VendorScore · Comparison · Data-access posture

ChatGPT Enterprise vs Claude vs Microsoft 365 Copilot vs Gemini: which AI assistant can read your data?

Get the full 5-dimension PDFs — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

All four process your prompts and the content they retrieve in plaintext. In the scored configurations, Gemini for Google Workspace (69/100) has the least inherent vendor read access, mainly because content you protect with client-side encryption stays out of Gemini's and Google's reach; ChatGPT Enterprise and Microsoft 365 Copilot (66 each) and Claude for Work (64) offer customer-managed keys that add custody and revoke, not zero access.

Higher score = less inherent vendor read access in the scored configuration, not a more secure product. Each score comes from that vendor's VendorScore page.

Last reviewed: · Evidence date: Gemini for Google Workspace 2026-10-07, ChatGPT Enterprise 2026-10-07, Microsoft 365 Copilot 2026-10-07, Claude for Work 2026-10-07 (from each vendor page) · Sources

Side by side

Gemini for Google Workspace ChatGPT Enterprise Microsoft 365 Copilot Claude for Work
Overall score 69/100 66/100 66/100 64/100
Scored configuration Gemini in Workspace apps and the Gemini app on Workspace Enterprise Plus/Frontline Plus with data regions (in-region processing and storage), DLP/IRM, and Client-side encryption (CSE) used to keep sensitive content out of Gemini. ChatGPT Enterprise with Enterprise Key Management (customer AWS/GCP/Azure KMS), admin-set retention, SSO, Compliance API, and EU data residency where eligible. Commercial tenant with Purview Customer Key (multi-workload DEP covering Copilot interactions), Customer Lockbox, Purview sensitivity-label encryption and EU Data Boundary; AI subprocessors at their defaults. Claude Enterprise with customer-managed encryption keys (AWS/GCP/Azure KMS), custom data retention, Compliance API, and feedback ('Rate chats') disabled.
Key custody option Google-managed keys for Gemini interactions; Google documents no customer-managed key option for them. Enterprise Key Management: content keys from your AWS, Google Cloud or Azure KMS, but OpenAI still needs decrypt permission to serve the product. EKM docs checked via a search index only. Customer Key multi-workload policies encrypt Copilot interactions with your Azure Key Vault root keys (Microsoft keeps an availability key); Customer Lockbox covers Copilot interactions. Customer-managed keys (CMEK) for eligible Enterprise organizations, via your AWS, Google Cloud or Azure key; revoking it makes CMEK data permanently inaccessible. US regions only, new data only.
E2EE / CSE scope CSE-protected content only: Google says no Google system or employee has the technical means to access it, which also means no Gemini features on it. Other content Gemini retrieves is processed in plaintext. None; OpenAI makes no E2EE claim. None; Microsoft makes no E2EE claim for Copilot. None; Anthropic makes no E2EE claim.
AI training default (scored config) Not used for training by default. Google says Workspace doesn't use customer data, including prompts, to train models without your prior permission or instruction. Off by default (opt-in). OpenAI may train only on data you explicitly opt in to share, for example through feedback. Not used for training by default. Microsoft says prompts, responses and Microsoft Graph data aren't used to train foundation LLMs. Opt-in Anthropic models with Data Retention fall under Anthropic's terms. Off by default (opt-in). Exception: feedback (thumbs up/down, bug reports) stores the whole conversation for up to 5 years and may be used for training; Team and Enterprise owners can disable Rate chats.
EU residency Yes on Enterprise Plus or Frontline Plus: data regions cover Gemini prompts and responses at rest and in processing (Europe or US); Gemini Notebook is excluded. Eligible new Enterprise and Edu workspaces: in-scope content at rest in Europe (EEA + Switzerland), optional in-region inference. Checked via a search index only. Mostly: Copilot is an EU Data Boundary service, but Anthropic models are excluded from the EUDB and OpenAI-operated models from in-country processing commitments. No: Anthropic says data is stored in the US, and CMEK is US-region only.
DPA link Google DPA OpenAI DPA Microsoft DPA Anthropic DPA

Dimension scores (key custody, plaintext access, encryption claims, subprocessors, auditability) stay in the full PDFs.

What this means

Get the full 5-dimension PDFs — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: ChatGPT Enterprise vs Claude vs Microsoft 365 Copilot vs Gemini

Which AI assistant can read my data the least?

In the scored configurations, Gemini for Google Workspace scores 69/100, ChatGPT Enterprise and Microsoft 365 Copilot 66/100 each, and Claude for Work 64/100. Gemini's lead rests on client-side encryption keeping CSE-protected content out of reach; for everything else, all four process prompts and retrieved content in plaintext.

Do ChatGPT Enterprise, Claude, Copilot or Gemini train on my company's data?

Not by default. OpenAI says it doesn't use business data for training by default; Anthropic says it won't use inputs or outputs from commercial products such as Claude for Work to train its models by default; Microsoft says prompts, responses and Microsoft Graph data aren't used to train foundation LLMs; Google says Workspace doesn't use customer data for training without prior permission or instruction. Feedback flows are the main exception to check.

Do customer-managed keys stop the vendor reading my chats?

No. ChatGPT Enterprise Key Management, Claude CMEK and Copilot's Customer Key give you custody and revocation, but the service still decrypts content to work. Gemini has no documented customer-managed key option for its interactions; CSE instead keeps protected content away from Gemini entirely.

Can OpenAI, Anthropic, Microsoft or Google employees read my prompts?

OpenAI says authorized employees access Enterprise conversations only to resolve incidents, recover conversations with your permission, or where the law requires. Anthropic describes human review of content flagged by automated trust-and-safety systems by a small set of approved reviewers. Microsoft says engineers have no default access and Customer Lockbox covers Copilot interactions. Google says your content isn't human reviewed for generative AI training outside your domain without permission.

Can I keep AI assistant data in the EU?

Claude: no, Anthropic says data is stored in the US. ChatGPT Enterprise: eligible new workspaces can store in-scope content at rest in Europe (checked via a search index only). Copilot: an EU Data Boundary service, but Anthropic models are excluded from the EUDB. Gemini: data regions cover prompts and responses in Europe on Enterprise Plus or Frontline Plus.

Do these assistants send my data to other AI companies?

Microsoft's Copilot docs name OpenAI (OpenAI-operated models, on by default for eligible commercial tenants since 2026-07-24 unless admins select 'No users') and Anthropic (off by default in the EU/EFTA/UK) as AI subprocessors. Google's Privacy Hub lists no third-party AI model provider for Gemini. We couldn't read the OpenAI or Anthropic subprocessor lists directly.

Sources

Every URL cited on this page. Scores, configurations and facts come from the linked VendorScore vendor pages and their reports; nothing here goes beyond them.

Disclaimer

This comparison restates the vendor pages for the scored configurations only; default setups usually score lower. A higher score means less inherent vendor read access in that configuration, not a safety rating. VendorScore doesn't certify compliance. Public-docs review only. Not a pen test, not legal advice, not a SOC 2 substitute.