, buyers should record the OpenAI product, enabled tools, connected sources, agent identity, allowed actions, retention policy, storage region, inference region, external processors and available audit events. API teams should verify endpoint eligibility for Zero Data Retention rather than assuming it applies organization-wide. App owners should determine whether synchronization creates an index and where that index is stored.
Finally, the company should test the controls with real scenarios: a departed employee, a confidential folder with inherited permissions, an agent attempting to send data to an unapproved domain, a prompt-injection instruction inside a connected document, and a forensic review after an action. Governance is credible only when those tests produce the expected denial, approval or audit trail.
Key Questions
Does OpenAI train on company data?
For ChatGPT Business, Enterprise, Edu, Healthcare, Teachers and the API, OpenAI says business data is not used for model training by default. A customer can explicitly opt in to share selected data or feedback.
Does “no training” mean OpenAI stores nothing?
No. Storage and training are separate. Chat history, files, synchronized app indexes, application state and abuse-monitoring logs may be retained depending on the product, configuration and API endpoint.
Can OpenAI keep European company data in Europe?
Eligible new Enterprise and Edu workspaces can select European data residency for covered customer content. Eligible customers can also use European inference residency so covered GPU processing occurs in Europe. The scope does not include every category of system or account data.
What is the most important new security product?
For organizations connecting private infrastructure, Secure MCP Tunnel is particularly significant because it avoids exposing an internal MCP server publicly. For agent governance at enterprise scale, Frontier’s separate identities, permissions and boundaries are the more strategic layer.
What should companies verify before deploying ChatGPT Work or Frontier?
They should verify source permissions, agent identities, enabled tools, allowed actions, app-index behavior, retention settings, residency scope, downstream processors and the exact events captured by compliance and security logs.
Primary sources: OpenAI Enterprise Privacy, Business Data Privacy and Security, ChatGPT Data and Inference Residency, API Data Controls, Company Knowledge, OpenAI Frontier, ChatGPT Work, OpenAI Presence, OpenAI API Changelog.