The Free Version Stopped Being the Trail Version

OpenAI made free ChatGPT genuinely capable overnight — which means the budget that quietly kept AI in a small, careful circle at your company just disappeared. Access is now free; permission still isn’t.

Originally published as The Decision Layer, Issue 11 (week of August 3–9, 2026). References to days of the week and “this week” reflect that period.

HEADLINE STORY

On Thursday, OpenAI moved every free ChatGPT account onto a current-generation model. Starting this week those accounts also get text conversations with no message cap, and a button that makes the model work longer on a hard question.

Be careful with the word unlimited, because it is already being repeated wrong. It applies to text. File uploads, images, and voice stay capped. It is also a staged rollout, so what your people see this week and next will differ.

The free version was never useless. What it was, for a casual business user, was rationed. Somebody at your company tried it, ran into the message limit on a weaker model, and formed an opinion. That opinion was fair about what they were handed. It is out of date now.

Here’s what matters. Everyone on your payroll without a company seat has a capable tool this week and nobody sent them a memo. Your counter staff, your credit manager, the inside salesperson drafting follow-up letters. What they are using is a personal account.

The line that matters is not free versus paid. Read OpenAI’s own documentation and you find that on personal plans, including the paid ones, conversations are used to help improve its models by default, and shutting that off is a toggle inside each individual user’s settings. On the business and enterprise plans the default runs the other way and the company administers the workspace. The real distinction is personal account versus company-controlled workspace, and a subscription your bookkeeper bought on her own card sits on the wrong side of it.

That matters for a bigger reason than whether a vendor trains on your information. It decides where your company’s knowledge ends up living, who owns the account holding it, and what happens to it when that person goes to work for somebody else.

So the free upgrade did not remove a decision. It moved it. The question is no longer who gets access. It is who controls it.

WHAT ELSE MATTERED

Voice stopped being proof of identity

Bloomberg reported Wednesday that Point72, Citadel, Two Sigma, and Millennium were targeted in a wave of voice-phishing attempts. No malware and no emailed link. Callers impersonated trusted colleagues, and at one firm the help desk itself, working to get employees to hand over credentials. Two Sigma said it blocked the attempt, and Point72 told investors it found no evidence client data was taken. Voice cloning is what makes this cheap now, since a few seconds of audio off a podcast or a conference panel is enough to build something convincing. Tell whoever answers your phone, and whoever can reset a password, that a familiar voice is not proof of who is calling, and give them one verification step they are never allowed to skip.

A compliance department does not solve this

PwC surveyed 1,004 executives, director level or above, at US financial services firms with at least $500 million in revenue. More than half said employees using their own AI tools instead of company-approved ones happens to a moderate extent, and 35% said it happens to a significant extent. Ninety percent said that unapproved use created regulatory risk. Those numbers do not tell you how much of this is happening at your company. What they tell you is that headcount, an IT department, and a compliance function do not make it go away. The only way to know your own number is to ask.

THE PATTERN BEHIND THE WEEK

Two things happened this week that belong together. The cost of basic text access went to zero. And companies with far more resources than yours reported they cannot keep unapproved AI out of their own buildings.

Price was doing more governance work than anyone assigned it. A seat you had to buy kept the group small and deliberate, usually the people who would be careful with it. That was never a policy. It was a budget acting like one.

This week the budget stopped doing that work and nothing replaced it. That is the argument for writing something down, and it is a better argument than the one people usually make. Not because the tools are dangerous. Because the thing that used to keep the circle small is gone.

Access is now free. Permission still isn’t.

This does not call for a policy manual. It calls for one page a person can read in two minutes and repeat from memory.

WHAT TO DO NOW

  1. Take a fifteen-minute pulse check. Ask one person in sales, one in operations, and one in credit which AI tools they use for work and what they put into them. You are not building an inventory. You are finding out whether the answer is none, some, or considerably more than you assumed.
  2. Draw two lines instead of one. The first is what never goes into a personal account: customer-specific pricing, credit applications, employee records, anything under a nondisclosure agreement. The second is the proprietary company information your people can work with inside an approved company workspace under your rules — customer pricing, quote analysis, margin work, contract language. Those are among the best things this technology does for a dealer, and you do not want to ban them by accident. Personal and financial records are a separate question that deserves its own answer, not an automatic yes.
  3. Put the people doing that work on a company-controlled workspace. Not everyone — the ones using these tools on proprietary company information, which in most yards means parts of sales, credit, contracts, and personnel. There the training default runs your way, you administer who belongs, and you can cut off access the day somebody leaves. That is a far smaller purchase than licensing the building, and it covers where your exposure sits.

WHAT I’M WATCHING

  • Washington’s testing framework landed quietly. The voluntary cybersecurity testing program I flagged as overdue last issue was finalized Monday, and four labs met at the White House on Tuesday. It is still voluntary, and the metrics and reporting rules have not been published. Worth tracking because voluntary frameworks have a way of becoming the standard your insurance carrier asks about.
  • A lab hit the brakes on itself. OpenAI said Friday it had paused work on an unreleased model after internal testing suggested it could not rule out the top tier of its own cybersecurity risk framework. Nothing on your desk changed. It is the first time a company under this much pressure to ship slowed itself down in public before anyone made it.

ONE QUESTION WORTH ASKING

If one of your salespeople left on Friday for a competitor, what would go with them that they typed into a chat window you never knew about?

The answer should be: nothing the company does not control.

Similar Posts

Leave a Reply