Most of the comparisons you read on the internet ranks them by which AI tool writes the nice paragraph. If you are looking to choose AI for your team, you are not concerned about the nice paragraphs it writes probably you are more worried about how much it costs for 100 to 200 users in your team. Whether your company data leaves the country and what happens when your auditors asks where the prompts your users are typing are shared.
This guide answers those questions. Every price and policy below was verified against vendor documentation on 1 September 2026, with sources listed at the end.
If a vendor doesn’t publish or publicly revealed certain information we have quoted the same instead of guessing because in enterprise procurement what a vendor declines to publish is often most useful signal you shouldn’t miss.
Why does it matter? Not long ago everyone picked tools based on the kind of job the tool did for them. In 2026 we have reached a place all the tools listed in the article be it Claude, Gemini, ChatGPT, or Grok all of them can now write, reason, code and even search competently. Only differences that matter the most now are commercial and architectural – be it price, data handling, and how well the tool fits on the tech stack your orgnisation is already owing. That last point is why most AI projects fail on their data foundations rather than on model choice.
The 30-second answer
| Your situation | Pick | Why |
| You run on Microsoft 365 | Microsoft 365 Copilot | It inherits your existing permissions rather than creating a second permission model to govern |
| You run on Google Workspace | Gemini | Bundled into your Workspace licence since 2025 – you may already be paying for it |
| Engineering is the main use case | Claude | A 1M-token context window, matched here only by Gemini, plus the most mature agentic coding tooling |
| You want one assistant for a mixed, non-Microsoft org | ChatGPT Business | Broadest feature surface, cleanest admin story outside the Microsoft stack |
| The job is research with citations | Perplexity | Built around sourcing; routes across several frontier models rather than betting on one |
| You need real-time signal from X | Grok | Direct access to the X firehose, which no competitor has |
If you are in a regulated industry, skip to the data and compliance section before you get attached to any of these. It changes the answer more often than people expect.
What each one actually costs
Published list prices as at 1 September 2026, in USD per user per month. Annual pricing where both are offered.
| Product | Entry | Main business tier | Enterprise | Watch out for |
| ChatGPT | Plus $20 (individual) | Business $20 annual / $25 monthly, 2-seat minimum | Custom pricing, annual billing only | Premium seats at $100 annual / $125 monthly for 5× usage |
| Gemini | Workspace Business Starter $7 annual / $8.40 monthly | Business Standard $14 / $16.80 · Business Plus $22 / $26.40 | Contact sales | AI is bundled into the Workspace SKU rather than sold as a separate Gemini add-on – but Starter gets limited access, and a paid “AI Expanded Access” add-on exists for higher limits |
| Claude | Pro $17 annual / $20 monthly | Team $20 annual / $25 monthly, 2–150 people | $20 per seat plus usage at API rates, 20-seat minimum, annual | Enterprise is the only one here with a usage component on top of the seat |
| Microsoft 365 Copilot | Copilot Chat, included with eligible M365 subscriptions | M365 Copilot Business standalone $18 after a 15% promo running to 31 Dec 2026, 1–300 licences | $30 annual / $31.50 monthly, annual commitment | Requires a qualifying M365 subscription the $30 is on top |
| Perplexity | Pro $20 | Enterprise Pro $40 per seat, or $400 per seat annually | Enterprise Max $325 per seat / $3,250 annually | The gap between Enterprise Pro and Enterprise Max is eight times |
| Grok | SuperGrok $30 | Grok Business – xAI now directs buyers to sales rather than publishing a seat price | Custom pricing | SSO and directory sync are Enterprise-only, Business does not include them |
Three things this table hides, which matter more than the numbers in it.
Copilot requires a prerequisite licence. The $30 sticker price is an add-on cost on top of a qualifying Microsoft 365 subscription, so budgeting based on the headline figure alone will overlook the expense of the underlying seat. Since 1 July 2026, Microsoft has offered unified SKUs – Business Standard with Copilot for $23.50 and Business Premium with Copilot for $32 – which frequently work out cheaper than separate line items. Note the current $21 Business Basic bundle available until the end of 2026, and a 15% discount for three-year commitments exceeding 300 users. This larger discount expires on 30 September 2026, making it worth pricing renewals this month. Compare every deployment path before signing; the commercial variance is often significant.
