Is ChatGPT safe? The ultimate guide for privacy risks, lawsuits, and tips
ChatGPT is generally safe for everyday tasks, but it pays to be mindful of what you share with it. Learn about its privacy risks, security features, and limitations, then bring Norton Scam Protection into ChatGPT to help identify suspicious links, messages, and scams before you act.
ChatGPT is generally safe for everyday tasks like researching, drafting, and brainstorming, but it carries real privacy and security risks. Privacy concerns relate to the amount of user data that’s stored and how long it’s retained, while security risks include cybercriminals exploiting this powerful technology to run convincing scams.
Here, we’ll unpack the key things you need to know about ChatGPT, including its security and privacy risks, its built-in privacy features, recent lawsuits against its parent company OpenAI, and how to use it responsibly.
What is ChatGPT?
ChatGPT is a type of generative AI that responds to your prompts by generating natural, human-like text. People use it to research, generate code, get writing help, and brainstorm ideas. It’s built on a large language model (LLM) that’s been trained on massive amounts of data and can fire back a human-sounding answer in seconds.
Like most cloud services, data you input to ChatGPT is transmitted across the internet to its servers. The data is encrypted in transit and isn’t published or indexed anywhere. But nothing transmitted over the internet is 100% secure or private in theory, so avoid sharing personal, financial, or sensitive information.
While the chatbot itself is safe to use, cybercriminals can misuse AI tools to support malicious activities. For example, they may use ChatGPT to help generate code or convincing text for phishing websites, scam campaigns, or malware-related projects, making fraudulent sites and attacks appear more legitimate.
ChatGPT security and privacy risks
The popularity of LLMs like ChatGPT has made traditional cybersecurity threats like fake apps and phishing scams more convincing, scalable, and accessible to novice cybercriminals. The rise of AI has also brought new risks, including VibeScammed websites and prompt injection attacks.
By mid-2025, Sift reported a 62% increase in the number of people successfully targeted by AI scams from 2024. As AI tools become part of everyday life, attackers keep finding smarter ways to exploit them.
Data breaches
A data breach occurs when sensitive data is exposed without authorization and then accessed and used by a cybercriminal. For example, if personal data you shared in a conversation with ChatGPT is compromised, it could put you at risk of identity theft or personalized scams.
Although OpenAI shares content with, as it describes, “a select group of trusted service providers,” it claims not to sell or share user data with third parties, like data brokers, who would use it for marketing or other commercial purposes.
But AI tools can still accidentally leak sensitive information. This was the case in these recent incidents:
- In what became one of ChatGPT’s more embarrassing incidents, Google indexed links to conversations users had shared, making private chats about health conditions, legal questions, and business strategies searchable by anyone. OpenAI removed the feature and worked with Google to scrub the results.
- A breach at a third-party analytics vendor exposed customers’ identifying information. OpenAI was quick to note that its own systems weren’t compromised, but that’s precisely the point: ChatGPT’s data footprint doesn’t end at OpenAI’s servers, and third-party vendors pose a liability the company can’t fully control.
These incidents illustrate how data shared with any large online platform, including ChatGPT, can surface in unexpected ways. The safest assumption is to treat anything you type into ChatGPT as potentially accessible beyond your conversation window.
Prompt injection attack
Prompt injection attacks happen when someone hides malicious instructions to trick an LLM into ignoring prior instructions and taking a different action. This usually happens indirectly, through hidden instructions in data that ChatGPT is asked to process, rather than simply hiding a command in a user prompt.
For example, you may ask an AI tool to summarize information on a website. If that website contains a hidden, malicious instruction, the tool may execute it, ignoring prior instructions or safeguards.
A successful attack can expose sensitive data, trigger unwanted actions, or bypass safety filters. As ChatGPT becomes more deeply embedded in productivity workflows by summarizing emails, reading documents, and browsing the web, the attack potential for prompt injection grows.
These hidden commands can lurk inside uploaded text, form fields, or in ordinary user prompts — though most major LLMs can now detect this type of attack and ignore direct prompt injection in user prompts.
Data poisoning
Data poisoning is when bad actors slip false or toxic information into the data used to train AI. This can lead to biased, inaccurate, or unsafe responses. Over time, the model’s “brain” gets warped, generating half-truths and bad advice that can slowly erode trust, one prompt output at a time.
Research from Anthropic, the company behind the Claude LLM, showed that even a relatively small amount of bad data can mess up a big AI model’s behavior. Because these LLMs scrape so much information from the web, these poisoned documents can sneak in and cause the model to misbehave in ways you wouldn’t expect.
ChatGPT privacy features
ChatGPT offers several privacy controls that let you manage how your conversations and data are handled. But disabling a feature doesn't necessarily mean your previous data is immediately deleted, so it's worth understanding the limits of each privacy option.
