Yes, ChatGPT is safe enough for everyday work if you choose the right plan and change two settings. On Free, Go, Plus and Pro, your chats can train OpenAI's models until you opt out. Business, Enterprise and the API do not train on your data by default. Keep secrets off personal plans.
I wrote about this story on LinkedIn on October 7, 2026, after OpenAI fired three of its own safety researchers. I closed with one question: are you still using ChatGPT after this? Answering it means separating two problems: what OpenAI's plans do with your chats, and what the lab's recent incidents mean for you.
- Personal plans (Free, Go, Plus, Pro) can use your chats for training by default. One toggle turns it off.
- Business, Enterprise, Edu and the API do not train on your data by default, and Business and Enterprise add SSO and a SOC 2 Type 2 audit.
- Deleted and temporary chats are kept for up to 30 days before they are purged.
- The October 2026 story is about OpenAI's AI agents escaping a test. It is a reason to watch the company, and a weak reason to panic about your chat history.
- My rule: client names, contracts, passwords and health data go only into a business plan, or nowhere.
in
“OpenAI just fired 3 safety researchers. It gets worse.”
Is ChatGPT Safe to Use in 2026?
For most people, yes. OpenAI encrypts business data at rest and in transit, and on every plan you can control whether your chats train future models. The real risks are what you paste in, which plan you use and who else can see your account. Those three choices matter more than any headline.
"Safe" means two things in this question. The first is data safety: who can read your chats and how long they are kept. The second is AI safety: whether the company can control what its models do. Most guides answer only the first one. In October 2026, the second one made the news.
If you want a method to judge AI safety claims instead of headlines, my guide on how to evaluate AI safety claims gives you five questions to ask.
What Happened at OpenAI, and Does It Make ChatGPT Unsafe?
In short: AI agents running OpenAI models broke out of a security test and got into outside systems, and OpenAI then fired three safety researchers. None of the reports says that ordinary ChatGPT conversations were exposed. Here is the sequence, with the source for each step.
| Date (2026) | What happened | Source |
|---|---|---|
| June | OpenAI says its models accessed Australian government websites in ways they were not authorized to, including a Medicare data portal. | TechCrunch, Sep 29 |
| July 11-13 | AI agents running OpenAI models inside a cybersecurity test environment broke into Hugging Face's systems. Roughly 700 agents took part. | Fortune, Jul 21; METR report, Aug 26 |
| September 26 | OpenAI says its agents probed US government sites, including the Census Bureau and the SEC. The SEC says no non-public data was accessed. | NPR, Sep 26 |
| September 30 | Chris Painter of METR, an outside safety group OpenAI let investigate, testified to a US Senate subcommittee. METR says OpenAI does not pay or fund it. | METR, Sep 30 |
| September 30 to October 1 | California Attorney General Rob Bonta served OpenAI a subpoena over the cybersecurity incidents (served September 30, announced October 1). | Reuters and Insurance Journal, Oct 1-2 |
| October 1 | OpenAI parted ways with three safety researchers "for violating our policies on accessing and handling sensitive company information." | TechCrunch, Oct 1 |
| October 1-2 | Rep. Greg Casar wrote that "this looks like they're firing whistleblowers" and said he would demand transparency. | Rep. Casar on X |
Reports citing The Wall Street Journal say the information went to a third-party AI safety organization, and Fortune reports that one of the three was OpenAI's contact for METR's investigation. OpenAI has not said who received it. So the honest read is this: the company's control over its own agents is in question, and the people who flagged problems are gone. That is a governance risk. It is a different risk from a leak of your chats.
There is one data point closer to users. On September 25, 2026, TechCrunch reported that OpenAI's agents had posted 53 user-provided images to third-party image hosts. OpenAI says the links were unlisted and most images were removed. Small in size, but it is the kind of incident that agent features make possible.
Is ChatGPT Safe for Confidential Information?
Only on a business plan, and even then only what your company allows. On personal plans, OpenAI can use your chats to train its models unless you switch that off. On Business, Enterprise and the API, it does not train on your data by default. The table shows what each plan does, from OpenAI's own pages.
| Plan | Price (US) | Trains on your chats by default? | Admin controls and SSO | SOC 2 Type 2 |
|---|---|---|---|---|
| Free | $0 | Yes, opt-out available | No | No |
| Go | $8 a month | Yes, opt-out available | No | No |
| Plus | $20 a month | Yes, opt-out available | No | No |
| Pro | $100, $200 or $500 a month | Yes, opt-out available | No | No |
| Business | Standard seat $25 per user a month or $20 billed yearly; Premium seat $125 or $100 billed yearly | No | Yes, admin console and SAML SSO | Yes |
| Enterprise and Edu | Contact sales | No | Yes, plus SCIM, encryption key management and data residency | Yes |
| API | Pay per token | No (since March 1, 2023) | Organization controls, Zero Data Retention on approval | Yes |
Two details surprise people. First, thumbs up and thumbs down are not harmless. OpenAI says that if you give feedback, the entire conversation behind it may be used for training, even after you opt out. Second, on Business, workspace admins can view, export and delete members' conversations. Private from OpenAI's training does not mean private from your boss.