Claude Enterprise bills usage on top of seats. At $20 per seat plus API-rate usage, a heavy engineering team can cost several times a light one on identical seat counts. Model your actual token consumption before committing. Every other vendor here is flat-rate per seat.
Gemini may already be paid for. Google folded the Gemini add-on into Workspace SKUs and raised base prices in 2025. If you renewed after that, AI is in your licence. A surprising number of Workspace organisations are buying a second assistant they did not need. Check which tier you are on first – Business Starter gets limited Gemini access, and heavier use may still need the paid AI Expanded Access add-on.
Data, security and compliance
This is where enterprise deals are won and lost, and it is the section most comparison articles skip.
| Trains on your data | Retention | Data residency | SSO | SCIM | Audit logs | |
| ChatGPT Business | No, by default | Admin-configurable; deleted conversations purged within 30 days | Enterprise tier only | Yes | Enterprise only | Enterprise only |
| ChatGPT Enterprise | No, by default | Customer-controlled | US, EU, UK, Japan, Canada, Korea, Singapore, India, Australia, UAE | Yes | Yes | Yes, via Compliance API |
| Gemini / Workspace | Not without your permission or instruction | 90 days to indefinite, admin-set; Gemini app up to 36 months | US, Europe, or no preference | Yes | – | Via Vault |
| Claude Enterprise | No, by default opt-in only | API inputs and outputs deleted within 30 days | US and Asia-Pacific via Bedrock, Vertex or Microsoft Foundry; Canada and Europe listed as coming in 2026 – see the caveat below | Yes, with domain capture | Yes, with JIT provisioning | Yes, plus Compliance API |
| M365 Copilot | No foundation-model training on tenant data | Governed by Purview retention policies; the Anthropic preview path adds Anthropic-side retention | EU Data Boundary service – with a significant exception, below | Entra ID | Yes | Via Purview |
| Perplexity Enterprise | No – enterprise data never used for training | Uploaded files auto-delete after 7 days by default; session retention admin-configurable | Not published | Yes, with MFA | Yes | Yes |
| Grok Business | No, on business, enterprise or API data | 30 days by default on API; zero-data-retention available; custom retention on Business and Enterprise | Not published | Enterprise tier only | Enterprise tier only | Enterprise tier |
One caveat on Anthropic residency, because it is the kind of detail that derails a procurement cycle: their regional-compliance documentation is internally inconsistent. While the availability table marks the US and Asia-Pacific as live-listing Canada and Europe as “coming 2026”-the FAQ on that same page describes Europe as currently available. If European residency is a prerequisite for your organisation, secure a written confirmation from the vendor rather than relying on the public website.
A second observation on Grok: governance controls are tier-gated. Identity features-including organisations, custom SSO, and directory sync-are restricted to the Enterprise tier. The $30 self-serve Business tier provides consolidated billing and team analytics but lacks these critical identity controls. Most 2026 comparisons overlook this distinction.
Certifications. OpenAI, Google and Anthropic have reached the same baseline, holding SOC 2 Type 2, ISO 27001 and ISO 42001 and if those standards are new territory for your team, our guide to what SOC 2 and ISO 27001 actually require covers what an audit involves. Google additionally holds FedRAMP High, while OpenAI lists PCI DSS and FedRAMP 20x. When assessing HIPAA, the scope is the differentiator: Google and Anthropic provide BAAs for their assistant products, whereas the OpenAI BAA is scoped to the API Platform rather than ChatGPT generally a distinction that matters if you are working through HIPAA compliance obligations. Perplexity and xAI both hold SOC 2 Type 2 but do not publish ISO 27001 or ISO 42001 certifications.
Note that Perplexity and xAI decline to publish specific data-residency commitments. Both vendors gate their full trust documentation behind portals xAI’s explicitly requires an NDA. This is not necessarily a signal of a problem, but it means you cannot pre-qualify them using public documentation; budget extra time for your security review to navigate these requirements.
Three things most 2026 comparisons get wrong
- Copilot is no longer only OpenAI – and that has a compliance consequence.
