ChatGPT、Claude、Geminiに貼り付けても安全なものは何か

いちばん安全な選択は、いちばん高い選択ではありません。個人向けのProプランにお金を払って手に入るのは、より優れたモデルであって、会社のデータを守る契約ではありません。

ビジネスと経済 · 2026-09-03

チームの誰かが、2つの画面を並べて仕事をしています。片方には顧客ファイル、もう片方にはチャットボット。手早く要約を得ようと数段落を貼り付けると、うまくいきます。そして翌日も、また同じことをします。そこで浮かぶのは、もっともな問いです。これらのツールのうち、本物の仕事を任せて安全なのはどれか。

ところが、これは間違った問い、少なくとも最初に立てるべき問いではありませんでした。あなたのリスクを左右する分かれ目は、どのチャットボットかでもなければ、無料か有料かでもありません。従業員が入力しているアカウントが本人のものか、それとも会社のものか。そこにあります。

分かれ目は無料か有料かではない

それぞれ異なる役割を与えられた4つのAIモデルが、Poloraの対話でこの問いをともに検討し、ひとつの出発点で一致しました。すべてのアカウントを、2つの山のどちらかに分けることです。ひとつめの山には個人アカウントが入ります。Plus、Pro、Max、Advancedといったおなじみの名前がついた有料のものも、ここに含まれます。ふたつめの山には、会社が従業員のために用意して管理するアカウント、ビジネスプランやエンタープライズプランとして売られているものが入ります。

この分け方が価格よりも重要なのは、ふたつの山を律しているものが違うからです。個人アカウントは、有料であってもなくても、誰もが同意ボタンを押す標準の規約のうえで動きます。会社アカウントは、提供元とあなたの会社との間で結ばれた契約のうえで動きます。ここから先の話は、ほとんどすべてがこの一点の違いに行き着きます。

アカウントを律するのは、標準の規約か、会社との契約か。 · 個人アカウント 個人アカウントは、有料であってもなくても、誰もが同意ボタンを押す標準の規約のうえで動きます。 · 会社アカウント 会社アカウントは、提供元とあなたの会社との間で結ばれた契約のうえで動きます。
アカウントを律するのは、標準の規約か、会社との契約か。 · 個人アカウント 個人アカウントは、有料であってもなくても、誰もが同意ボタンを押す標準の規約のうえで動きます。 · 会社アカウント 会社アカウントは、提供元とあなたの会社との間で結ばれた契約のうえで動きます。

入力したものはモデルの学習に使われるか

個人側では、公表されている方針がいまや同じ方向を指しています。あなたが入力したものは、誰かが設定画面を開いてオフにしない限り、将来のモデルを学習させるために使われうる、というものです。これは3つのサービスすべてに当てはまり、そのうちのひとつは立ち止まって見る価値があります。最近になって変わったからです。

長らくClaudeは、既定では個人の会話を学習に使っておらず、安全な例外として広く扱われてきました。パネルのリサーチャー役が現行の方針を確認したところ、その例外はなくなっていました。Anthropicは2025年に消費者向け規約を改定し、Free、Pro、Maxの各アカウントのデータをモデルの改善に使えるようにしました。設定は、ユーザーが自分でオフにしない限りオンのままです。現時点では、消費者向けの3製品はいずれも、既定であなたの入力を学習に使います。

契約がものを言うのは、ビジネスおよびエンタープライズの区分です。OpenAI、Anthropic、Googleはいずれも、ビジネス顧客のコンテンツを既定では汎用モデルの学習に使わないと明言しています。ここでは顧客はあなたの会社であり、その約束は、従業員一人ひとりが忘れずに切り替えねばならないスイッチではなく、契約の条項です。

落とし穴はこうです。このオフ設定が効くのは、全員が忘れずに切り替えたときだけ。しかも、全員が切り替えたと証明する手立ては、あなたにはありません。

データはどれだけの間残るか

保持期間は、こうした懸念のなかでもっとも地味で、そしてしばしばもっとも意外なものです。個人アカウントでは、あなたの会話はふつう、削除するまで履歴に残り続けます。しかも削除は、必ずしもその場で済むわけではありません。

具体的なあり方は提供元によって異なります。OpenAIは、削除された会話を一定の期間内にシステムから消去すると述べています。ただし、保持が義務づけられる場合は別です。Googleの消費者向けGeminiは、既定で一定期間アクティビティを保持し、その期間は変更できます。3か月に短縮することも、より長い期間に延ばすこともできます。人間のレビュー担当者が目にした会話は、あなたがアクティビティを削除した後でも、最長で3年間保持されることがあります。Anthropicの新しい規約は、もっとも踏み込んでいます。消費者ユーザーが自分のデータをモデル改善に使うことを認めた場合、保持期間は5年に及ぶことがあります。

