OpenAI
GPT-4o
v4o · frontier · Released May 13, 2024
Updated July 29, 2026
OpenAI's new ChatGPT Work agentic product introduces material access control and audit risks that affect the broader GPT-4o deployment context. Additionally, the ChatGPT Health expansion amid an active product liability lawsuit raises unresolved enterprise risk concerns tied to the same underlying model family.
Enterprise guidance
GPT-4o is broadly available and the recommended default for organizations that need a commercially cleared frontier model. For regulated industries, use ChatGPT Enterprise or Azure OpenAI Service — both offer zero data retention, configurable data residency, and HIPAA Business Associate Agreements. The standard API retains inputs and outputs for 30 days by default; disable this in API settings or switch to a zero-retention endpoint.
Data handling
Default data retention
30 days (API); zero by default (ChatGPT Enterprise, Azure OpenAI)
Zero-retention available
YesVia: ChatGPT Enterprise; Azure OpenAI Service
API data used for training
NoAPI data is not used to train OpenAI models by default. ChatGPT.com free tier may use conversations for model improvements unless opted out in settings.
GDPR Data Processing Agreement
AvailableHIPAA Business Associate Agreement
AvailableChatGPT Enterprise; Azure OpenAI Service
Data residency options
US (default); EU and APAC regions available via Azure OpenAI
Vendor compliance certifications
Key use restrictions
- —No CSAM or sexual content involving minors
- —No instructions for creating weapons capable of mass casualties (biological, chemical, nuclear)
- —No cyberweapons or malicious code intended to cause significant damage
- —No content designed to facilitate real-world violence against specific targets
- —No election interference or voter suppression content
Safety documentation
GPT-4o System Card published May 2024. OpenAI Preparedness Framework published. Third-party red-team evaluations conducted by external safety researchers before release.
Safety documentation →Related governance resources
Governance controls
AI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
AI Contractual Requirements
Set minimum AI vendor contract terms for data handling, transparency, audit rights, and incident notification.
AI Procurement Risk Assessment
Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.
AI Vendor Concentration Risk Assessment
Assess dependence on a small number of AI vendors or underlying model providers. Document supplier alternatives supporting continuity if a primary provider fails, suspends access, or becomes unavailable.
Third-Party AI Model Evaluation
Evaluate third-party AI models against defined performance, safety, and bias criteria before deploying them in enterprise workflows.
Playbook guides
How do we ensure third-party AI vendors meet our standards?
Review AI vendors for model transparency, data handling, bias testing, and contractual liability for their outputs.
How do we maintain data privacy compliance when using AI?
Review training data sources, data minimization, cross-border transfers, and applicable explanation duties under GDPR and CCPA.
How are we managing third-party AI risks?
Govern external AI APIs and models embedded in vendor software. Review data handling, documentation, and ongoing monitoring.
Status history
July 29, 2026· green to yellow
Two high-severity developments affect the OpenAI GPT-4o product line. ChatGPT Work introduces agentic autonomous task execution with identified access control and audit risks, meeting the YELLOW criterion for unresolved enterprise concerns. ChatGPT Health's expansion while subject to active product liability litigation introduces legal exposure that further supports a YELLOW designation.
