From Aryan Vatsa | Product & Market Analysis

ChatGPT, Claude and Gemini Enterprise: Governance Decides, Not the Model

On this page

Three vendors sell an enterprise AI assistant, and on answer quality they are close enough that a bake-off rarely separates them. On governance they are not close at all. Claude Enterprise exports 180 days of audit events and strips chat content out of them. ChatGPT Enterprise offers data residency in 10 regions. Gemini Enterprise ships its most useful log type switched off.

Key takeaways

  • Model tier is the wrong variable to score. All three vendors ship their strongest general model on the enterprise plan and refresh it several times a year, so a quality ranking made in March describes a product that no longer exists in June.
  • Audit logging is the widest gap and the least advertised. Claude audit log exports carry event identifiers but not chat titles or content. Google's Data Access audit logs are disabled by default on every service except BigQuery.
  • Residency splits the three cleanly. ChatGPT Enterprise offers at-rest residency across 10 regions. Claude Enterprise's first-party control is US-only inference, billed at 1.1x standard rates. Gemini Enterprise inherits Google Cloud regions, with named exclusions.
  • Connector control is where Anthropic is furthest ahead and everyone is exposed. Claude Code admins can allowlist MCP servers by URL and command. Every platform still stops at the connector boundary, where a third party processes the data on its own infrastructure.
180 daysThe Claude Enterprise audit log window. Titles and content of chats are excluded from the export. Source: Anthropic Help Center.
10 regionsAt-rest data residency options for ChatGPT Enterprise, Edu and the API, as of November 2025. Source: Computerworld.
Off by defaultGoogle Cloud Data Access audit logs, the ones that record reads and searches. Source: Google Cloud documentation.

What actually separates the three enterprise plans

Most enterprise AI evaluations start the same way. Someone assembles a prompt set, runs it through three assistants, and scores the answers on a spreadsheet.

The exercise is worth doing once. It stops being worth doing the moment the three scores land within a few points of each other, which is now the ordinary result rather than the surprising one.

What survives the tie is administrative. Who can switch a connector on. Where the data sits at rest. What the log records, how long it keeps it, and who can read it eighteen months later during a regulatory review.

The model tier stopped being the variable

All three vendors put their strongest general-purpose model on the enterprise plan. All three replace it several times a year. Your evaluation is a photograph of a moving object.

That is not an argument for ignoring quality. It is an argument for treating quality as a threshold rather than a ranking. Run a two-week test, confirm each candidate clears the bar for your actual work, then stop measuring.

I would spend the rest of the evaluation window on the admin console, because admin architecture changes slowly and it is the part you can write into a contract. A model benchmark is not a contractual term. A retention setting is.

Four dimensions, three enterprise plans Dark blue is the strongest position of the three. Oxblood marks a gap a buyer has to design around. ChatGPT Enterprise Claude Enterprise Gemini Enterprise Identity and roles Own console Own console Cloud IAM reuse Data residency 10 regions at rest US only, 1.1x Cloud regions Audit logging Compliance API 180 days, no content Reads off by default Connector control Apps off by default URL allowlists 30 plus sources No column is strongest on all four. The right answer depends on which row your regulator reads first. Sources: vendor documentation opened in August 2026 and listed in the references below.
Read this as a shortlist filter, not a scoreboard. A row that is oxblood for you may be irrelevant to a company with no European entity and no data access audit requirement.

Identity, roles and where the admin console lives

Start here, because it is the cheapest thing to verify and the most expensive thing to get wrong. Every one of the three ships the basics.

SSO and SCIM are universal, the defaults are not

Anthropic lists SSO with domain capture, SCIM provisioning, role-based access control, usage analytics and spend controls on the Claude Enterprise plan. It also states that audit logs, OpenTelemetry monitoring and data retention controls are Enterprise-only features, not Team features.

ChatGPT Enterprise carries domain verification, SAML SSO, SCIM, IP allowlists and role-based access control. The default that matters more than any of those: on Enterprise, apps and connectors start disabled, and an admin enables them one at a time. On the Business plan they start on.

