OpenAI employs hundreds of contract workers to read and evaluate real ChatGPT conversations. The stated goal is to reduce overly compliant behavior from the model. The problem is that the setting that allows this review is active by default on all accounts.
Prompts are anonymized, but anonymization doesn't eliminate the risk: a conversation might contain details about customers, suppliers, internal strategies, or personal data that remain readable even without a name at the beginning of the text.
If your company operates in regulated sectors — healthcare, finance, legal, HR — or handles data covered by confidentiality agreements, you need to check this setting today. It's not a technical problem: it's a compliance issue and a matter of trust with your clients.
What really happens when you send a prompt to ChatGPT
According to reports by The Decoder , OpenAI has hundreds of contractors — contract workers, not employees — who read real user conversations and rate them on a scale of one to seven. The work helps train the model to be less sycophantic and less "human" in the wrong way.
What matters for those using ChatGPT in the company is a specific detail: the setting «Improve the model for everyone» — improves the model for everyone — is active by default. Until you disable it, your conversations can be read by real people.
Anonymized is not enough: the real risk for SMEs
OpenAI anonymizes prompts before passing them to reviewers. But anonymizing doesn't mean making text harmless. A conversation where you ask to summarize a client contract, analyze revenue data, or draft a response to a complaint contains sensitive information even without the person's name at the top of the page.
Who is really exposed:
- Law firms and consultants who use ChatGPT for draft documents or opinions
- HR offices processing texts on evaluations, dismissals, salaries
- Healthcare or pharmaceutical companies with patient or trial data
- Accountants and CFOs who paste financial statements or projections
- Anyone who has signed NDAs with clients and uses ChatGPT to work on those projects
The issue is not new: we've already looked at what ChatGPT contractors really read and how the review process works . Today's news is the confirmation of the scale of the phenomenon: not one or ten reviewers, but hundreds.
How to turn off human review: three steps
The procedure is simple. The problem is that almost no one knows it.
- Go to settings of your ChatGPT account (bottom left icon on desktop, or profile menu on mobile)
- Go to «Data controls» — data controls — in the settings section
- Turn off «Improve the model for everyone» : the switch needs to turn gray
Once done, your conversations are not used to train the model and are not assigned to human reviewers. Warning: this setting needs to be checked on each company account separately. If your company has multiple users on ChatGPT, each person must perform this operation on their own profile.
Who uses ChatGPT Enterprise — the paid version for businesses — already has this protection active by contract. But anyone using the free account or individual Plus plan does not.
The bigger picture: AI governance and company data
This situation is part of a more structural problem. Companies are adopting AI tools quickly, often without a clear policy on what data can be shared with external services. The risk is not only regulatory — GDPR, NIS2, sector-specific regulations — but also contractual and reputational.
It's not an isolated case. We've seen how Meta offers 95% discounts in exchange for data sharing for training : different models, same principle. The data you produce using a free or semi-free AI tool has value, and that value is extracted in some form.
On the governance front for AI agents — systems that act autonomously on behalf of the user — the problem is further amplified. We discussed this by analyzing the real risks for anyone using AI APIs and what changes for governance when agents operate outside direct control .
The topic of regulation, privacy, and AI governance is becoming operational, not just theoretical. It's no longer about waiting for European guidelines: it's about deciding today which data goes into which tools.
Mistakes to avoid in the coming days
Turning off the setting is the first step, but it is not enough on its own. The most common mistakes SHM Studio sees in companies tackling this issue:
- Thinking it's enough to do it once : if you add new users or accounts, the setting returns to active by default
- Confusing ChatGPT with ChatGPT Enterprise : they are different products with different terms of service
- Not updating internal policies : turning off the setting without communicating it to colleagues does not solve the cultural problem
- Ignoring the other AI tools you use : ChatGPT is not the only service with similar settings; it is worth doing the same check on Copilot, Gemini, and other tools adopted in the company
The question to ask your team this week is simple: do we know what corporate data is going into which AI tools, and with what settings?
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.