ChatGPT Enterprise

OpenAI

Vendor

Enterprise tier of ChatGPT with workspace RBAC, SCIM-synced groups, Compliance API, data residency options and bundled Codex.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Compliance API for SIEM export
  • SCIM groups and workspace RBAC
  • No training on business data by default

Practitioner note

Confirm up front which content and workloads are eligible for data residency and EKM, and note that strict zero data retention is not offered for Work Cloud features.

Governance posture

Reviewed 2026-09-30
PartialData residency

Data and inference residency apply only to eligible content and supported workloads, subject to agreement, region and configuration.

Source
YesDeployment model

OpenAI-hosted SaaS (web, desktop, mobile); no self-hosted option. (saas)

Source
YesAudit logging

Compliance API provides an append-only compliance log stream (conversation, auth and Codex events) for SIEM or data lake export.

Source
YesSOC 2

SOC 2 Type 2 (Jul 2025-Jun 2026) covers ChatGPT Enterprise.

Source
YesISO 27001

ISO/IEC 27001:2022 (plus 27017/27018/27701) covers ChatGPT Enterprise.

Source
YesISO 42001

ISO/IEC 42001:2023 listed on OpenAI trust portal covering ChatGPT Enterprise.

Source
UnknownEU AI Act

Assessed limited-risk by product category (general-purpose assistant); no published OpenAI EU AI Act conformity statement for this product. (role: limited-risk)

YesLicense risk

Proprietary SaaS; OpenAI model and workspace lock-in. (medium)

Source

EU AI Act obligations

Risk tier: Limited risk · as of 2026-08-23

Source-backed information mapped from ChatGPT Enterprise's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

Article 4AI literacy

Providers and deployers must take measures to ensure a sufficient level of AI literacy in staff and other persons operating AI systems on their behalf.

Applies from

Official text
Article 50Transparency for certain AI systems

People must be informed when they interact with an AI system; synthetic audio, image, video, and text content must be marked as artificially generated, and deepfakes disclosed.

Applies from

Official text

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.