Gemini Enterprise does not build a separate identity plane. It uses Google Cloud IAM, with Workforce Identity Federation, Google Identity and Workload Identity Federation as the supported authentication paths.

Where each vendor puts the control plane

That last difference is the real fork in the road. Two of these products give you a new console with a new permission vocabulary. One gives you a surface your cloud team already administers.

Reuse is not automatically an advantage. Google's own security overview warns that incorrect changes to workforce pool attribute mappings risk enabling user impersonation, which can lead to unauthorized document access. A powerful control plane is also a large blast radius.

Spend controls are the underrated line in this table. Claude Enterprise exposes per-user and per-organisation limits, which is what makes a usage-based plan safe to hand to 800 people. If you are budgeting for one of these, the forecasting problem is covered separately in the piece on tools that actually predict AI spend.

Identity and administrative controls, enterprise tiers
ControlChatGPT EnterpriseClaude EnterpriseGemini Enterprise
SAML SSOYes, with domain verification.Yes, with domain capture.Through Google Identity or Workforce Identity Federation.
SCIM provisioningYes.Yes, plus JIT provisioning.Handled by the identity provider mapping.
Role-based accessYes, including per-app roles.Yes.Cloud IAM roles and conditions.
Control planeDedicated workspace console.Dedicated organisation settings.Google Cloud console and IAM.
Spend limitsNot published.Per-user and per-organisation.Cloud billing budgets and quotas.

Compiled from vendor documentation opened in August 2026. "Not published" means the vendor does not state it on a public page, not that the capability is absent. Ask for it in writing during procurement.

Data handling: who trains, who stores, and where inference runs

All three contractually exclude enterprise content from model training. That is the answer to the question every board asks, and it is the least interesting part of the topic.

The interesting part is what happens on the plans your employees are already using without asking. Anthropic's August 2025 consumer terms update applies to Claude Free, Pro and Max, and explicitly excludes Claude for Work, Government, Education and API use. Users who allow training move from a 30-day retention window to a five-year one.

So the governance risk on day one is not your enterprise tenant. It is the personal accounts already holding your contracts, and the shadow tooling around them. That is the same rationalisation problem described in the analysis of 291-app software estates, arriving through a new door.

Residency is the widest single gap

OpenAI expanded at-rest data residency in November 2025. It covers ChatGPT Enterprise, ChatGPT Edu and the API across Europe, the UK, the US, Canada, Japan, South Korea, Singapore, India, Australia and the UAE. For Enterprise and Edu the setting applies only to new workspaces, which is a migration problem rather than a switch.

Read the fine print on inference separately from storage. Computerworld reported at the time of that expansion that model processing still ran on US infrastructure regardless of storage location. HFS Research analyst Akshat Tyagi put at-rest residency at 70 to 80 percent of the compliance friction, and called the remainder a grey area for defence and government buyers.

Anthropic's first-party answer is narrower and more explicit. US-only inference is available on usage-based Enterprise plans, billed at 1.1x standard rates for Opus 4.6, Sonnet 4.6 and later models. There is no European equivalent on the first-party plan, and the setting governs inference rather than storage. Anthropic also states plainly that it does not cover connected services, which process data on their own infrastructure.

Google inherits the widest set of controls and publishes the exclusions. Gemini Enterprise supports data residency, customer-managed encryption keys, VPC Service Controls and Access Transparency. The exclusions are named: CMEK and Access Transparency are unsupported in the global region and do not apply when Grounding with Google Search is on. Google also documents that it deletes user-requested data within 60 days.

Data handling on the enterprise tiers, as documented in August 2026
QuestionChatGPT EnterpriseClaude EnterpriseGemini Enterprise
Trained on by defaultNo.No.No.
At-rest residency10 regions, new workspaces only.Not offered first party.Google Cloud residency regions.
Inference location controlSeparate opt-in, narrower than storage.US-only inference at 1.1x rates.Follows the configured region.
Customer-managed keysNot published on the trust portal.Available to eligible organisations.CMEK, with named region exclusions.
Named certificationsSOC 2 Type 2, ISO 27001, ISO 42001, PCI DSS, FedRAMP 20x.SOC 2 Type I and II, ISO 27001, ISO 42001, HIPAA BAA.SOC 1, 2 and 3, ISO 27001, HIPAA, FedRAMP, BSI C5.