会社が管理するアカウントでは、管理者が全員に対して保持と削除のルールを定めます。Google Workspaceには、記録を保全し取り出すために作られたツールも加わります。要点は、こうした期間が常に短くなるということではありません。決めるのが個々の従業員ではなく会社である、ということです。

訴訟が明るみに出すもの

パネルは、見落としやすい一点をはっきりと述べました。あなたのデータを学習に使わないという約束は、そのデータが決して開示されないという約束ではない、と。どの提供元が保持している情報であっても、召喚令状や裁判所の命令、あるいは紛争が始まって以降のあなた自身の義務を通じて、なお手が届きうるのです。

ここで消費者向けアカウントは、とりわけ厄介なものになります。関係する会話が従業員の個人アカウントに存在する場合、会社は基本的な問いにすら答えられないことが少なくありません。誰が顧客データをAIに使ったのか。その人は正確には何をアップロードしたのか。訴訟が始まったとき、それらの会話を保全し、適切に収集して提出できるのか。この最後の手続きは法的ディスカバリーと呼ばれますが、記録が会社からは見えないアカウントに散らばっていると、これを満たすのは困難です。ビジネス区分は法的リスクを消し去りはしませんが、対応に必要なもの、すなわち中央に集約された本人確認、ログ、保持の管理、そして訴訟に備えて記録を保全する仕組みを、会社に与えます。

※ 法的ディスカバリーとは、訴訟の一段階で、各当事者が、相手方から求められた文書や記録を引き渡さなければならない過程を指します。

では、Proにお金を払えば解決するのか

これこそ、多くの人が本当に答えを知りたい問いですが、パネルの答えはノーでした。個人向けのProやAdvancedのプランで買えるのは能力です。すなわち、より強力なモデル、より高い上限、より長い記憶、より多くの機能です。それは、あなたのデータを律する契約ではありません。

そこから抜け落ちているのは、ビジネス区分を別物にしていたすべてです。会社と提供元の間の契約はなく、全従業員に学習の設定を必ずオフにさせる手立ても、オフにしたと確認する手立てすらありません。データがどれだけの間存続するかを組織全体で制御することもできず、訴えられたときに会話を確実に保全したり書き出したりする手立てもありません。有料の個人プランと無料アカウントは、会社アカウントよりも、互いのほうにはるかに似ています。

パネルが挙げたもうひとつの注意は、どの区分を使うかにかかわらず当てはまります。秘匿特権のある法律資料や機微な交渉の内容を、外部のAIサービスに貼り付けること自体が、独自の守秘上の問題を生みかねません。そしてそれは、どんな契約プランでも解決しません。そうした用途は、弁護士の承認のもとに置かれるべきものです。

小さなチームでも実際に守れるルール

パネルが行き着いたのは、1ページに収まるほど簡単なルールでした。個人のAIアカウントは、無料であれ有料であれ、すでに公開されている情報、架空の情報、あるいは識別につながる細部を本当に取り除いた情報のためのものです。本物の顧客データや会社の機密文書は、会社が承認したビジネスまたはエンタープライズのワークスペースにのみ、しかもその具体的な用途が認められた場合にのみ入れます。

平たく言えば、顧客の名前、財務や健康の記録、パスワードや鍵、ソースコード、契約書、人事ファイル、そして他者の守秘義務のもとで受け取ったものはすべて、どれほど高くつこうとも、消費者向けアカウントには入れないということです。このやり取り全体から持ち帰るべきことは短い。無料のツールと個人向け有料のツールは同じものとして扱い、プランの価格には答えの質を決めさせても、データの安全を決めさせてはならない。

ChatGPT、Claude、Geminiに貼り付けても安全なものは何かChatGPT、Claude、Geminiに貼り付けても安全なものは何か従業員が顧客ファイルの数段落をチャットボットに貼り付けて要約を得る。翌日もまた同じことをする。どのツールが安全かを問いたくなりますが、リスクを左右するのは、入力しているアカウントが本人のものか、それとも会社のものか、その一点です。分かれ目は無料か有料かではない · アカウントを律するのは、標準の規約か、会社との契約か。入力したものはモデルの学習に使われるかデータはどれだけの間残るか訴訟が明るみに出すものでは、Proにお金を払えば解決するのか無料のツールと個人向け有料のツールは同じものとして扱い、プランの価格には答えの質を決めさせても、データの安全を決めさせてはならない。出典 help.openai.com · OpenAI : keeping history on while disabling training, anthropic.com · Anthropic : updates to our consumer terms, docs.anthropic.com · Anthropic : data usage

People on my team paste customer data and internal documents into ChatGPT, Claude, and Gemini every day, and I am not sure which is actually safe. Explain clearly, for someone who is not a lawyer, the real difference between the free and personal-paid consumer plans and the business or enterprise tiers on three points: whether your input is used to train the model, how long it is retained, and whether it could surface in legal discovery. Use each provider's current published policy. What practical rule should a small company set for what can and cannot go into a consumer AI account, and does paying for a Pro subscription actually fix the problem, or only buy better models?

