Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document asserts that enterprise customers retain rights to their inputs and own outputs to the extent permitted by law, and that OpenAI's license to use inputs and outputs is limited to service provision, legal compliance, and policy enforcement.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision defines the contractual rights framework for business data submitted to and received from OpenAI services. The phrase 'to the extent permitted by law' introduces a qualifier on output ownership that may be relevant in jurisdictions where AI-generated content ownership is unsettled.
Interpretive note: The scope of output ownership is qualified by 'to the extent permitted by law,' which introduces variability depending on jurisdiction and evolving legal standards for AI-generated content.
The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View change record →The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
View change record →This provision explicitly establishes customer data ownership and limits OpenAI's rights to only those necessary for service delivery and legal compliance, providing crucial intellectual property protections.
View full change record →Under this clause, enterprise customers retain ownership of their inputs and outputs as between the parties, with OpenAI asserting only a limited operational license. The qualification 'to the extent permitted by law' means the scope of output ownership may vary depending on applicable jurisdiction and legal developments regarding AI-generated content.
Cross-platform context
See how other platforms handle Data Ownership and Rights Grant and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"As between you and OpenAI: you retain all rights to the inputs you provide to our services and you own any output you rightfully receive from our services to the extent permitted by law. We only receive rights in input and output necessary to provide you with our services, comply with applicable law, and enforce our policies.Excerpt from OpenAI's Enterprise Privacy
(1) REGULATORY LANDSCAPE: Output ownership of AI-generated content is an evolving legal question in multiple jurisdictions. In the United States, the Copyright Office has issued guidance indicating that AI-generated content without sufficient human authorship may not receive copyright protection. In the EU, similar questions are under active legal and regulatory consideration. This provision's qualifier 'to the extent permitted by law' reflects this uncertainty. (2) GOVERNANCE EXPOSURE: Medium. The limited license grant to OpenAI for service provision, legal compliance, and policy enforcement is broadly worded. The phrase 'enforce our policies' as a basis for using input and output data warrants scrutiny regarding what policy enforcement activities may involve access to or use of business data. (3) JURISDICTION FLAGS: Organizations in the EU should evaluate how this rights framework interacts with GDPR data subject rights, particularly where inputs contain personal data and the data subject seeks erasure or portability. Organizations relying on AI-generated outputs for commercial purposes should assess copyright protectability under applicable law before asserting ownership rights over outputs. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether the enterprise agreement or DPA provides more specific language on the scope of OpenAI's license, particularly regarding the 'enforce our policies' basis. Downstream commercial use of outputs may carry IP risk that this provision does not fully resolve. (5) COMPLIANCE CONSIDERATIONS: Legal teams should map this rights framework against their organization's IP and data governance policies, particularly for outputs intended for commercial exploitation. Where inputs contain personal data, data processing records should reflect the limited license structure asserted here.
This provision defines the contractual rights framework for business data submitted to and received from OpenAI services. The phrase 'to the extent permitted by law' introduces a qualifier on output ownership that may be relevant in jurisdictions where AI-generated content ownership is unsettled.
Under this clause, enterprise customers retain ownership of their inputs and outputs as between the parties, with OpenAI asserting only a limited operational license. The qualification 'to the extent permitted by law' means the scope of output ownership may vary depending on applicable jurisdiction and legal developments regarding AI-generated content.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.