Certification lists are what each vendor publishes, not an equivalence claim. Scope statements differ, and a certification covering a company is not the same as one covering the specific product you are buying. Ask for the scope section of the report.

Audit logging is where the three diverge most

This is the section that should decide the shortlist in any regulated business, and it is the section vendor comparison pages skip.

Claude Enterprise: 180 days, identifiers rather than content

Anthropic documents 25 audit event types. They cover sign-ins, sign-outs, invitations, user deletion, project creation and deletion, document additions to project knowledge, conversation lifecycle, file uploads, SSO configuration changes and data exports. Exports cover the past 180 days and arrive by email as a link that expires in 24 hours.

The limitation is stated in the same document, and it is the one to plan around. Titles and content of chats and projects are not exported, only their identifiers. If you need the content, that is the Compliance API, which is a separate entitlement enabled in organisation settings. Organisations using customer-managed keys cannot use the export button at all and must go through the API.

ChatGPT Enterprise: a compliance platform with a partner ecosystem

OpenAI's Compliance API records time-stamped interactions including conversations, uploaded files, workspace GPT configuration and metadata, memories, and workspace users. It was announced in July 2024 alongside integrations with eDiscovery and data loss prevention vendors.

The practical advantage is not the log format. It is that Microsoft Purview, Palo Alto Networks and Sumo Logic all ship documented connectors into it, so the data lands in a tool your security team already runs. Content is in scope by default rather than behind a second entitlement.

Gemini Enterprise: the best plumbing, half of it switched off

Gemini Enterprise writes into Cloud Audit Logs, which is the most mature logging system of the three by a wide margin. Admin Activity logs record operations such as CreateAssistant, UpdateDataStore and DeleteEngine, and they cannot be disabled.

Data Access logs are the other half. They record the reads: Search, CompleteQuery, GetDocument. Google states that except for BigQuery, Data Access audit logs are disabled by default because they can generate large volumes of data.

That is a defensible engineering decision and a trap for a buyer who assumes logging is on. If nobody enables Data Access logging during rollout, the question "which employee searched the acquisition folder in March" has no answer, and the gap is silent.

What each audit log actually captures out of the box Dark blue is captured by default. Light blue needs a separate entitlement or configuration. Oxblood is not captured. Sign-ins Admin actions Chat content File uploads Reads and searches ChatGPT Yes Yes Yes Yes Via API Claude Yes Yes Not in export Yes Via API Gemini Yes Always on Config Config Off by default Claude exports 180 days of events. Google keeps Admin Activity logs permanently on and Data Access logs off unless enabled. Sources: Anthropic Help Center, Google Cloud audit logging documentation, SecurityWeek on the OpenAI Compliance API.
The right-hand column is the one to check before signing. It is the column that answers "who looked at what", and it is the column two of the three make you configure.

Connectors are a permissions problem, not a feature count

Every vendor page counts connectors. Gemini Enterprise lists roughly 30 third-party sources, from Confluence and Jira to Salesforce, ServiceNow, SharePoint, Workday and Zendesk, plus direct access to BigQuery, Drive, Gmail and the rest of Google's own estate. ChatGPT ships a large app directory. Claude connects through remote MCP servers and a public directory.

The count tells you almost nothing. The question is what an admin can prevent, and here the three are genuinely different products.

What a connector does not inherit

Anthropic ships the most granular control I have seen from any of the three. Claude Code administrators can deploy a managed-mcp.json file that defines the only servers that will load, or run an approved catalogue using allowedMcpServers with allowManagedMcpServersOnly. Servers match by URL pattern, exact command, or name.

What makes it credible is the warning in the same document. Anthropic states that a name entry is not a security control, because the name is the label a user assigns, so a user can call any server "github". A vendor that documents how its own control can be defeated is telling you something useful.

Anthropic is equally direct that it reviews directory listings against criteria but does not security-audit or manage any MCP server. Google says the parallel thing about its own perimeter: VPC Service Controls govern Google Cloud services and do not inherently block or secure traffic to external, non-Google endpoints. The protocol layer underneath all this is covered in the piece on MCP as an interoperability standard.

