What happened in the OpenAI preservation order?
A court ordered a provider to preserve user data that users had deleted, in litigation those users were not party to. In In re: OpenAI, Inc., Copyright Infringement Litigation, No. 25-md-03143 (SHS)(OTW) in the Southern District of New York, Magistrate Judge Ona T. Wang ordered on 13 May 2025 that OpenAI preserve and segregate all output log data that would otherwise be deleted.
A stipulation on 9 October 2025 terminated the ongoing obligation as of 26 September 2025, and its three carve-outs are the actual lesson. Everything captured before 26 September 2025 stays preserved, except logs originating in the European Economic Area, Switzerland or the United Kingdom — so geography determined who got their data back. Preservation continues going forward, irrespective of location, for accounts associated with roughly 100 domains the plaintiffs named. And the stipulation expressly does not waive obligations under Federal Rule of Civil Procedure 37(e).
Which tiers were covered and which were not?
Impacted: ChatGPT Free, Plus, Pro and Team, plus API customers without zero-retention agreements. Not impacted: ChatGPT Enterprise, ChatGPT Edu, and API customers using zero-retention endpoints.
Read that boundary carefully, because Team is a paid business product and it fell on the wrong side of it. The procurement lesson is exact: a firm on ChatGPT Team would have had its deleted client-related conversations preserved under a court order in third-party litigation it had nothing to do with. A firm on Enterprise would not. The tier boundary, not the vendor’s privacy marketing, was the control that mattered.
Why can a partner’s personal subscription have fewer protections than a cheap firm seat?
Because consumer tiers are built for individuals and business tiers are built for organisations, and the controls that matter to a firm live on the organisational side. On consumer tiers, training on content is typically opt-out rather than off by default, and the enterprise control plane — single sign-on, user provisioning, audit logging, retention control, compliance interfaces, data residency — does not exist at all.
The result is genuinely counterintuitive and worth stating plainly: a partner paying a premium personal subscription out of pocket can have fewer protections than the same firm’s much cheaper business workspace seats. Price signals capability, not governance.
It also means expense reports are an AI governance surface. A firm that has never looked at what its partners are personally subscribing to does not know what its actual deployment is.
Is zero data retention actually zero?
It is zero for the endpoints it covers, and it does not cover all of them. Zero data retention on the OpenAI API is endpoint-scoped rather than account-scoped: it is available for the chat completions, responses, embeddings, images, audio, completions, realtime and moderations endpoints, and it is not available for conversations, assistants, threads, vector stores, files, fine-tuning jobs, batches or evaluations.
That list is the trap. A firm cannot build a stateful retrieval system on managed vector-store and files endpoints and simultaneously claim zero data retention, because zero retention covers the inference call and not the corpus. The corpus is the part containing the client documents.
Do retention terms stay put once they are agreed?
No — they are business policies rather than physical laws, and they change. Effective 9 June 2026, Anthropic began retaining prompts and outputs for a defined set of covered models for 30 days to support safety work, across the platforms where those models are offered, and that policy applies specifically to organisations holding zero-data-retention workspaces.
The Institute names this example because the fact is about a published term with a date attached, not as a comparison between providers. The transferable point is the one to keep: a retention promise is a contractual position a vendor can revise, and a firm’s posture should not depend on remembering to re-read a policy page.
The robust version is to enforce retention posture in infrastructure rather than in a policy document, so that a change breaks access visibly instead of silently retaining. For a law firm, loud failure is the correct failure mode.
How should a firm evaluate a tier?
By reading three things in the contract and ignoring the marketing page: whether inputs are used for training and whether that is on by default, what the retention period is and which endpoints or surfaces it applies to, and whether the administrative controls a firm needs to supervise use actually exist at that tier.
There is a cost problem underneath this that is worth naming honestly, because it affects smaller firms disproportionately. Across many categories the tier that satisfies a firm’s confidentiality obligations is priced for organisations roughly ten times the buyer’s size. The most practical answer for a small firm is usually the capability already inside its Microsoft or Google agreement, where the enterprise terms have already been bought.
The Institute’s Tool Selection & Evaluation area covers evaluation criteria in more depth. The Institute does not rank tools, and its founder advises firms on adoption, which is disclosed on every page for the obvious reason.