Microsoft 365 Copilot now runs Anthropic models alongside OpenAI’s, with Anthropic acting as a Microsoft subprocessor. Claude Fable 5 and Claude Mythos 5 are available in Excel and PowerPoint, with Word stated as coming in summer 2026.
Here is the part almost nobody covers: the Anthropic models are excluded from the EU Data Boundary and from Microsoft’s in-country processing commitments. They are disabled by default in the EU, EFTA and the UK, disabled by default for non-federal GCC since 22 July 2026, and unavailable in GCC High, DoD and other sovereign clouds. An admin can enable them tenant-wide or for specific groups. Retention differs too – the Anthropic path carries its own 30-day retention, extendable to two years where a policy violation is suspected.
If your organisation bought Copilot partly on the strength of the EU Data Boundary, that guarantee does not extend to the Anthropic-powered features. Someone should be making that decision deliberately, with a documented rationale – not discovering it during an audit.
- “We don’t train on your data” is table stakes, not a differentiator.
Every vendor in this comparison now commits to not training on business customer data by default. It has stopped being a selling point. The questions that actually separate them are the ones underneath: how long is data retained, can you change that, where does inference physically execute, and can you prove any of it to an auditor?
On those, the spread is wide, and it is still moving. OpenAI announced Private Safety Processing on 19 August 2026, extending zero-data-retention to cover cross-interaction safety monitoring so customer content can remain on customer infrastructure or under customer-held keys – with the rollout and technical white paper due during September. If ZDR is a requirement for you, that is worth a fresh conversation with OpenAI rather than relying on terms you were quoted earlier in the year.
Elsewhere the gaps are structural. ChatGPT gives you SCIM and audit logs only at Enterprise tier. Claude retains Fable 5 and Mythos 5 prompts for 30 days even for organisations with zero-data-retention agreements – those orgs must enable standard retention to use those models at all. OpenAI separates data residency from inference residency, and in-region inference is available only in Europe, the US and the UAE, and only if you have data residency first.
Those are the details that fail a security review. “We don’t train on your data” never does.
- Seat count is the wrong unit for budgeting.
Three of the six have a pricing dimension that does not scale linearly with headcount. Claude Enterprise adds usage-based billing on top of seats. ChatGPT and Claude both sell premium seats at roughly five times the standard price for heavier usage. Copilot requires a base licence underneath. Build the model on expected usage patterns, not seat count, or you will present a number to your CFO that you cannot hold.
The models behind each tool, September 2026
The model landscape moves every few months, so treat this section as the most perishable part of this guide.
| Tool | Current models | Context window |
| ChatGPT | GPT-5.6 family, launched 9 July 2026 – Sol (flagship), Terra (balanced), Luna (cost-efficient) | 272K on Sol, 128K on Terra and Luna, within ChatGPT |
| Gemini | Gemini 3.7 Flash is the generally available lead model; Gemini 3.1 Pro remains in preview, with Gemini 3.5 Pro flagged as coming soon | 1M input, 64K output on 3.1 Pro |
| Claude | Claude Fable 5 as flagship, with Opus 5 (24 July 2026), Sonnet 5 (30 June 2026) and Haiku 4.5 | 1M tokens and 128K output on Fable 5, Opus 5 and Sonnet 5; Haiku 4.5 is 200K |
| M365 Copilot | OpenAI models plus Anthropic’s Fable 5 and Mythos 5 in preview | Varies by underlying model |
| Perplexity | Sonar 2 in-house, plus frontier models from OpenAI, Google, Anthropic and xAI depending on plan tier | Varies by model |
| Grok | Grok 4.6, current flagship; Grok 4.5 still available | 500K tokens; knowledge cutoff February 2026 |
One caveat on context windows: the figures above are what you get inside each vendor’s own assistant. Via cloud platforms the limits can be higher – GPT-5.6 supports a 1M-token window on Amazon Bedrock, for instance. If long context is central to your use case, check the deployment path, not just the model name.
Two observations worth more than the numbers. Anthropic’s flagship is Fable 5, not Opus 5 – Opus 5 is positioned as roughly half the cost at comparable results, which for most business workloads makes it the more sensible default. And Perplexity is not really a model company: it routes across several frontier models, so what you get depends on your plan tier rather than on a single vendor’s roadmap.
