OpenAI AI Vendor Risk Profile
Creator of the GPT model family and ChatGPT, one of the most widely adopted AI platforms globally. Operates as a capped-profit entity under a nonprofit parent.
Risk overview
Risk score: 18/100
Risk tier: Low
Safety rating: 82/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 23/100 |
| IP Exposure | 17/100 |
| Jurisdiction | 13/100 |
| Security | 18/100 |
| Regulatory Compliance | 30/100 |
| Transparency | 10/100 |
| Business Stability | 16/100 |
| Dependency Chain | Not assessed |
| Agent Governance | 40/100 |
Analyst summary
Rating: Acceptable
OpenAI operates the most widely deployed AI models (GPT-5 family) and has the largest developer ecosystem in the industry. Its enterprise tier is enterprise-grade from a security standpoint, but consumer-tier data handling, training data provenance lawsuits, and deep Microsoft Azure dependency keep it from a clean bill of health.
Bottom line: Safe for most enterprises on the Team or Enterprise tier; treat the consumer tier as unfit for confidential data.
Strengths
- Industry-leading model capability, tooling, and ecosystem adoption
- SOC 2 Type II, ISO 27001, and HIPAA BAA available on Enterprise/Team and API tiers
- Copyright Shield indemnification covers ChatGPT Enterprise and API customers
- Mature enterprise controls: SSO, SCIM, audit logs, no-training guarantee, 30-day or custom retention
Concerns
- Consumer ChatGPT trains on user inputs by default (opt-out required)
- Active copyright lawsuits from NYT, Authors Guild, and music publishers over training data
- Sole-source infrastructure dependency on Microsoft Azure creates concentration risk
- US CLOUD Act exposure on customer data stored in US regions
Best for
- General-purpose code, text, and reasoning on Team or Enterprise plans
- Applications needing broad tool/plugin ecosystem and widest third-party integrations
- Teams that want fastest access to frontier models with acceptable enterprise controls
Avoid if
- You cannot accept US jurisdiction (CLOUD Act) on proprietary or regulated data
- You process healthcare data without a signed BAA and API tier
- Your legal team requires full training data provenance disclosure (publishing, media)
- You are using the consumer ChatGPT tier for anything sensitive
Citations
- Data Handling — Data Retention Period
OpenAI retains API inputs and outputs for up to 30 days to identify abuse, after which they are deleted (unless legally required to retain).
- Data Handling — Hipaa Baa Available
ChatGPT Enterprise and the API Platform are HIPAA-eligible and support Business Associate Agreements.
- Data Handling — Outputs Feed Model Improvement
You own your inputs and outputs. We do not train on your business data by default.
- Data Handling — Trains On User Data
We don't use content from our Business Services (ChatGPT Team, ChatGPT Enterprise, and the API Platform) to train our models.
- Ip Profiles — Copyright Shield Program
Copyright Shield: We will defend our customers and pay the costs incurred if they face legal claims around copyright infringement regarding generally available features of ChatGPT Enterprise or our developer platform.
- Ip Profiles — Known Ip Lawsuits
The New York Times sued OpenAI and Microsoft, accusing them of using millions of its articles without permission to train chatbots.
- Ip Profiles — User Owns Outputs
As between you and OpenAI, and to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output.
- Jurisdiction Profiles — Incorporation Country
OpenAI, LLC is a Delaware limited liability company headquartered in San Francisco, California.
- Security Compliance — Gdpr Compliant
OpenAI Ireland Limited is the data controller for users in the EEA, UK, and Switzerland, and provides a GDPR-compliant DPA for business customers.
- Security Compliance — Soc2 Type2
OpenAI has achieved SOC 2 Type 2 compliance, including an unqualified audit opinion covering security, availability, and confidentiality.