What the enterprise tier covers
Start with the questionnaire answers, because they are strong. A third-party review of ChatGPT Enterprise's published admin controls, dated 17 April 2026, describes AES-256 encryption at rest and TLS 1.2 or better in transit, customer-managed keys through Enterprise Key Management, domain verification, single sign-on with SAML, directory-based provisioning, IP allowlists, an admin console with custom roles, switches for individual apps and actions, exportable usage and compliance logs, a SOC 2 Type II attestation, and data residency across ten named regions including Australia and the European Union. Contract terms set whether your data trains base models and how long logs are kept. If the question in the room is whether someone outside your organisation can read this, the enterprise tier answers it.
The gap is per-message, not per-account
Every control in that list is about the account and the workspace: who signs in, what is switched on, where the bytes sit. None of them is a decision about one message. OWASP names the failures this leaves open. Improper Output Handling is LLM05 in the 2025 LLM Top 10 and Excessive Agency is LLM06, defined as an assistant granted more functionality, permission or autonomy than the job needs. Encryption touches neither. If you have also switched on custom GPTs, actions or connectors, add Identity and Privilege Abuse, ASI03 in OWASP's 2026 agentic list, because an admin role decides who may sign in rather than what one action may do once inside.
Why a regulated team feels it as a stalled pilot
The consequence usually shows up as adoption that stops, rather than as a breach. In a June 2026 survey of 114 data and analytics leaders by insightsoftware, 31% named the inability to verify a result as a barrier to production and 53% put audit trails for AI-generated answers among their governance requirements. Small sample, one vendor's survey, US-leaning, so weigh it accordingly. The pattern holds anyway. Nobody signs off a decision they cannot reconstruct, and an account-level log tells you that someone in finance used the tool on Tuesday. It does not tell you what was asked, what was hidden before the model saw it, or why an answer came back refused.
Size the gap in your own console, in about an hour
Do this with your administrator present, on your own workspace, before anyone writes a business case either way.
- Send a message containing a real customer identifier from an account you control. Then establish from a record, rather than from memory, whether that identifier reached the model.
- Ask for something your acceptable-use policy forbids. Watch whether anything stops the message, or only the answer.
- Switch on one connector or action and have the assistant use it. Ask who authorised that specific call, and where that authorisation is written down.
- Try to export, for one conversation, the sequence of checks that were applied to it. The transcript is not what you are asking for. The checks are.
- Ask what survives if the person who ran all of this leaves next month, and who can read it after they go.
What a control layer adds on top
Difinity.ai answers a narrower question: what happens to this specific message, right now. Where a use case is configured to detect personal information, detected values are replaced before the model sees them, and the message is also checked against that use case's compliance rules, topic scope and blocked words. A refusal at that stage stops the turn, so the request never reaches a provider and is not charged. The workspace at chat.difinity.ai shows the run in the order it happened: the checks, the model's own reasoning, each tool call, and what the tool returned, with the model that answered named on the answer. What happened is written to an append-only run trail as it happens. The trail is evidence and the transcript is the person's own data, and neither one is derived from the other, which is what lets an erasure request and an audit request both be answered honestly. This sits on top of your provider rather than replacing it. OpenAI is one of the model providers Difinity connects to.
What this answer depends on
Two things this page cannot do for you. The ChatGPT Enterprise controls above come from a third-party summary dated April 2026, because OpenAI's own enterprise privacy page refused an automated fetch when this was written, so confirm the attestation, the key management and the region list against OpenAI's own page before quoting any of it in a risk assessment. And OpenAI ships quickly. If per-message content policy has arrived in the admin console since April 2026, the gap described here is narrower than it was, which is why the hour in your own console beats reading about it. The same honesty applies in this direction: governed run records contribute operational evidence to an EU AI Act or ISO/IEC 42001 process, and Difinity does not determine that an organisation or an AI system is compliant, nor does it provide ISO/IEC 42001 certification.
Frequently asked questions
Is ChatGPT Enterprise secure?
It holds up on confidentiality, on access and on where the data sits: encryption in transit and at rest, customer-managed keys, single sign-on, admin roles, exportable logs and a choice of hosting regions. Security of the account is not the same as governance of a message, and the second is where regulated teams get stuck.
Does ChatGPT Enterprise train on our data?
That is set in your agreement rather than in the product, and it is one of the questions the enterprise tier exists to settle. Read your own contract instead of a summary of someone else's, and check the retention window for logs and telemetry while you are in there.
What doesn't ChatGPT Enterprise control?
Whether a specific prompt should be carrying regulated data, whether a specific answer should be returned, whether a specific action in another system should run, and what durable record those decisions leave. Those are per-message decisions, and account-level controls do not make them.
Do we still need a control layer if we are already on ChatGPT Enterprise?
If your people only ask questions and read the answers themselves, probably not. It starts earning its keep the moment a message can carry regulated data you are obliged to hide, or the assistant can act in another system. Both are decisions about one message or one action.
Sources and further reading
- ChatGPT Enterprise admin controls and security settings, third-party review (17 April 2026) (opens in a new tab)
- OWASP Top 10 for LLM Applications, v2025 (LLM05, LLM06) (opens in a new tab)
- OWASP Top 10 for Agentic Applications 2026 (published 9 December 2025) (opens in a new tab)
- insightsoftware 2026 AI survey, 114 data and analytics leaders (9 June 2026) (opens in a new tab)