Here’s what each control does, and what they can and can’t do:
- Turning off chat history/opting out of model training: Prevents your chats from being used to train future models. Chats are still stored on OpenAI’s servers for 30 days before deletion. This setting does not apply retroactively, and data already used in training is not removed.
- Temporary Chat (incognito mode): Chats aren’t saved to your history or used for training, and they disappear after the session ends. However, OpenAI retains a copy on its servers for up to 30 days for abuse detection, so “temporary” doesn’t mean no record. A 2026 update added the option to retain personalization settings (like memory and tone preferences) even in Temporary Chat, giving users more flexibility without sacrificing session privacy.
- Deleting your chat history: Removes conversations from your visible history immediately, but not necessarily from OpenAI's systems. Deleted chats are typically retained for up to 30 days before permanent deletion. In some cases, they may be kept longer if required for legal, security, or operational reasons, or if they're already de-identified. If your account is subject to a legal hold, retention may be extended.
- Memory settings: You can view, edit, or delete what ChatGPT remembers about you. Memories aren’t used in Temporary Chat sessions, giving you a clean slate when needed.
ChatGPT isn't private by default. Depending on your settings, OpenAI may retain and review conversations for safety, security, and policy enforcement. If you're discussing sensitive topics, use Temporary Chat and avoid sharing information you wouldn't want stored. More broadly, protecting your privacy online requires good habits beyond any single app — our internet privacy guide explains the tools and practices that can help.
ChatGPT misuse
While ChatGPT was built for productivity, efficiency, and learning, AI scammers can exploit its capabilities for criminal gain. Some use it to write malicious code, while others use it to automate social engineering schemes. OpenAI does have guardrails in place, but no system can entirely prevent misuse.
Malicious code generation
Malware is malicious software that cybercriminals use to gain access to and damage computer systems or networks. All types of malware require computer code, meaning hackers generally have to know a programming language to create new malware (or they buy it illegally in shady dark web marketplaces).
Scammers can now use ChatGPT or similar tools to indirectly write, or at least improve, malware code for them. Although ChatGPT has security measures in place to detect malicious intent, and the tool doesn’t knowingly write malicious code, there have been cases of users bypassing those restrictions.
A team of researchers from Cornell Tech, Technion, and Intuit demonstrated that generative AI systems, including ChatGPT, can be vulnerable to zero-click AI worms. In their proof-of-concept attack, the worm spread by exploiting how AI assistants process malicious prompts hidden in content, without requiring the user to click a link or download a file.
Scam message creation
Cybercriminals can also use ChatGPT to craft phishing emails, catfishing profiles, and whaling attacks that mimic real communication styles. The model’s ability to generate natural, convincing text makes social engineering scams more believable.
A study published in Expert Systems with Applications in 2026 found that AI-generated spear phishing emails were just as effective as those written by human experts, achieving a 54% click-through rate compared to 12% for generic phishing emails.
Attackers trick victims into revealing personal information, transferring money, or clicking malicious links disguised as messages from trusted brands or executives. Crucially, LLMs like ChatGPT allow scammers to scale their attacks. This was found to boost scam ROI by up to 50 times according to the same study.
Our own threat researchers came to similar conclusions about how LLMs make scams scalable when they studied AI-generated fake websites, which they dubbed VibeScams. These malicious websites, which look and feel real (thereby passing the “vibe check”), can be built in mere minutes.
Academic and professional dishonesty
Some students use ChatGPT as a shortcut, but not one that enhances their learning. Instead of doing the work themselves, they’ll let the AI assistant generate essays, homework, or exam answers, then put their name on it. To counter this, many schools now use AI detection tools and stricter policies to help flag fake work and encourage responsible AI use.
The issue extends beyond the classroom. In the workplace, some employees use ChatGPT to generate reports, emails, or other content and present it as entirely their own. While workplace policies vary, passing off AI-generated work as original can raise ethical concerns and, in some cases, amount to plagiarism.
Whether at school or work, relying too heavily on AI without proper disclosure can undermine credibility and limit the development of critical thinking and communication skills.
ChatGPT misinformation
Some of the risks associated with using ChatGPT don’t even need to be deliberate or malicious to be harmful. While LLMs are trained on vast amounts of data and can answer many questions accurately, they’ve been known to make serious errors and generate false content.
No matter how you use ChatGPT or any other generative AI, it’s crucial to fact-check the information it outputs.
Hallucinations
ChatGPT can sometimes generate incorrect or entirely fabricated information, a phenomenon known as a “hallucination.” These errors may include inaccurate facts, made-up statistics, misattributed quotes, or references to sources that don't exist.
Hallucinations occur because ChatGPT generates responses by predicting likely sequences of words rather than verifying every statement against authoritative sources. Research shows that large language models (LLMs), like that behind ChatGPT, can produce plausible-sounding but incorrect answers, with accuracy varying depending on the model, the topic, and how a question is phrased.
