Consumer vs Business AI Tiers: Why It Matters

Photo: Mathias Reding / Pexels
Key takeaways
- Consumer vs business AI is a bigger factor in risk than the vendor's brand reputation.
- Free and Plus-style consumer tiers are built for fast sign-up and often train on your inputs by default.
- Business and enterprise tiers are built to survive procurement, with training exclusions, DPAs and admin controls attached.
- Teams often vet the enterprise tier but never migrate staff off personal accounts.
- Name the specific tier in every tool approval, not just the product name.
Ask whether ChatGPT is safe for sensitive work and you're asking the wrong-shaped question. The real question is consumer vs business AI - which plan, not which brand. ChatGPT Free, Plus, Business, Enterprise and the API are five products under one name, each with a different data policy attached. This split, cheap and fast-signup consumer tiers built for individuals, against contract-backed business tiers built to survive procurement, repeats across almost every major AI vendor. Get the tier wrong and a vendor's enterprise security page becomes irrelevant to what your team is actually using.
The pattern behind the split
Consumer tiers exist to drive adoption at scale: cheap or free access, a fast sign-up, terms written for an individual rather than an organisation. Business tiers exist to win procurement decisions, and procurement teams ask about training, retention, DPAs and BAAs, so vendors build those protections into the paid contract rather than the free one. None of this is a conspiracy; it's just where the incentives point. The free tier usually isn't technically weaker in the security sense. It's built for a different legal relationship, with a different set of commitments attached to it, and those commitments only show up once a contract, not a sign-up form, is involved.
Concrete examples across vendors
With ChatGPT, Team, Enterprise and API data is excluded from training by default, confirmed on OpenAI's business data page, while Free and Plus train on conversations unless you switch that off yourself. Microsoft 365 Copilot does not train foundation models on your organisation's data and inherits your existing Microsoft DPA, a commitment documented on Microsoft's Copilot privacy page, while the consumer Copilot experience in Bing or Windows runs under separate, weaker terms. Google Gemini for Workspace excludes your content from training, per Google's generative AI privacy hub, while the consumer Gemini app has a different default. Anthropic's Claude API isn't used for training, and according to Anthropic's privacy centre, API log retention dropped from 30 days to 7 as of 14 September 2025 - though that change applies to the API, not the free Claude.ai consumer product.
Does 'enterprise-grade' marketing mean your plan is covered?
Not automatically. A vendor's homepage will happily describe the product as 'enterprise-grade security' while the page underneath is selling a $20-a-month personal subscription with no admin console in sight. That language usually describes the vendor's best available tier, somewhere further up the pricing page, not the one sitting in your shopping basket. Confirm the specific tier's protections in the DPA or enterprise-privacy page, never from marketing copy alone, and treat any claim you can't find in a contract or a named privacy page as unverified rather than reassuring.
Why this trips teams up
A 25-person recruitment agency we spoke to had done the right thing on paper: the founder read up on ChatGPT Enterprise, liked what she saw, and told the team AI was approved. Eight months later, a security review ahead of a big client contract found half the consultants were still logging into personal ChatGPT accounts they'd signed up for before the 'approval' conversation ever happened, because nobody had actually migrated them to the paid workspace or turned off the old accounts. The vetting had happened at the brand level, in a five-minute chat about ChatGPT in general. The usage was happening on a completely different set of terms, on accounts the company didn't even have visibility into. This is the tier version of a much larger problem: once a personal account is already in daily use, it tends to stay invisible unless someone goes looking for it specifically.
What if someone's already using the free tier for work?
Assume it's happening somewhere in your business - it usually is. Check admin consoles and expense reports for personal subscriptions, ask teams directly rather than relying on IT alone to know, and migrate anyone found onto the approved workspace within the week rather than the next time someone remembers. Don't assume a policy announcement did the migrating for you; policies change what's allowed, not what people are already doing.
How to make the tier explicit in your policy
Name the specific tier in every approval: 'ChatGPT Business or Enterprise', never just 'ChatGPT'. Re-verify that tier's protections periodically, since vendors do shift what each plan includes over time, and a feature that was Enterprise-only last year sometimes moves down a tier. Add one sentence to your AI usage policy that does most of the work on its own: use the business or enterprise plan of this tool, never the free one. It costs nothing to write and closes most of the gap between what a vendor advertises and what your team is actually running.
More vendors, same shape
The pattern isn't limited to the giants. GitHub Copilot Business and Enterprise do not retain or train on prompts and code suggestions, while individual Copilot accounts have an opt-out that isn't switched on by default, so an unmanaged personal account can still be feeding a developer's proprietary code into training. Perplexity's Enterprise Pro tier excludes customer data from training and adds SSO, while the consumer product may use queries to improve the service unless a setting is changed manually. A workspace-level note-taking or writing tool often shows the same split between its team plan and an individual's personal account, another reminder that the product name tells you less than the account type attached to it. Once you've seen the split in three or four vendors, checking a fifth becomes a two-minute exercise: find the plan name, then find that plan's specific privacy commitment, not the company's general one.
Bundled AI features hide the same split
The tier question doesn't only apply to standalone AI apps. Features quietly switched on inside software you already pay for follow the same pattern: an AI assistant bundled into your notes app or your team chat tool behaves differently depending on whether your workspace sits on a plan with admin controls, or a free, individual one, and the default can shift when your organisation's subscription changes tier, not only when someone explicitly toggles a setting. Treat an AI feature bundled into existing software with the same scrutiny as a standalone tool, not less. 'We already pay for this software' answers a different question from 'we've checked what this specific AI feature does with our data.'
Check before you assume
The gap between a tool's advertised security posture and what an employee is actually using is almost always a tier gap, not a brand gap, and it's the cheapest kind of risk to close once you know to look for it. Every profile in ModelCharter's AI Tool Risk Directory states the specific tier its sourced facts apply to, and the free AI vendor risk assessment walks you through checking your own team's actual usage in a few minutes.
| Vendor | Consumer tier default | Business/enterprise tier default |
|---|---|---|
| ChatGPT | Free and Plus may train on conversations unless you opt out | Team, Enterprise and API excluded from training by default |
| Microsoft 365 Copilot | Consumer Copilot (Bing, Windows) runs on separate terms | Does not train foundation models on organisational data; covered by your Microsoft DPA |
| Google Gemini | Consumer Gemini app has its own default, distinct from Workspace | Gemini for Workspace excludes your content from training |
| Claude (Anthropic) | Claude.ai consumer defaults differ from the API | API not used for training; log retention cut to 7 days from 14 Sept 2025 |
“ChatGPT Team, Enterprise and API usage is excluded from model training by default; Free and Plus are not, unless you turn it off yourself.”