How each one is actually positioned
Microsoft 365 Copilot is the default for Microsoft-centric organisations, and the reason is governance rather than capability. It only surfaces data a user already has permission to see, honours sensitivity labels and IRM, and is managed through Purview alongside everything else. If you have spent years building a permissions model in M365, Copilot is the only option that reuses it instead of asking you to build a second one. t is also the route into building agents on Microsoft Copilot, which is where most Microsoft-first organisations get their first real return.
Gemini has the same logic on the Google side. Google is also shipping fastest of the six right now – Gemini 3.5 Transcribe and Transcribe Live reached general availability on 26 August 2026 and Gemini Omni 1.1 Flash on 27 August, with Gemini 3.5 Pro flagged as coming. It has an unusually clean data-residency story – US, Europe or no preference, set at the admin level, with Gemini app data regions reaching general availability on 29 June 2026 for Enterprise Plus and equivalent tiers. If you are on Workspace, check your licence before you buy anything else.
ChatGPT Business and Enterprise offer the broadest capability surface and the widest data-residency list – ten regions at Enterprise tier. The catch is the feature gap between Business and Enterprise: SCIM, audit logs and residency are all Enterprise-only, and Enterprise is custom-priced and annual-billed. If you need those controls, budget for Enterprise from the start rather than planning to upgrade.
Claude is the developer and long-context choice. A 1M-token window handles entire codebases or document sets in a single pass, and the agentic coding tooling is the most mature in this group. If you are weighing how to ground a model on your own data, that decision RAG or fine-tuning usually matters more than which assistant you licence. Enterprise security is thorough – customer-managed encryption keys, US-only inference, IP allowlisting, connector governance. Note the 20-seat minimum, the usage-based billing, and one sharp edge: prompts and outputs for Fable 5 and Mythos 5 are retained for 30 days even for organisations holding zero-data-retention agreements, and ZDR organisations must enable standard retention to use those models at all.
Perplexity is a research tool that happens to have a chat interface. Everything is built around citation and sourcing, which is what you want for competitive analysis, due diligence and market research where the provenance of a claim matters as much as the claim. The Comet browser and the Computer agent product extend it beyond a search box. Weaker on published enterprise compliance detail than the big three.
Grok occupies a genuine niche: real-time access to the X firehose, which nothing else in this comparison can offer. For brand monitoring, crisis detection and sentiment analysis that is a real advantage. Enterprise credentials are better than its reputation suggests – SOC 2 Type 2, GDPR compliance, a HIPAA BAA on request, plus SSO, SCIM, RBAC and audit logs at Enterprise tier. Two gaps to plan around: those identity controls are not in the $30 Business tier, and data residency is not publicly documented. xAI also gates its full trust documentation behind an NDA, so budget extra time for security review.
How to choose without running a six-month evaluation
Work in this order. It eliminates most of the field before you spend time on demos.
- Start with your stack. If you are on M365 or Workspace, your default is Copilot or Gemini respectively. The integration and governance advantage usually beats a capability advantage elsewhere.
- Apply your compliance constraints next. Data residency requirements, sector regulation and certification needs will eliminate options faster than any feature comparison. Do this before demos, not after.
- Model the real cost. Seats, usage, premium tiers, prerequisite licences. Use expected usage, not headcount.
- Then, and only then, pilot on capability – with a real workload and a defined success measure, not a two-week free trial that nobody structures.
Note that the assistant is a separate decision from the platform you build on. If you are also standing up custom AI applications, deploying enterprise AI on Azure AI Foundry is a parallel workstream with its own governance requirements.
Most organisations end up with two: a primary assistant that lives inside their productivity suite, and a specialist for research or engineering. That is a reasonable outcome, not a failure to decide. What is not reasonable is six overlapping tools bought by six different departments, which is the situation we are most often called in to untangle.
Ready to make this decision properly?
Choosing the tool is step one. Deploying it without opening a data-governance gap is step two, and it is the one that takes the expertise.
At Gradient M we help organisations build secure digital workplaces and design the data and AI foundations underneath them – assessing the options against your actual compliance position, modelling the real cost, and running the rollout.