Errors are generally more common for niche subjects, recent events, and questions requiring precise numbers, citations, or highly specialized knowledge. For important decisions or factual claims, it's always best to verify the information using trusted, up-to-date sources.
Complex reasoning failure
ChatGPT can process information in seconds, but it doesn’t reason like a human. When faced with complex, multi-step questions, it can draw the wrong conclusions, mix up facts, or invent convincing but inaccurate details.
Essentially, when deeper, structured reasoning is needed, AI still falls short. This becomes especially risky when people treat ChatGPT as a substitute for professional guidance. As of late 2025, multiple lawsuits have been filed in the U.S. and Canada alleging that ChatGPT’s responses caused direct harm to vulnerable users — cases detailed in the lawsuits section below.
The pattern across these filings is consistent: when users treat ChatGPT as an authoritative advisor rather than a text generator, the consequences can be serious.
Content bias
Because ChatGPT is trained largely on data from the internet, which is filled with cultural, political, and social biases, it’s no surprise that these biases are baked into the model. So, when you ask a question, you may not always get the truth; you’re getting a reflection of current consensus. This can also lead to knowledge gaps, where the model may avoid or oversimplify topics it doesn’t fully understand.
Rival AI models also face the same problem. They may have different training data and use a different tone, but the inherent biases are still present.
OpenAI and ChatGPT Lawsuits: What Users Need to Know
OpenAI is currently facing legal challenges on multiple fronts — from copyright disputes over how ChatGPT was trained, to allegations that its products caused direct harm to users.
These cases won’t necessarily change how you use ChatGPT day-to-day, but some of them have already affected how your data is being retained. Here’s what’s happening and what it means for you:
Copyright lawsuits
The New York Times sued OpenAI, claiming ChatGPT was trained on copyrighted content without permission or payment. As of early 2026, 16 related lawsuits were consolidated into a multidistrict litigation in the Southern District of New York.
In January 2026, a federal judge ordered OpenAI to produce 20 million anonymous ChatGPT conversation logs to the plaintiffs — a significant legal setback for the company. OpenAI denies wrongdoing and argues its use qualifies as fair use.
Some comparable cases, like Kadrey v. Meta, have seen fair use arguments succeed — but narrowly, and the judge in that case was careful to note that AI training isn’t automatically protected just because it's transformative. The NYT case remains ongoing.
What this means for users: While OpenAI was previously required to preserve some user conversations, including deleted chats, that order ended in September 2025, and standard deletion practices resumed. However, chats from April through September 2025 may still be retained as legal evidence, even if users deleted them during that period.
Mental health and harm lawsuits
As mentioned earlier, seven lawsuits were filed in California alleging ChatGPT provided harmful guidance to vulnerable users, with some cases alleging the interactions contributed to suicide.
Additionally, in April 2026, families of victims of the Tumbler Ridge school shooting in British Columbia filed suit against OpenAI in a U.S. federal court. The filing alleges the company failed to alert authorities after its own automated systems flagged the shooter’s violent conversations months before the attack.
OpenAI has said it has strengthened its safeguards since. These cases are in early stages, but they’re expected to test a fundamental legal question courts haven’t yet answered: what responsibility do AI platforms carry for user actions?
Elon Musk vs. OpenAI
Musk sued OpenAI and its leadership, alleging the company abandoned its nonprofit mission and made deceptive commitments to early backers. A court denied his request for a preliminary injunction in 2025, and the case went to trial in spring 2026. In May 2026, a jury sided with OpenAI, finding that Musk had waited too long to sue and that his claims were barred by the statute of limitations.
It’s worth noting that Musk also competes with OpenAI through his own AI company, xAI. That conflict of interest was part of what OpenAI leaned on in its defense.
How does ChatGPT protect users?
ChatGPT has robust measures in place to protect your privacy and security as you interact with the AI. Below are some key examples of how ChatGPT protects users:
- Encryption: Encrypting data scrambles information into unreadable code that only someone with the right key can unlock. All data transferred between you and ChatGPT is encrypted in transit, so even if it were intercepted, it couldn’t be read by hackers without an encryption key.
- Data handling compliance: Data handling practices differ by version. Enterprise and API users get advanced privacy controls, while the consumer versions may use data for training purposes and store chats for up to 30 days. That said, when a court order is in place (like the NYT lawsuit preservation order), deleted chats may be retained beyond the standard 30-day window for legal purposes.
- Security audits: ChatGPT undergoes an annual security audit conducted by independent cybersecurity specialists who attempt to spot potential vulnerabilities.
