Every week a client asks me some version of the same question: our staff are already using ChatGPT, so are we exposed? It is a fair question, and the honest answer is more interesting than a simple yes or no.
ChatGPT is safe for business use on its Enterprise, Business, and API tiers with the right settings configured, and it is not safe for company data on free or personal accounts where conversations can be used to train models. That one distinction explains most of the confusion, most of the risk, and most of the fix. Let me walk through what actually matters for an Australian organisation in 2026.
Is ChatGPT safe for company data?
The tool itself is reasonably secure, but the way most staff reach for it is not. The gap is rarely a hacker breaking into OpenAI. It is an employee pasting a customer list, a contract, or a block of proprietary code into a free personal account to save twenty minutes.
The numbers here are sobering. Analysis of enterprise usage found that around 34.8 percent of the data employees paste into ChatGPT is sensitive, up from about 11 percent in 2023. That includes personally identifiable information, health data, source code, internal meeting notes, and financial projections. Separate reporting found that a large majority of AI users copy and paste content directly into chatbots, often through accounts their employer never sanctioned. This is the shadow AI problem, and it is where nearly all real exposure comes from.
The lesson is not “ban ChatGPT”. Banning it just pushes usage onto personal phones and home accounts where you have zero visibility. The lesson is to give people a safe, sanctioned place to work.
Does ChatGPT train on my data?
On free and personal plans it can, and on business plans it does not by default. This is the heart of the matter, so it is worth being precise.
According to OpenAI’s own enterprise privacy documentation, data from ChatGPT Business, Enterprise, Edu, and the API platform is not used to train or improve OpenAI models by default, and no opt-out is required. On consumer plans (Free, Go, Plus, and Pro), your conversations may be used to improve models unless you manually switch training off in settings.
Here is how the tiers compare on the things that actually matter.
| Feature | Free / Plus (personal) | Team / Business | Enterprise / API |
|---|---|---|---|
| Trains on your data by default | Yes, unless you opt out | No | No |
| Data Processing Addendum (DPA) | Not available | Available | Available |
| Admin controls and SSO | No | Yes | Yes, with SCIM and audit logs |
| Configurable data retention | Limited | Yes | Yes |
| Australian data residency (at rest) | No | Limited | Yes, where offered |
| Suitable for company data | No | Yes, with settings | Yes, with settings |
If you take one thing from this article, take that first row. The difference between a free account and a business account is the difference between “your prompt might help train the next model” and “your prompt stays yours”.
What are the real security risks?
The genuine risks are human behaviour, third-party exposure, and the occasional platform vulnerability, roughly in that order of likelihood. Let me be balanced here, because both the hype and the panic get this wrong.
Platform vulnerabilities are real but rare and usually patched quickly. In February 2026, OpenAI patched a data exfiltration flaw that could have let an attacker sneak information out through a hidden DNS side channel in the code-execution runtime, along with a separate token vulnerability in Codex. Security researchers who analysed the incident noted there was no evidence of malicious exploitation in the wild, and OpenAI fixed it after responsible disclosure. That is roughly how a mature vendor should behave. It is not a reason to avoid the platform, but it is a reminder that no cloud tool is risk-free, and that you should treat AI vendors with the same due diligence you apply to any other processor.
The far more probable risks are mundane:
- Staff pasting sensitive data into unmanaged accounts, where it may be retained and used for training.
- Over-trusting outputs, where a confident but wrong answer feeds into a decision without a human check.
- Weak account hygiene, such as shared logins and no single sign-on, which is a governance failure rather than an AI-specific one.
None of these are exotic. They are the same data-handling risks you already manage for email and cloud storage, wearing a new coat.
Is ChatGPT compliant with the Australian Privacy Act?
ChatGPT can be used in a Privacy Act compliant way, but the tool does not make you compliant. Your business does. Under the Australian Privacy Act 1988, your organisation is the accountable APP entity for the personal information you handle, whether you process it in a spreadsheet or a chatbot.
Two things have sharpened in 2026 that Australian leaders should have on their radar.
First, enforcement now has teeth. Following the 2024 reforms, the OAIC can pursue substantial civil penalties for serious or repeated interference with privacy, reaching up to 30 percent of adjusted turnover for the relevant period for a body corporate, alongside lower tiers and infringement notices for less serious breaches. Feeding customer records into an unmanaged AI tool is exactly the kind of avoidable handling that regulators look at.
Second, and specific to AI, new automated decision-making transparency obligations commence on 10 December 2026 under the Privacy and Other Legislation Amendment Act. From that date, if you use a computer program (a term broad enough to cover AI and machine learning) to make or substantially help make decisions that could reasonably be expected to significantly affect someone’s rights or interests, you must disclose this in your privacy policy. If ChatGPT sits anywhere near decisions about hiring, credit, eligibility, or service, you need to map that now and be ready to explain it plainly. I covered the mechanics in more detail in my breakdown of the 2026 automated decision rules.
Where does my data actually live?
On business tiers you can now keep stored content in Australia, but model processing still happens elsewhere by default. OpenAI has expanded data residency to Australia and other regions for eligible Enterprise, Edu, and API customers, so conversations, uploaded files, and custom GPTs can be stored at rest locally.
Read the fine print, though. Residency currently applies to data at rest. Inference, the actual processing of your prompt by the model, still defaults to United States infrastructure. For most Australian businesses that is manageable, but it means you must still treat prompts as a cross-border disclosure of personal information under APP 8 and account for that in your privacy policy and contracts.
A safe-use checklist for Australian businesses
You can get most of the value of ChatGPT while closing most of the risk with a handful of deliberate decisions. Here is the practical checklist I give clients.
- Provide a sanctioned account. Roll out ChatGPT Business or Enterprise so staff are not pushed onto free personal tools. This single step removes the biggest source of exposure.
- Configure the settings. Confirm training is off, set data retention to match your record-keeping policy, and enable Australian data residency where it is offered.
- Sign the paperwork. Execute a Data Processing Addendum so your Privacy Act and contractual obligations are covered.
- Enforce access hygiene. Use single sign-on, disable shared logins, and review admin and audit logs.
- Write a one-page acceptable-use policy. State plainly what must never be pasted: unmasked customer data, health records, credentials, unreleased financials, and third-party confidential material.
- Train your people. Most leaks are honest mistakes. Ten minutes of practical guidance beats a forty-page policy nobody reads.
- Keep a human in the loop. For anything that affects a person’s rights, interests, or money, a person signs off, not the model.
- Map your automated decisions now ahead of the December 2026 transparency deadline.
If you want the wider structure this sits inside, I have written a companion piece on building an AI governance framework for Australian businesses, and a more detailed look at getting real value from ChatGPT and OpenAI at work.
So, is ChatGPT safe?
Yes, on a properly configured business or enterprise tier, and no, on a free personal account holding company data. The technology is not the weak point. The weak point is an organisation that lets sensitive information flow into unmanaged tools with no policy, no training, and no accountability. Fix that, and ChatGPT becomes one of the safest productivity gains available to an Australian business this year. Ignore it, and the risk was never really about the AI at all.
I help Australian organisations adopt AI tools like ChatGPT safely and get real value from them without tripping over privacy and security. If that is on your plate, get in touch.