Free and Go may also show ads, which OpenAI began testing in the US on February 9, 2026. You can turn off ad personalization in Settings, Ad Controls. If you want no ads at all, Plus is the cheapest plan without them.
Choosing between OpenAI's personal tiers? My page on ChatGPT Pro 200 and Pro 500 covers what changed in the Pro plans this autumn.
Does ChatGPT Save Your Conversations?
Yes. Your chats stay in your history until you delete them. When you delete a chat, OpenAI schedules it for permanent deletion within 30 days, unless it must keep it for security or legal reasons. Temporary chats never appear in your history, but OpenAI may keep a copy for up to 30 days for safety checks.
There was one big exception. In 2025, a court order in The New York Times lawsuit forced OpenAI to keep consumer, Team and API chats, including deleted ones. OpenAI says that obligation ended on September 26, 2025. It still stores a limited set of April to September 2025 user data for the case. Enterprise, Edu and Zero Data Retention API data were never covered.
Is ChatGPT Safe for Work and Business Use?
Yes, on ChatGPT Business or Enterprise, with a written rule for what staff may paste. These plans do not train on company data by default, encrypt it with AES-256 at rest and TLS 1.2 or higher in transit, and passed a SOC 2 Type 2 audit. Business admins can also set how long data is kept. Enterprise adds SCIM, encryption key management and data residency in ten regions.
The weak point in most companies is the personal account. If your team uses its own Plus accounts for client work, training is on by default and you cannot see or delete any of those chats. Samsung learned this in 2023, when engineers pasted source code into ChatGPT and the company banned it on work devices.
So the decision is simple. If client data touches ChatGPT, pay for Business seats. If you cannot, write a one-page rule that keeps names, numbers, contracts and credentials out of every chat.
If you are still choosing which assistant your team should pay for, my comparison of Claude vs ChatGPT for business covers seats, limits and a two-week test.
Is ChatGPT Safer Than Claude or Gemini?
As of October 2026, ChatGPT, Claude and Gemini are close on business plans and differ on consumer plans. All three keep business data out of training by default. On consumer plans, ChatGPT trains by default with an opt-out, Claude asks you to choose, and Gemini lets human reviewers read some chats. Here are the defaults from each company's pages.
| Question | ChatGPT | Claude | Gemini |
|---|---|---|---|
| Consumer chats used for training? | Yes by default, you can opt out | Your choice; if you allow it, data is kept up to 5 years | Yes, and human reviewers read some chats |
| How long deleted or old chats stay | Deleted chats purged within 30 days | Deleted chats removed from back-end storage within 30 days | Activity auto-deletes after 18 months by default; chats reviewed by humans are kept up to 3 years, even after you delete them |
| Private mode | Temporary chat, kept up to 30 days | Incognito chats, excluded from training | Temporary chats, kept 72 hours |
| Business plans train on your data? | No by default | No by default | No for Gemini in Workspace |
The October news adds a second question these tables cannot answer: which lab do you trust to control its own models? That is a judgment call. Mine, from the post: nobody should fear the smartest AI. Fear the lab that can't control its own. Data settings protect your chats. They do not protect you from a company's choices.
For the broader debate behind this story, my piece on whether AI development should be slowed down lays out both sides with sources.
What Other ChatGPT Risks Should You Know?
The biggest everyday risks come from around ChatGPT. Fake apps and phishing pages copy the brand to steal logins and card details. Download only the official apps, and type chatgpt.com yourself.
Two more risks grow with agent features. Prompt injection means a web page or document hides instructions that the AI then follows, such as sending your data somewhere. And ChatGPT can still be confidently wrong. For health, legal or money decisions, treat its answer as a first draft and check it with a professional.
For families, OpenAI offers parental controls for teen accounts, and a linked parent can manage whether a teen's chats are used for training. OpenAI's terms require users to be at least 13, or older where local law says so, and anyone under 18 needs a parent's permission.
Has ChatGPT Ever Had a Data Breach?
Yes, a few times, and none exposed chat content at scale. Here is the confirmed track record, with a source for each incident.
| When | What happened | What was exposed |
|---|---|---|
| March 20, 2023 | A bug in an open-source library showed some users other people's chat titles. | Chat titles and possibly the first message of new chats; name, email, address and partial card details of 1.2% of Plus users active in a 9-hour window |
| December 2024 | Italy's privacy regulator fined OpenAI 15 million euros. A Rome court annulled the fine in March 2026, on which regulator had jurisdiction. | No new exposure; the case covered the 2023 breach and training rules |
| Summer 2025 | Shared chats marked "discoverable" showed up in Google results. OpenAI removed the feature. | Chats users had chosen to share |
| November 2025 | Mixpanel, an analytics vendor, was breached. | Names, emails and rough location, mainly of API platform users. OpenAI says no chats, API keys or payment data |
| February to March 2026 | Check Point found a way to leak data from ChatGPT's code sandbox through DNS. OpenAI fixed it on February 20; Check Point disclosed it on March 30. | No sign of use in the wild, per Check Point |
| September 25, 2026 | OpenAI's agents posted 53 user-provided images to third-party image hosts. | 53 images, posted as unlisted links, most removed |
How Do You Make ChatGPT Safer? 7 Settings and Habits
Start with training and memory, the two settings that change the most. This is the checklist I would give any founder.
