Home › Intelligence › Brief
BREACH BRIEF🟢 Low Advisory

OpenAI Releases Guidance on 7 Default‑Off ChatGPT Settings to Enhance Privacy and Security

OpenAI’s ChatGPT ships with several privacy‑related options disabled. A ZDNet Security guide details seven settings—appearance, model choice, ad controls, memory/history, etc.—that organizations should enable to reduce data exposure and align AI usage with third‑party risk policies.

LiveThreat™ Intelligence · 📅 March 21, 2026· 📰 zdnet.com
🟢
Severity
Low
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zdnet.com

OpenAI Releases Guidance on 7 Default‑Off ChatGPT Settings to Enhance Privacy and Security

What Happened — OpenAI’s ChatGPT interface ships with several privacy‑ and usability‑related settings disabled by default. A ZDNet Security article (Mar 21 2026) outlines seven of these options—appearance tweaks, model selection, ad controls, memory/history toggles, and more—explaining how to enable them for a more secure, personalized experience.

Why It Matters for TPRM —

  • Default‑off privacy controls can expose conversational data to unnecessary retention or profiling.
  • Unchecked model selection may lead to higher cost or inadvertent use of less‑secure versions.
  • Enabling ad‑control and history settings reduces attack surface for data leakage and improves compliance with data‑handling policies.

Who Is Affected — SaaS providers, enterprise users of generative AI, and any third‑party risk program that relies on OpenAI’s APIs (technology, finance, healthcare, education, etc.).

Recommended Actions —

  • Review your organization’s OpenAI account settings; enable memory/history limits and ad‑personalization controls.
  • Document the chosen model version and ensure it aligns with your security and cost policies.
  • Incorporate these configuration checks into your vendor risk assessment checklist for AI services.

Technical Notes — The settings are accessed via the “Personalization” or “Settings” panels in the web or mobile UI. No CVEs are involved; the risk is operational—excessive data retention, inadvertent model downgrade, and exposure to targeted ads. Source: ZDNet Security article

📰 Original Source
https://www.zdnet.com/article/chatgpt-settings-for-pro-users/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →