Task guide

Roll out AI without the leak.
Plan by plan, control by control.

The honest answer to "does it train on our data" is a table, not a sentence. It depends on the vendor, the plan, and whether anyone on your team has ever clicked thumbs up.

00

The short answer.

Neither vendor trains on business data by default. OpenAI states that it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API, and Anthropic says the same for Claude for Work and its API. Personal plans are the opposite: OpenAI uses content from its individual services for training unless the person turns it off, and Anthropic's privacy policy effective 8 July 2026 says it may train on inputs and outputs unless you opt out in account settings. That gap is the whole problem, because most company data that reaches an AI does not go through the account you approved. Verizon's 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% a year earlier, and that 67% of them reach AI services from non-corporate accounts. So the rollout is the control: verify your domain, turn on single sign-on, claim or block the personal accounts you can find, close the feedback exception that overrides an opt-out, set a retention window, and write down the things - browser extensions, personal webmail signups, data already in a training run - that you are simply not going to control.

AI without the leak at a glance
At a glance 
Does it train on our data?Not on the business tiers. OpenAI does not train on ChatGPT Business, ChatGPT Enterprise or API content by default, and Anthropic does not train on Claude for Work or API content by default. Personal plans on both vendors are the reverse.
The exception nobody readsFeedback. On both vendors, submitting a thumbs up or down can put the whole conversation into training even when training is otherwise off, and Anthropic retains feedback data for up to five years. An owner can switch rating off org-wide on Claude.
Who has to approve itWhoever owns DNS. Domain verification is the prerequisite for single sign-on and for claiming personal accounts, and it is exclusive: once one organisation verifies a domain, no other can.
What single sign-on needsLess than people expect. SSO is available on ChatGPT Business and on Claude Team, so it is not gated behind an Enterprise contract. SCIM provisioning is the thing that is Enterprise-only on both.
How long data is keptClaude for Work keeps conversations indefinitely unless an Enterprise admin sets a custom window, with a 30-day minimum. Deleted chats on both vendors clear back-end storage within 30 days.
Time to set upA week for the controls that exist. Longer if you need zero data retention or non-US residency, because both require the vendor's prior approval rather than a toggle.
Biggest limitationYou cannot claim an account you cannot see. Domain claiming only reaches accounts registered on a domain you own, so anyone who signed up with personal webmail stays invisible to you.
01

Side by side.

The rows are the controls a security review actually asks for. The columns are what you can buy. This is the table that decides whether you are on the right tier, and the honest headline is that the jump from a business plan to an enterprise one is mostly a jump in what you can export and prove.

AI without the leak: what each option can and cannot do
CapabilityPersonal accountsWhat you have nowChatGPT BusinessOpenAIChatGPT EnterpriseOpenAIClaude TeamAnthropicClaude EnterpriseAnthropicBeagleUs
Excluded from model training by defaultNoOff by hand, per personYesYesYesYesYesCommercial API terms
Single sign-onNoYesYesYesYesPartlySlack or Google identity
SCIM provisioningNoNoManual onlyYesNoJust-in-time onlyYesNo
Claim personal accounts on your domainNoNoUser-initiatedYesCancels their personal subNoBlocks new ones onlyYesFixed 30-day windowNoNot applicable
Audit log or compliance exportNoPartlyAdmins can read chatsYesLogs kept 30 daysNoYes180 days, no contentPartlyActivity feed
Set your own retention windowNo30 days after you deleteNoYesAdmin-controlledNoIndefinite by defaultYes30-day minimumNo
Zero data retention availableNoNoYesSales approval neededNoYesSales approval neededNo
Data stored in the EUNoNoYesNew workspace onlyNoNoUS only, or via a cloudNo
02

What each one actually is.

Four tiers and the thing you are actually replacing. Read these as a ladder: each rung buys a specific control, and knowing which rung you need is cheaper than buying the top one by reflex.

03

Step by step.

A week's work, in the order that stops you undoing something. Two of these steps are one-way doors, and they are both in the first three days, so read before you click.

  1. Verify your domain, from the organisation you mean to keep

    Domain verification is the prerequisite for single sign-on and for claiming accounts, and on ChatGPT it is exclusive: once one organisation has verified a domain, no other organisation can, which can block a sibling org on the same email domain from setting up SSO at all. Decide which workspace is the real one before you verify, not after.

    One-way doorExclusive per organisation, and not casually undone

  2. Turn on single sign-on, which is cheaper than you think

    SSO is available on ChatGPT Business and on Claude Team, not only on the enterprise tiers, so there is no reason to run an unauthenticated pilot while you wait for procurement. Note the gap that remains: SCIM provisioning is Enterprise-only on both vendors, so on the lower tiers deprovisioning is a manual step somebody has to own.

    NoteClaude Team gets just-in-time provisioning, not SCIM

  3. Deal with the personal accounts that already exist

    On Claude Enterprise, domain claiming finds existing Free, Pro and Max accounts on a verified domain and migrates them. Budget for it: the migration window is a fixed 30 days, it cannot be customised, and accounts that do not migrate are deactivated with subscriptions cancelled and prorated. On ChatGPT Enterprise an invited user on a verified domain is prompted to migrate and their personal paid subscription is cancelled as part of it. On the business tiers you can ask, but you cannot enforce.

    Communicate firstThe window is 30 days and it is not adjustable

  4. Close the feedback exception

    This is the control most rollouts miss. Both vendors carve feedback out of the no-training default: a thumbs up or down can put the entire associated conversation into training even for an opted-out user, and Anthropic retains that data for up to five years. On Claude an owner can turn rating off for the whole organisation. On ChatGPT there is no equivalent switch, so it has to be a briefing.

