Get the weekly research letter
What the week's governance changes actually mean, read against a corpus of 844 tracked documents. Grounded analysis of the changes that matter, not a feed of every change. Email only, no account.
OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their conversations were retained and could view their own conversations. The updated language now establishes that workspace admins control data retention duration and can view, access, export, and delete end user conversations within their workspace. Additionally, the policy now permits OpenAI to retain deleted or unsaved conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.
The updated terms establish that workspace admins, rather than individual end users, control how long workspace conversation data is retained and authorize admins to view, access, export, and delete end user conversations. Previously, the policy stated that each user controlled whether their conversations were retained and that only end users could view their own conversations. The revised terms also permit OpenAI to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm. Workspace users should review their organization's data governance policies to understand what access and retention practices their admins have implemented.
The updated terms transfer control over conversation data retention from individual users to workspace admins and expand OpenAI's authority to retain deleted data beyond the standard 30-day window. Organizations using ChatGPT Business need to clarify how admins will exercise this new authority and may need to update privacy notices or vendor agreements if they previously represented that users controlled retention or that data would be deleted after 30 days.
→ If you are an end user in a workspace environment, review your organization's data governance policies or ask your workspace admin about how they will exercise access and retention authority over conversations.
→ If you are a compliance officer or workspace admin, document your organization's policies governing admin access to conversations and retention duration.
→ Workspace admins will have authority to access, view, export, and delete your conversations as stated in the updated terms.
→ Your organization's admins, rather than you, will control how long your conversations are retained in the system.
Across all monitored documents, OpenAI has made 8 significant changes.
5 of OpenAI's significant changes have been classified as negative for consumers.
Admins now explicitly permitted to view, access, export, and delete end user conversations within their workspace.
Retention duration is now controlled by workspace admins rather than individual end users.
OpenAI now reserves the right to retain deleted conversations beyond 30 days if retention is required by law or reasonably necessary to protect OpenAI's services or third parties from harm.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
The expanded admin authority creates a need for organizations to define clear internal policies about who can access user conversations and when.
Employees or users no longer have control over how long their conversations are kept; that decision now belongs to their organization's admins.
Organizations may need to update their privacy statements or contracts to reflect that OpenAI can keep conversation data longer than 30 days if it claims this is necessary for service protection.
OpenAI clarified and expanded workspace admin authority over end user conversation data on May 28, 2026. The change shifts data retention control from individual users to workspace admins and explicitly authorizes admins to view, access, export, and delete conversations. Additionally, OpenAI reserved an expanded ground for retaining deleted conversations beyond 30 days, now including retention 'reasonably necessary to protect our services or any third party from harm' in addition to legal requirements. Organizations deploying ChatGPT Business should evaluate whether this expanded admin authority aligns with their internal data governance frameworks and employee privacy expectations. The change engages data protection compliance considerations if the organization operates in jurisdictions with employee privacy or workplace monitoring regulations.
Full institutional analysis
Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.
Analyst $49/moConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002395.
OpenAI's GPT-5.5 System Card was updated in an update detected on July 21, 2026. The document removed a reference to …
OpenAI updated the related-content section in its GPT-5 System Card detected on July 21, 2026. The previous version linked to …
OpenAI updated its Frontier Governance Framework on July 21, 2026, modifying a single sentence within the document's reference section. The …
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get alerted when this policy changes again, including what changed and why it matters.