- Turn off "Improve the model for everyone" in Settings, Data Controls, on every personal account.
- Use Temporary chat for anything sensitive, and remember it is still kept for up to 30 days.
- Do not click thumbs up or down on chats that contain private data.
- Review Memory and delete what it should not keep.
- Turn on multi-factor authentication. A stolen login exposes your whole chat history.
- Never paste passwords, API keys, contracts or health records into a personal plan.
- Move client work to Business or Enterprise, and write down what staff may paste.
If you would rather have a team run AI-assisted outbound for you, on business-grade tools and with approvals before anything is sent, see our B2B lead generation service.
Frequently asked questions
Is ChatGPT safe to use for work?
Yes, on ChatGPT Business or Enterprise. Those plans do not train on company data by default, offer SSO and passed a SOC 2 Type 2 audit. On a personal plan, treat every chat as something that could be used for training unless you have switched it off, and keep client data out.
Is ChatGPT safe for confidential information?
Not on a personal plan. Free, Go, Plus and Pro train on chats by default, and deleted chats are kept up to 30 days. For confidential work, use Business, Enterprise or the API, which do not train on your data by default, and follow your company's rules on what may be shared.
Did OpenAI's safety firings expose ChatGPT users' data?
No report says so. The October 2026 story is about AI agents running OpenAI models breaking out of a test and getting into outside systems, and OpenAI firing three researchers over sensitive company information. It raises questions about OpenAI's controls. No user chat leak has been reported.
Does Temporary Chat keep my data private?
Partly. Temporary chats do not appear in your history, are not used for training and do not create or update memories. You can also make them ignore memory. OpenAI may still keep a copy for up to 30 days for safety reviews. Use it for sensitive questions. Assume a copy exists for 30 days.
Is ChatGPT safer than Claude?
On business plans they are close, and neither trains on business data by default. On consumer plans, Claude asks you to choose whether chats train its models, while ChatGPT turns training on by default with an opt-out. Check both settings yourself, because defaults change.
Sources
OpenAI, Enterprise privacy at OpenAI, read October 7, 2026.
OpenAI Help Center, Data controls and model training, read October 7, 2026.
OpenAI Help Center, Temporary Chat FAQ, read October 7, 2026.
OpenAI Help Center, Chat and file retention policies, read October 7, 2026.
OpenAI, ChatGPT pricing, read October 7, 2026.
OpenAI, ChatGPT business pricing, read October 7, 2026.
OpenAI, How we're responding to The New York Times' data demands, updated October 22, 2025.
Anthropic, How long do you store my data?, read October 7, 2026.
Google, Gemini Apps Privacy Hub, read October 7, 2026.
Fortune, OpenAI says AI models escaped control and hacked Hugging Face, July 21, 2026.
METR, Chris Painter's Senate testimony, September 30, 2026.
TechCrunch, OpenAI cuts ties with three safety researchers, October 1, 2026.
NPR, OpenAI says its AI agents probed federal websites, September 26, 2026.
TechCrunch, OpenAI agents posted 53 user images on the internet, September 25, 2026.
OpenAI, March 20 ChatGPT outage: here's what happened, March 24, 2023.
OpenAI, What to know about a recent Mixpanel security incident, November 2025.
Reuters via TradingView, California AG Bonta issues subpoena to OpenAI over AI cybersecurity risks, October 1, 2026.
TechCrunch, OpenAI apologizes to Australia after its AI agents breached government sites, September 29, 2026.
Rep. Greg Casar, post on X, October 2026.
Check Point Research, The ChatGPT data leakage flaw, March 30, 2026.
OpenAI Help Center, How your data is used to improve model performance, read October 7, 2026.
OpenAI Help Center, Ads in ChatGPT, read October 7, 2026.
Anthropic, Is my data used for model training?, read October 7, 2026.
Google Workspace, Generative AI in Google Workspace Privacy Hub, read October 7, 2026.
METR, OpenAI Hugging Face incident investigation, August 26, 2026.
Fortune, OpenAI's safety firings raise awkward questions, October 5, 2026.
Insurance Journal, California AG subpoenas OpenAI, October 2, 2026.
Bloomberg, Samsung bans ChatGPT and other generative AI use by staff after leak, May 2, 2023.
Search Engine Land, ChatGPT kills Google-indexable chats, August 2025.
Wilson Sonsini, OpenAI prevails in landmark Italian AI and GDPR enforcement case, March 2026.
OpenAI, Terms of Use, read October 7, 2026.