    WhereClaude: Organization settings, Data and privacy, Rate chats

  5. Audit connectors and sharing, because the defaults differ

    Apps and connectors are enabled by default on ChatGPT Business but disabled by default on Enterprise and Edu, which surprises teams who assume the cheaper tier is the more locked-down one. On Claude, public projects are enabled by default on both Team and Enterprise and can be disabled org-wide. Do this before the first sensitive document goes in, not after.

  6. Set retention deliberately rather than by default

    Claude for Work keeps conversations indefinitely unless an Enterprise admin sets a custom period, with a 30-day floor. Be careful the first time: saving a shorter window deletes everything outside it immediately and irrecoverably. On ChatGPT Enterprise and Edu, retention duration is admin-controlled and deleted conversations clear within 30 days.

    IrreversibleShortening the window deletes out-of-window data on save

  7. Send the logs somewhere you actually keep them

    Both compliance surfaces are Enterprise-tier, and both are shorter-lived than your retention policy probably is. OpenAI's compliance log platform keeps 30 days. Claude's audit log export looks back 180 days, carries identifiers rather than chat content, and arrives as an emailed CSV link valid for 24 hours. Wire them into your existing tooling and archive on your side.

  8. Write down what you are not controlling

    A control list is only honest if it has a second half. You cannot see accounts registered on personal webmail. You cannot pull data back out of a model that has already trained on it. You cannot opt out of safety retention. And you cannot rely on approval prompts at scale - Anthropic measured 93% blanket approval of Claude Code permission prompts before it added operating-system sandboxing.

04

What trips people up.

The specific things that are wrong in most internal AI policies right now, including one that was true a year ago and is not any more.

Most company data does not leak through the AI you approved. It leaves through the one somebody signed up for on a Tuesday, on their own card, in a browser tab you cannot see.
05

Or skip the build.

The durable fix for shadow AI is not a stricter policy, it is a sanctioned thing that is better than the unsanctioned one. Beagle is built for that shape: it lives where the work already is, so there is less reason to paste anything anywhere.

01

Nothing to paste in the first place

Beagle reads the CRM record, the thread and the ticket directly, so the context never has to be copied out of a system of record into a chat window on someone's personal account.

02

It runs on your existing grants, not a new pool of data

Every connection is your own OAuth, so Beagle reaches exactly what you reach and nothing more. Tools can be switched off one at a time when you want a narrower blast radius on a particular connection.

03

Every outbound action waits for a human

Drafts, replies, updates and record changes are all held for approval. The design assumption is the one Anthropic's own data supports: that the person will click yes, so the limit has to be somewhere other than the click.

04

One accountable account, not forty invisible ones

Work happens in the channel where the team already is, which means it is visible to the team by default. That is a weaker guarantee than an audit log and a stronger one than hoping nobody opened a private tab.

06

Plugged into your stack.

OAuth in, every read scoped to the teammate who asked.

See every integration

07

Common questions.

Does ChatGPT train on my company's data?

Not on the business products. OpenAI states that by default it does not train on any inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API. Individual plans are the opposite: content from OpenAI's services for individuals may be used to train models unless the person switches it off under Settings, Data controls, Improve the model for everyone. Two exceptions survive the toggle on every plan - submitting feedback on a conversation can put the whole conversation into training, and support conversations may be used to improve models if training is enabled.

Does Claude train on our data?

Not on the commercial products. Anthropic states that by default it will not use inputs or outputs from Claude for Work, the API or Claude Gov to train models. Consumer plans are different: the privacy policy effective 8 July 2026 says Anthropic may use inputs and outputs for training unless you opt out in account settings, and users who allow it move from 30-day retention to five-year retention. The exception on commercial plans is feedback, which an organisation owner can disable by turning off chat rating.

Is the New York Times court order still forcing OpenAI to keep our deleted chats?

No, not on a going-forward basis. The May 2025 preservation order was terminated as of 26 September 2025 by a stipulation entered on 9 October 2025. Output log data OpenAI had already segregated before that date is still preserved, with a carve-out for requests originating in the EEA, Switzerland and the UK, and preservation continues going forward for accounts associated with roughly ninety named news-publisher domains. If your AI policy still cites the order as a current reason to avoid ChatGPT, it needs updating.

What is the difference between ChatGPT Business and Enterprise for security?

Both exclude your data from training by default and both support single sign-on. Enterprise adds the things a formal security review asks for: SCIM provisioning, custom roles, admin-controlled retention, the compliance platform and its integrations with tools like Purview and Netskope, data residency, business associate agreements and zero data retention on request. There is also a default worth knowing: connectors are enabled by default on Business and disabled by default on Enterprise.

Can we get EU data residency for Claude or ChatGPT?

For ChatGPT, yes. OpenAI offers data residency in Europe and several other regions for Enterprise, Edu and eligible API customers, with the caveat that it must be configured on a new workspace rather than added to an existing one, and that inference residency is a narrower list than storage residency. For Claude, not directly. The only workspace geography on Anthropic's own platform is the US and it cannot be changed after creation, so European residency for Claude runs through AWS Bedrock, Google Cloud Vertex or Microsoft Foundry regional endpoints instead.

What can we not control, however much we spend?

Four things, and a policy that pretends otherwise will be ignored. You cannot find or claim accounts your staff registered with personal webmail, because domain claiming only reaches domains you own. You cannot retract data from a model that has already been trained on it. You cannot opt out of safety retention: both vendors keep policy-violation material and classifier results well beyond their normal windows, and Anthropic does so even under a zero-data-retention agreement. And you cannot treat an approval prompt as a hard control once people are used to it.

The best control
is a better option.