- Threat monitoring: ChatGPT’s Bug Bounty Program encourages ethical hackers, security researchers, and tech enthusiasts to hunt for and report any potential security weaknesses or bugs. OpenAI also continuously monitors for malicious activity, abuse patterns, and security vulnerabilities in real time.
- User authentication: Access to ChatGPT requires account verification, login credentials, and secure HTTPS connections to prevent unauthorized use on paid plans. In 2025, OpenAI also added passkey support as a login option for a more phishing-resistant alternative to traditional passwords.
- Continued AI model training: ChatGPT continuously develops its platform using model updates and data from conversations (for those who opt in). Users who prefer not to contribute their data can disable model training in Settings > Data controls. Temporary Chat mode bypasses training entirely, regardless of account-level settings.
How to use ChatGPT safely
Despite ChatGPT’s security measures, as with any online tool, there are risks. Here are some key tips and best practices for staying safer while using ChatGPT:
- Create a strong password for your account: Follow good password security practices by creating strong, unique passwords. Consider using a password manager to securely store all of your details.
- Don’t share sensitive data: Keep personal details private and never disclose financial or other confidential information during conversations with ChatGPT.
- Fact-check AI outputs: ChatGPT’s outputs are not always accurate. That’s why cross-checking additional sources ensures your data isn’t false, misleading, or biased.
- Report problematic outputs: Reporting problematic outputs helps create a feedback loop that flags harmful, biased, or misleading content for review. This can help OpenAI improve response accuracy and objectivity, and reduce future risks.
- Stop ChatGPT from training AI on your data: Check your ChatGPT version and disable model training to reduce the risk of data exposure.
- Use Temporary Chat for sensitive topics: Switch to Temporary Chat when discussing health, legal, or financial matters. Note: OpenAI may still retain a server-side copy for up to 30 days for abuse detection, but it’s a meaningfully better option for privacy-sensitive conversations.
- Understand what deleting actually means: Removing your chat history in ChatGPT is not the same as permanently deleting it. Chats typically remain on OpenAI’s servers for 30 days. If your account is subject to a legal hold, deleted chats may be retained even longer. Treat past conversations as potentially recoverable.
Outsmart advanced AI scams with Norton
ChatGPT is generally safe to use as long as you’re careful about what you share. But staying safe online still takes a little effort on your part. As AI-generated phishing tactics grow more convincing, having a tool that can flag threats before you engage is more valuable than ever.
That’s where Norton Scam Protection can help. It uses smart technology, including AI-powered detection, to help you determine whether you’re looking at a scam. And now, it’s available directly in ChatGPT — so you can get scam advice delivered right where you're chatting.
Frequently Asked Questions
Is ChatGPT regulated?
ChatGPT sits in a gray regulatory zone. For example, the EU’s AI Act lays down rules on transparency and safety, but in most other regions, comprehensive AI regulation doesn’t exist yet. However, there are some emerging U.S. state laws and voluntary guidelines on the way.
Does OpenAI sell my data to third parties?
OpenAI states that it doesn’t sell user data to third parties such as data brokers or advertisers. It does share data with a “select group of trusted service providers” that help operate its infrastructure. But these relationships are governed by data processing agreements, not commercial data sales.
With the introduction of ads in early 2026, this policy warrants close monitoring: OpenAI has stated that its ad model will not involve sharing personal data with advertisers, but users should periodically review OpenAI’s privacy policy as the ad model evolves.
Does the OpenAI lawsuit affect my ChatGPT data?
For a stretch of 2025, yes — a federal court ordered OpenAI to preserve all user conversations indefinitely, including ones people had deleted, in case they became evidence in the New York Times copyright case. That order ended in September 2025, and OpenAI returned to its standard practice of deleting conversations within 30 days on Free, Plus, Pro, and Team plans.
The one exception: a specific window of data from April through September 2025 is still being preserved for the litigation. If you used ChatGPT during that period, those conversations may still exist even if you deleted them. Outside that window, standard deletion timelines apply. If you have concerns about older conversations, the safest move going forward is to use Temporary Chat for anything sensitive.
Can I consult ChatGPT about medical and mental health concerns?
You can ask ChatGPT general questions about health topics, but you shouldn’t use it in place of a medical health professional — it can’t diagnose or assess your specific situation. Plus, its answers might be inaccurate, and relying on them could delay proper medical care.
As of late 2025, multiple lawsuits have been filed in the U.S. alleging that ChatGPT provided dangerous guidance to vulnerable users, a reminder that the stakes of misplaced AI trust can be very real.
Is ChatGPT safe for kids?
No, you shouldn’t let your kids use ChatGPT without adult supervision. The bot can still generate inappropriate responses or encourage kids to provide personal information. OpenAI requires users to be at least 13 years old, but there are no robust age-verification mechanisms in place, making parental oversight and device parental controls essential.
Editors’ note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.
Want more?
Follow us for all the latest news, tips, and updates.