Corporate Risk and Compliance Specialist · claude-sonnet-5

The core risk framework, from a compliance perspective Let me give you the practical mental model, since I don't have live search this round to pull exact clause text — treat specific retention-day numbers as approximate and worth verifying against current policy pages before you finalize a written policy. The general pattern across all three providers Free / consumer personal-paid (ChatGPT Plus, Claude Pro, Gemini Advanced): - Your content can be used to improve/train models by default unless you manually opt out in settings (OpenAI, Google) — Anthropic has generally been more conservative here but check current terms. - Retention is typically tied to your account and can persist even after deletion for some backend period (often 30 days minimum for abuse/safety review, sometimes longer). - No contractual protection. These are consumer terms of service — click-through agreements, not negotiated contracts. There's no Business Associate Agreement, no data processing addendum, no liability structure. - Discovery exposure: consumer accounts have essentially no defined legal hold, litigation hold, or discovery-response process. If you're sued and opposing counse…

IT Operations and Security Administrator · deepseek-v4-pro

I’m an IT/security admin, not a lawyer — so here’s the operational read. Short answer: none of the consumer plans — free or the paid “Pro/Max/Advanced” ones — are safe for customer data or internal documents. The business/enterprise tiers are materially safer, but only if you actually configure and enforce them. Paying for Pro mostly buys better models and higher limits, not corporate data protection. The three points that actually matter 1. Is your input used to train the model? Consumer plans: - ChatGPT free/Plus/Pro — training is on by default. OpenAI says it may use your content to improve models unless the user turns off “Improve the model for everyone” in settings. That is a personal opt-out, not a company control. - Gemini consumer apps — Google uses consumer Gemini conversations to improve and train its models. On a personal Google account, you should assume training/human review is in play unless you’ve specifically limited or turned off activity settings. - Claude free/Pro/Max — this is the exception. Anthropic generally does not train on consumer content by default; training is opt-in. But that still doesn’t make it a corporate too…

Researcher · claude-sonnet-5

Fact-check: one important correction, everything else largely holds up I ran three searches to verify the specifics both debaters used. The overall three-tier framework both of you laid out is directionally correct and well-matched to current published policy — but there's one significant factual error in the IT Admin's post that changes the picture for Claude specifically. Correction: Claude is NOT currently the "training-off exception" The IT Admin stated: *"Claude free/Pro/Max — this is the exception. Anthropic generally does not train on consumer content by default; training is opt-in."* This was true historically but is no longer accurate. Anthropic changed this in a major policy shift: - Effective September 2025, Anthropic's own documentation states: "Consumer users (Free, Pro, and Max plans): Starting August 28, 2025, we're giving you the choice to allow your data to be used to improve future Claude models. We will train new models using data from Free, Pro, and Max accounts when this setting is on." - Critically, the setting defaults to ON, not off — a third-party review notes "The current policy frames consumer training as opt-out, the opt-out itsel…

The Arbiter · gpt-5.6-terra

The useful line is not “free versus paid.” It is personal consumer account versus company-managed business/enterprise account under business terms. One correction to carry into the final answer: Claude consumer plans should not be treated as a training-safe exception. Anthropic’s current consumer policy makes model-improvement sharing an opt-out choice, with the setting on by default for applicable new/resumed activity; opting in can also bring a much longer retention period. So, in practice, all three consumer services require a “do not enter confidential company data” rule, whether free or personally paid. Two nuances are essential: - “Not used for training” is not “cannot be disclosed.” Data held by any provider may still be subject to lawful subpoena, court order, regulatory request, or your own discovery obligations. - Enterprise is risk reduction and governance, not a magic confidentiality cloak. It gives the company contractual terms, admin control, identity management, retention/deletion settings, and often audit/e-discovery capabilities. It does not cure an NDA breach, eliminate privilege-waiver risk, or make sensitive data appropriate to paste without a…

The Arbiter's Final Verdict · gpt-5.6-terra

Bottom line For company data, the meaningful dividing line is not free versus paid. It is: - Personal/consumer account — including paid personal plans such as ChatGPT Plus/Pro, Claude Pro/Max, and Gemini Advanced. - Company-managed business or enterprise account — under business terms, with admin controls and usually a DPA or equivalent privacy commitments. A personal Pro subscription generally buys better models, higher limits, and features. It does not turn a consumer account into a company-controlled, contract-protected workspace. For a small company, the safe default is: > Do not put customer data or confidential internal material into any consumer AI account, even a paid one. > Use consumer AI only for public, synthetic, or genuinely de-identified information. Use real business data only in an approved company business/enterprise workspace. The practical differences | Question | Consumer free / personal-paid plans | Business / enterprise tiers | |---|---|---| | Can prompts be used to train models? | Often yes by default or unless each user opts out. This applies to current consumer offerings from OpenAI, Anthropic, and Google. | Providers…