Both statements point at the same hole. Once a connector authenticates, your controls end and the third party's begin, and no amount of tenant configuration changes that. Treat every connector as a subprocessor and diligence it like one.

Retention settings are a vendor promise. A court order outranks a vendor promise, and one of these three has already been tested in public.

In May 2025 a federal magistrate directed OpenAI to preserve and segregate output log data that would otherwise have been deleted. That obligation was released going forward in October 2025. In November 2025 Magistrate Judge Ona Wang ordered production of 20 million ChatGPT conversation logs, which OpenAI characterised as roughly 0.5 percent of its logs. District Judge Sidney Stein affirmed the order on 5 January 2026.

Nothing about that sequence is specific to OpenAI. Any vendor holding conversation logs is subject to discovery in litigation it is party to, and your retention configuration does not travel with the data once a court is involved. OpenAI is simply the one whose turn came first.

The practical response is contractual rather than technical. Ask for notice obligations, ask what happens to your tenant's data under a preservation order, and get the answer in the agreement. The clauses worth insisting on are set out in the CFO's list of AI contract terms, and the remedy side is covered in the piece on liability caps for agent failures.

A retention setting, tested against a court The ChatGPT output log dispute, May 2025 to January 2026 May 2025 Court orders logs preserved Oct 2025 Preservation released going forward Nov 2025 20 million logs ordered produced Jan 2026 District judge affirms the order The same exposure exists at every vendor holding conversation logs. Only the litigation calendar differs.
Eight months separate a deletion policy working as documented from 20 million conversations heading to opposing counsel. Plan the contract for the second state.

Where this comparison is weakest

Three things you should hold against everything above.

The source base is not symmetric

Anthropic and Google publish their admin documentation openly, and every claim about those two here traces to a page opened during research. OpenAI's enterprise privacy pages and help centre refused automated retrieval, so the ChatGPT column leans on the public trust portal and on secondary reporting from Computerworld and SecurityWeek.

That asymmetry is itself a small procurement signal, because documentation you cannot read is documentation your security team cannot review before a call. It also means the ChatGPT column here is thinner than the other two, and you should treat it as a starting point rather than a finding.

Two further caveats. Feature parity in this category moves in weeks, so verify every row against the vendor's current page before you rely on it. And the prices are not comparable. Google publishes list pricing, at $30 per seat per month for Gemini Enterprise and $21 for Gemini Business at the October 2025 launch. Neither OpenAI nor Anthropic publishes an enterprise rate card. Any per-seat figure you read for those two is deal data, not a published price. How usage-based terms change that maths is covered in the analysis of Anthropic's shift away from seat pricing.

A scoring sheet you can take into the evaluation

Weights are the argument, so change them rather than adopting mine. The point is to force the conversation into rows a vendor has to answer in writing.

Suggested evaluation weights for an enterprise AI assistant
CriterionWeightWhat a passing answer looks like
Answer quality on your own corpus15%Clears a threshold you set in advance. Not ranked.
Audit log completeness and retention25%Named event types, a stated window, and content included or a documented path to it.
Residency and inference location20%Storage and processing answered separately, in writing.
Connector governance20%Default deny, admin allowlisting, and a named review process.
Identity, roles and spend limits10%SCIM, RBAC, and a hard spend ceiling per user.
Contract terms on preservation and notice10%A written answer on what happens under a court order.

These weights are my judgement, not measured outcomes. They deliberately push quality below a quarter of the total, because quality converges and governance does not. If your deployment is customer-facing rather than internal, raise the first row.

Frequently asked questions

What is the difference between ChatGPT Enterprise and Claude Enterprise?

The differences that survive procurement are administrative. ChatGPT Enterprise offers at-rest data residency across 10 regions and a Compliance API that logs conversation content, with connectors into Purview and other security tools. Claude Enterprise exports 180 days of audit events but excludes chat titles and content from that export, offers US-only inference at 1.1x rates, and ships the most granular connector allowlisting of the three.

Does Claude Enterprise have EU data residency?

