Skip to content
Enclavean
All insights

Why ChatGPT Enterprise is not enough for regulated data

/3 min read/Enclavean

Most organisations evaluating AI start in the same place. Someone trials a public tool, the productivity gain is obvious, and the question becomes how to roll it out safely. The usual answer is to upgrade to an enterprise tier, on the assumption that the enterprise badge resolves the risk.

For most organisations, it does. For organisations holding regulated, classified or commercially sensitive information, it does not, and the reason is worth understanding precisely.

What an enterprise tier actually changes

Enterprise agreements from public AI providers typically give you a commitment not to train on your data, a longer list of compliance attestations, administrative controls such as SSO and user management, and a contractual promise about retention.

These are real improvements. They are also, without exception, contractual improvements. They are promises about how someone else will behave with your data once they have it.

What it does not change

The architecture is unchanged. Your prompts, your documents and your retrieved context still leave your environment and are processed on infrastructure you do not operate, cannot inspect, and cannot audit independently.

That leaves four questions you still cannot answer to a regulator's satisfaction:

  1. Where exactly was this processed? You have a jurisdiction clause, not a demonstrable boundary.
  2. Who could technically access it? Not who is permitted to, but who could.
  3. What is the sub-processor chain? Each link is another party in scope for your Article 28 obligations.
  4. Can you produce an independent audit trail? Provider-supplied logs are provider-supplied.

For a marketing team, these questions are academic. For a clinical safety officer, a defence supplier or a firm holding privileged client material, they are the entire assessment.

Trust as an architectural property

The distinction that matters is between risks that are mitigated by policy and risks that are removed by design.

A policy says data will not be retained. An architecture where data never leaves your network means retention by a third party is not a possibility that requires a policy at all. You are no longer auditing a promise. You are auditing a boundary, and a boundary is something you can demonstrate.

This is the principle Enclavean is built on. AI runs inside your infrastructure or a dedicated private cloud. Retrieval happens against your own indexed sources, behind your existing access controls. There is no path to a public provider, so there is nothing to promise about.

When a public enterprise tier is the right answer

It usually is, and pretending otherwise would be dishonest. If your data is not regulated, not confidential and not commercially sensitive, a public enterprise tier is cheaper, faster to deploy and perfectly appropriate. Frontier models are excellent and the operational burden is near zero.

The calculation changes when one of the following is true:

  • A breach would be a breach of statutory or professional duty, not just an incident
  • You must evidence data residency to a regulator, client or board
  • Your material is covered by legal privilege, patient confidentiality or a security classification
  • Your contracts impose obligations you cannot flow down to an opaque sub-processor chain

If none of those apply, use the public tier. If any of them do, the question is not which provider to trust. It is whether trust should be required at all.

A practical evaluation

If you are assessing options now, the useful test is a single question put to each vendor:

Describe the technical path by which our data could reach a system we do not operate, and show us the control that prevents it.

A good answer is specific and architectural. It names the boundary and the enforcement point. A weaker answer restates the contract.

That question separates the two categories quickly, and it is the one we would expect any serious buyer to ask us.

Talk to us

Bring AI to your most sensitive work, without giving up control.

Tell us about your environment and the outcomes you are after. We will walk you through the deployment model, security architecture and integration approach that fit.