Neither vendor trains on business data by default. OpenAI states that it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API, and Anthropic says the same for Claude for Work and its API. Personal plans are the opposite: OpenAI uses content from its individual services for training unless the person turns it off, and Anthropic's privacy policy effective 8 July 2026 says it may train on inputs and outputs unless you opt out in account settings. That gap is the whole problem, because most company data that reaches an AI does not go through the account you approved. Verizon's 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% a year earlier, and that 67% of them reach AI services from non-corporate accounts. So the rollout is the control: verify your domain, turn on single sign-on, claim or block the personal accounts you can find, close the feedback exception that overrides an opt-out, set a retention window, and write down the things - browser extensions, personal webmail signups, data already in a training run - that you are simply not going to control.

