HomeGenAI PracticeOpenAI Privacy Terms
OpenAI  |  Enterprise Terms Contract Brief 2026

A policy page can change with a web edit and an order form term cannot, and treating the two as equivalent is the most common GenAI procurement error we see

The defaults are stronger than most procurement teams assume. The gap is everything the defaults do not cover, and all of it is set by contract.

Prepared by Redress Compliance · August 19, 2026 · GenAI vendor contracts reviewed. 25 to 35 files, 2024 to 2025.

Executive summary

Roughly 1 in 4 enterprise buyers had no executed Data Processing Addendum, despite processing personal data through the API, across roughly 25 to 35 GenAI vendor contracts reviewed between 2024 and 2025.

Training defaults were misread. Teams assumed API traffic trains models by default, then paid for assurances already given in writing.

Retention windows went unmanaged in 60 to 70 percent of agreements, which kept the standard abuse monitoring retention where zero data retention was available.

OpenAI paper was the most frequently signed without a single privacy redline of any vendor in the file.

1 in 4
Enterprise buyers with no executed DPA.
60 to 70%
Agreements leaving retention unmanaged.
9
Privacy clauses in the buyer checklist.
25 to 35
GenAI vendor contracts reviewed, 2024 to 2025.
1.

What happens to enterprise data by default?

Models are not trained on enterprise or API data by default, and that commitment sits in the published privacy commitments. The default position is stronger than most procurement teams assume.

The gap is everything the defaults do not cover. Retention windows, subprocessor changes, breach notice timing and audit rights are set by the contract documents, not by the marketing page.

The three documents that actually govern

The business terms set ownership and liability, the addendum sets processor obligations, and the portal evidences the controls. A privacy review reading only one of the three is incomplete.

ChannelTrains on your dataDefault retentionZero retention available
Consumer tiersYes unless opted outProvider discretionNo
TeamNoWorkspace controlledNo
EnterpriseNoAdmin controlledNo
API standardNo30 days abuse monitoringBy approval
API with zero retentionNoNone at restYes
2.

Which nine clauses should the agreement carry?

Nine separate a defensible agreement from a signed marketing page, and each one has a concrete buyer position.

Clauses one to five, data handling

Clauses six to nine, control and exit

Try Vera AI · free 30 day trial
Vera reads the GenAI paper clause by clause.
  • Every privacy clause checked against the vendor's own published commitments
  • Retention, subprocessor and deletion language flagged with replacement text
  • The gap between policy page and order form made explicit before signature
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
3.

How do you negotiate these without stalling the deal?

Anchor every ask to something the vendor has already published, because the fastest redlines are the ones conceded elsewhere.

The privacy page, the addendum and the trust portal give you the anchor for seven of the nine clauses.

Sequence matters. Send the addendum and the security questionnaire in week one, in parallel with commercial terms. Teams that treat privacy as a closing formality lose two to four weeks at signature.

What the account team will push back on

Free white paper

The OpenAI negotiation guide

The nine clause checklist, the published anchors behind each one, and the sequence that keeps privacy off the critical path.

Get the guide →
4.

What 25 to 35 GenAI contract reviews showed

Across the GenAI vendor contracts reviewed between 2024 and 2025, OpenAI paper was the most frequently signed without a single privacy redline.

The three patterns that recurred

The first and third point in opposite directions. One is paying for protection you already have, the other is operating without protection you assumed you had.

OpenAI and Anthropic agreement briefingResearch briefingReading the frontier vendor agreementsWhere the published commitments, the processing addendum and the order form meet, and which of the three actually binds.
5.

Where the common advice on these terms is wrong

The standard advisory line is that the terms are non negotiable below seven figures, so buyers should sign the standard paper and move on. We disagree.

In roughly 12 of the 30 reviews run in 2024 to 2025, named retention, subprocessor notice and deletion clauses were accepted at mid six figure spend, because the asks restated published commitments as contract terms rather than inventing new obligations.

Convert policy into contract. That is the whole move, and it is cheaper than any assurance you could buy instead.

Most privacy clauses are conceded fastest when the redline quotes the published commitment it restates.

1 in 4
Buyers with no executed addendum

Despite processing personal data through the API.

60 to 70%
Agreements with unmanaged retention

Keeping the standard window where zero retention was available.

12 of 30
Reviews where clauses were accepted

At mid six figure spend, by restating published commitments.

The equivalent work on the neighbouring vendor sits in negotiating with Anthropic and with our GenAI licensing practice. The signature stage itself is walked through in episode three of the negotiation series.

6.

Your first five moves

  1. Execute the processing addendum before anything else, because 1 in 4 buyers were operating without one.
  2. Restate the no training default as an order form term, so it survives a policy page edit.
  3. Check whether your use case qualifies for zero data retention and submit that review early, since it is granted on use case rather than pressure.
  4. Name the retention window, the subprocessor notice period, the breach notice hours and the deletion timeline as contract terms.
  5. Send the addendum and security questionnaire in week one alongside commercial terms, rather than treating privacy as a closing formality.
7.

Frequently asked questions

Does enterprise data train the models by default?

No. Enterprise, team and API data are excluded by default, and that commitment is published. The default is stronger than most teams assume.

So what is actually at risk?

Everything the defaults do not cover: retention length, subprocessor changes, breach notice timing, residency and exit deletion. All are contract variables.

How many buyers lacked a processing addendum?

Roughly 1 in 4 enterprise buyers had none executed, despite processing personal data through the API.

Which documents actually govern?

Three: the business terms for ownership and liability, the addendum for processor obligations, and the trust portal for control evidence.

What is the most common wasted spend?

Paying for assurances already given in writing, because the team misread the training defaults before reading the published commitments.

How often is retention left unmanaged?

In 60 to 70 percent of agreements, which kept the standard abuse monitoring window where zero data retention was available for the use case.

Are these terms negotiable below seven figures?

Yes. In roughly 12 of 30 reviews, named retention, subprocessor and deletion clauses were accepted at mid six figure spend.

Why do those asks get accepted?

Because they restate published commitments as contract terms rather than inventing new obligations. The vendor has already conceded the substance.

What will the account team resist?

Zero retention eligibility outside a use case review, custom breach windows on smaller deals, and audit rights beyond the standard report.

Why does a policy page not suffice?

Because it can change with a web edit and an order form term cannot. Treating the two as equivalent is the most common GenAI procurement error.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
OpenAI Negotiation Guide

The full openai negotiation guide from the GenAI Practice.

Commercial levers, the nine privacy clauses, ZDR eligibility, and the redlines that pass OpenAI legal without stalling the deal.

Used across more than five hundred enterprise clients. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the software spend health check against your GenAI estate in under five minutes.
Open the Tool →