Not on the first-party plan. Anthropic documents US-only inference for usage-based Enterprise organisations, billed at 1.1x standard rates for Opus 4.6, Sonnet 4.6 and later models, and does not publish a European equivalent. Buyers who need EU processing generally deploy Claude models through Amazon Bedrock or Google Cloud Vertex AI in a European region instead, which is a different product with a different admin console.

Does Gemini Enterprise log what users search for?

Only if you turn it on. Gemini Enterprise writes into Google Cloud Audit Logs, where Admin Activity logs are always written and cannot be disabled. The read operations, including Search, CompleteQuery and GetDocument, land in Data Access audit logs, and Google states these are disabled by default on every service except BigQuery because of the volume they generate. Enable them during rollout, not after an incident.

How much does Gemini Enterprise cost per user?

Google published list pricing at launch on 9 October 2025: Gemini Enterprise from $30 per seat per month, and Gemini Business from $21 per seat per month. Compute consumption beyond your subscription quotas bills separately to the linked Google Cloud account, so the seat price is a floor rather than a total. Neither OpenAI nor Anthropic publishes an equivalent enterprise rate card.

Can admins control which connectors employees use?

Yes, and the mechanisms differ sharply. ChatGPT Enterprise starts with apps disabled and admins enable them individually with per-app roles. Claude Code administrators can deploy a managed configuration file that defines the only MCP servers permitted, or enforce an allowlist matched on URL and command. Gemini Enterprise governs its own connectors through Cloud IAM, but VPC Service Controls do not extend to non-Google endpoints.

Which enterprise AI platform is best for a regulated industry?

It depends on which obligation binds first. If in-region data storage is the binding constraint, ChatGPT Enterprise and Gemini Enterprise both offer residency and Claude does not, first party. If complete read logging is the constraint, Google has the strongest system but ships it off by default. If connector governance is the constraint, Anthropic's allowlisting is the most granular published control of the three.

Where to start this week

Skip the bake-off for a moment and run two checks that cost nothing.

First, ask each vendor for the audit log event list, the retention window, and a plain answer on whether message content is included. Three sentences in an email. The vendor who answers with a link to documentation rather than a call is the one whose controls are real, and the exercise takes an afternoon.

Second, pull the list of AI tools already authenticated against your identity provider and mark which ones are personal accounts. That inventory decides more about your actual exposure than the platform you eventually pick, and it usually finds something. The failure patterns that follow are catalogued in the breakdown of how agent pilots fail.

Related on buying AI at work

If you are drafting the paper rather than the shortlist, start with the contract clauses a CFO should insist on. Then read what it takes to forecast AI spend before you commit to a seat count.

References

  1. Anthropic Help Center, Access audit logs, accessed August 2026. Used for the 180-day window, the event list and the content exclusion.
  2. Anthropic Help Center, Enable US-only inference for your organization, accessed August 2026. Used for the 1.1x rate and the connector caveat.
  3. Anthropic, Updates to Consumer Terms and Privacy Policy, August 2025. Used for the consumer and commercial split and the retention windows.
  4. Claude Code documentation, Control MCP server access for your organization, accessed August 2026. Used for the allowlist mechanics and the server name warning.
  5. Google Cloud, Cloud Audit Logs overview, accessed August 2026. Used for the default-off status of Data Access logs.
  6. Google Cloud, Compliance certifications and security controls, Gemini Enterprise, accessed August 2026. Used for certifications and the global region exclusions.
  7. Computerworld, OpenAI expands data residency for enterprise customers, 26 November 2025. Used for the region list and the inference caveat.
  8. SecurityWeek, OpenAI rolls out Compliance API and integrations for ChatGPT Enterprise, 18 July 2024. Used for what the Compliance API records.

The weakest part of this source base is that OpenAI's own enterprise privacy and help pages returned errors to automated retrieval. So the ChatGPT column rests on the public trust portal and secondary reporting, while the other two rest on primary vendor documentation. Court filing details in the log preservation section reach this post through legal trade coverage rather than the docket itself.

AV
Aryan Vatsa
Contributing Analyst, Zan Digital. Founding product designer, writing here on how AI products are priced, packaged and measured against each other.

Related reading