Which AI tools are safe for work? Every tool below gets a tier verdict — Approved, Limited, or Prohibited — plus the facts a compliance or IT lead actually needs: does it train on your data, what does it retain, what can an admin control, will the vendor sign a BAA, and what certifications it can show.
Verdicts are our generic recommendation for a 50–500 person company that handles client or regulated data, based on publicly documented vendor terms assessed 29 July 2026. Each tool page lists the vendor documents behind every claim and links them. Click any tool for the full breakdown — including HIPAA/BAA status and healthcare, financial-services, and legal risk notes.
| Tool | Tier verdict | Trains on your data? | Will sign a BAA? | Certifications |
|---|---|---|---|---|
| ChatGPT (free) OpenAI · General assistant |
Limited assessed 29 July 2026 |
Depends on plan | No | — |
| ChatGPT Plus OpenAI · General assistant |
Limited assessed 29 July 2026 |
Depends on plan | No | — |
| ChatGPT Enterprise OpenAI · General assistant |
Approved assessed 29 July 2026 |
No | Enterprise- or plan-dependent | SOC 2 Type 2 |
| Claude (claude.ai free) Anthropic · General assistant |
Limited assessed 29 July 2026 |
Depends on plan | No | — |
| Claude for Work / API Anthropic · General assistant |
Approved assessed 29 July 2026 |
No | Enterprise- or plan-dependent | — |
| Microsoft Copilot for M365 Microsoft · Productivity suite AI |
Approved assessed 29 July 2026 |
No | Yes | Microsoft’s Copilot privacy documentation references ISO 27001, HIPAA and the ISO 42001 AI management standard for the service |
| GitHub Copilot GitHub (Microsoft) · Code assistant |
Limited assessed 29 July 2026 |
Depends on plan | N/A — not a PHI system | — |
| Google Gemini (personal) Google · General assistant |
Prohibited assessed 29 July 2026 |
Yes | No | — |
| Google Gemini for Workspace Google · Productivity suite AI |
Approved assessed 29 July 2026 |
No | Yes | — |
| Grammarly (free) Grammarly (Superhuman Platform Inc.) · Writing assistant |
Limited assessed 29 July 2026 |
Depends on plan | No | — |
| Grammarly Business Grammarly (Superhuman Platform Inc.) · Writing assistant |
Limited assessed 29 July 2026 |
Not documented | Not publicly documented | — |
| Otter.ai Otter.ai · Meeting transcription |
Limited assessed 29 July 2026 |
Yes | Not publicly documented | — |
| Notion AI Notion · Workspace AI |
Approved assessed 29 July 2026 |
No | Enterprise- or plan-dependent | Notion states Notion AI is in scope of its SOC 2 Type 2 report and ISO 27001 certification |
| Midjourney Midjourney · Image generation |
Limited assessed 29 July 2026 |
Yes | No | — |
| DALL·E (OpenAI Images) OpenAI · Image generation |
Limited assessed 29 July 2026 |
Depends on plan | Enterprise- or plan-dependent | — |
| Perplexity Perplexity AI · AI search |
Limited assessed 29 July 2026 |
Depends on plan | Not publicly documented | SOC 2 Type II, stated on Perplexity’s Enterprise page |
| Canva AI / Magic Write Canva · Design & content |
Limited assessed 29 July 2026 |
Depends on plan | Not publicly documented | — |
| HubSpot AI (Breeze) HubSpot · CRM / marketing AI |
Limited assessed 29 July 2026 |
Not documented | Not publicly documented | HubSpot’s DPA states its hosting sub-processors maintain independently validated security programmes including SOC 2 and ISO 27001, and that HubSpot’s systems are audited annually as part of SOC 2 compliance |
| Salesforce Einstein Salesforce · CRM / platform AI |
Approved assessed 29 July 2026 |
No | Not publicly documented | — |
| DeepSeek DeepSeek (Hangzhou) · General assistant |
Prohibited assessed 29 July 2026 |
Yes | No | — |
| Meta AI Meta · General assistant |
Prohibited assessed 29 July 2026 |
Not documented | No | — |
| Zoom AI Companion Zoom · Meeting AI |
Limited assessed 29 July 2026 |
No | Enterprise- or plan-dependent | — |
| Slack AI Slack (Salesforce) · Workspace AI |
Approved assessed 29 July 2026 |
No | Enterprise- or plan-dependent | — |
| Adobe Firefly Adobe · Image generation |
Limited assessed 29 July 2026 |
No | Not publicly documented | — |
| Fireflies.ai Fireflies.ai · Meeting transcription |
Limited assessed 29 July 2026 |
No | Enterprise- or plan-dependent | Fireflies states it is certified for SOC 2 Type II and GDPR compliance on its security page |
| Grok (xAI) xAI · General assistant |
Limited assessed 29 July 2026 |
Depends on plan | Enterprise- or plan-dependent | — |
Sorting by the BAA column instead? See the HIPAA and BAA comparison →
This is the generic list. A hospital, a hedge fund, and a marketing agency should not classify these tools identically. The $79 policy kit produces a tier list tailored to your industry, size, and data — plus the acceptable use policy, acknowledgment form, and manager FAQ that make it enforceable.
And every verdict is dated. Vendor data policies change quietly, so each verdict here carries the date we last read the vendor’s documents. The $149/mo Monitor plan re-checks the landscape monthly, alerts you when a tool’s data policy changes, and regenerates your kit — so your tier list is never a year out of date.
We never list a certification we can’t find in the vendor’s published documentation. Where something isn’t publicly documented — or where the vendor’s page would not load in a form we could read — the tool page says exactly that instead of guessing.
Already have an AI policy? See how many of these tools it actually covers: run the free policy gap check →. Not sure where your company stands overall? Take the 2-minute exposure scorer →.
A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies all of these tools for your company, industry, and data. Generated in about 10 minutes.
Generate my policy kit →We re-check vendor terms monthly, alert you when any tool’s data policy changes, and regenerate your kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.
See Monitor plan →