OpenAI employs hundreds of contract workers who read real ChatGPT conversations and rate them on a scale of one to seven. The stated goal is to reduce overly compliant responses and overly "human" behaviors from the model.
Chats are anonymized, but anonymization doesn't eliminate the risk: if a user has written sensitive data — customer names, contract numbers, business strategies — those contents can appear in the review queue. The setting that enables this collection is called "Improve the model for everyone" and is active by default. To disable it, you need to do it manually from your account settings.
For those using ChatGPT in the company without having verified this item, the risk is not theoretical: it concerns the confidentiality of the data processed and, in certain contexts, compliance with GDPR. The first thing to do this week is to check the setting on every active company account.
The setting that almost no one has disabled
OpenAI has hundreds of contract workers who read real ChatGPT conversations. This was reported by The Decoder , citing an investigation by 404 Media. The task of these reviewers is to evaluate the model's responses on a scale of one to seven, with the goal of reducing ChatGPT's tendency to be too compliant or to artificially imitate human behavior.
The point concerning companies is not the training method itself. It's that this collection happens by default, through an option called «Improve the model for everyone» , and that deactivating it requires a manual user action. Those who have never looked for it almost certainly still have it active.
Anonymized does not mean secure
OpenAI states that conversations are anonymized before being assigned to reviewers. But anonymization removes explicit identifying data — username, email address — not the content of the chats.
If a marketing manager used ChatGPT to draft a business proposal with client names, prices, and contract terms, those details remain in the conversation text. A human reviewer can read them. In a B2B context, this isn't an abstract problem: it's a potential breach of confidentiality obligations to the clients themselves.
On the regulatory front, GDPR — the European regulation on the protection of personal data — requires that data processing occur on precise legal bases and with adequate measures. Entrusting third-party data to a tool that transmits them to human reviewers without informing the data subjects is a gray area that many companies have not yet evaluated. The issue fits into a broader framework of governance and privacy in the use of AI tools , which is also becoming urgent for Italian SMEs.
Who is really exposed and who can rest easy
Not all ChatGPT users are in the same situation. There are important differences between the plans:
- Free accounts and personal ChatGPT Plus : the «Improve the model for everyone» setting is active by default. Data can be used for training and human review.
- ChatGPT Team and Enterprise : OpenAI states that conversations are not used to train models by default. But "by default" doesn't mean "never": it's worth checking your contract terms.
- Direct API : those who use ChatGPT via API without explicitly enabling data training have different conditions. Here too, reading the updated terms of service is necessary.
In summary: if a company uses a free or Plus account for activities involving customer data or confidential information, the risk is concrete and immediate.
Three actions to take this week
No need for long consultations or projects. Three operational checks are enough:
- Check the setting on each active business account. In ChatGPT: Settings → Data Controls → «Improve the model for everyone» → disable.
- Map who uses ChatGPT in the company and with what data. Often the use is informal and widespread: sales, assistants, marketing. Each of them is a potential point of exposure.
- Evaluate if the current plan is adequate. If business use is intensive and involves sensitive data, switching to an Enterprise plan with explicit contractual terms is the safest route.
This type of risk doesn't arise from an external attack, but from a setting that's active by default. It's the same pattern already seen in other contexts: as in the case of Meta Muse Spark, which offered a 95% discount in exchange for sharing data for training . The mechanism is different, but the logic is identical: the user gives away data without realizing it, because the default option works silently.
The most underestimated risk: customer trust
Beyond formal compliance, there's a reputational risk that companies tend to overlook. If a client discovers that their data — even just a draft proposal or an email exchange reprocessed with ChatGPT — has been read by human reviewers from a third-party company, the ensuing conversation is difficult to manage.
The issue of human supervision of AI tools is already at the center of regulatory debate. Those who deal with API governance and risks related to AI agents knows that the exposure surface widens every time a new tool enters the workflow without prior evaluation. And it doesn't just concern developers: it concerns anyone who has a ChatGPT account open in their browser during a meeting.
The issue of OpenAI's transparency on its internal processes has returned to the spotlight several times in recent months. Each time, the pattern is the same: the news emerges from external sources, not from proactive company communications. For those who have to make decisions about which tools to adopt, this is a fact to consider as much as the product's features.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.