Book a free AI readiness assessment →
Frequently asked questions
Which AI is best for business in 2026?
There is no single answer, and any article that gives you one is selling something. The right choice follows your existing stack: Microsoft 365 organisations should default to Copilot, Google Workspace organisations to Gemini. From there, compliance requirements narrow the field further than any feature comparison will.
Is Microsoft Copilot safe for financial or regulated data?
Copilot does not use your prompts, responses or Microsoft Graph data to train foundation models, honours your existing M365 permissions, and is covered by Purview retention policies. Important caveat for 2026: Copilot now also runs Anthropic models, and those are excluded from the EU Data Boundary, disabled by default in the EU, EFTA and UK and for non-federal GCC, and unavailable in GCC High and DoD. If your compliance position depends on the EU Data Boundary, keep them disabled or approve them deliberately and document the decision.
Do any of these train their models on my company’s data?
Not by default. OpenAI, Google, Anthropic, Microsoft, Perplexity and xAI all commit to not training on business or enterprise customer data without permission. The meaningful differences are in retention periods, residency and auditability – not in the training commitment itself.
Which AI has the best data privacy for enterprises?
For published, verifiable controls, OpenAI, Google and Anthropic lead – all three hold SOC 2 Type 2, ISO 27001 and ISO 42001. OpenAI publishes the longest data-residency list at ten regions, though its HIPAA BAA is scoped to the API Platform rather than ChatGPT generally. Anthropic offers customer-managed encryption keys and US-only inference. Google offers the simplest residency model – US, Europe, or no preference. Perplexity and xAI hold SOC 2 Type 2 but publish neither ISO 27001 nor residency commitments.
ChatGPT vs Copilot for enterprise – which should we pick?
If you run Microsoft 365, Copilot, because it reuses your permission model rather than creating a parallel one. If you do not, ChatGPT Enterprise offers a broader feature set and wider residency options. Budget for ChatGPT Enterprise rather than Business if you need SCIM, audit logs or data residency – those are Enterprise-only.
How much does Microsoft 365 Copilot cost per user?
$30 per user per month on annual commitment, $31.50 billed monthly, on top of a qualifying Microsoft 365 subscription. Since 1 July 2026 Microsoft also sells combined SKUs – Business Standard with Copilot at $23.50 and Business Premium with Copilot at $32 – which are frequently cheaper than the add-on route. There is also a standalone M365 Copilot Business at $18 for 1-300 licences.
What is the largest context window available?
Inside the vendors’ own assistants, Claude and Gemini both offer 1M tokens, Grok 4.6 offers 500K, and GPT-5.6 Sol offers 272K. Via cloud platforms the ceilings differ – GPT-5.6 supports 1M tokens on Amazon Bedrock, for example – so check your deployment path. For most business use a larger window matters less than people assume: it is decisive for whole-codebase analysis or large document sets, and largely irrelevant for drafting and summarisation.
Do we need more than one AI assistant?
Often two, rarely more. A primary assistant inside your productivity suite covers most day-to-day work; a specialist tool for research or engineering covers the rest. Beyond two, you are usually paying twice for overlapping capability and governing two sets of controls for no benefit.
Is Grok usable in a business context?
Yes, and its enterprise credentials are stronger than its public reputation suggests – SOC 2 Type 2, GDPR compliance, a HIPAA BAA on request, and SSO, SCIM, RBAC and audit logs at Enterprise tier. Its genuine differentiator is real-time X data for brand monitoring and sentiment analysis. Two things to plan around: those identity controls are Enterprise-only and not included in the $30 Business tier, and data residency is not publicly documented, so allow more time for security review.
How often does this comparison need updating?
Model names and context windows change every few months. Pricing and data-handling terms change roughly annually. We re-verify this page quarterly; the “last verified” date at the top tells you how current it is.
Sources
Verified 1 September 2026.
OpenAI: GPT-5.6 announcement · ChatGPT business pricing · Business models and limits · Enterprise privacy · Data residency · Trust portal
Google: Gemini API models · Gemini Pro · Workspace pricing · Generative AI privacy hub · Data regions · Gemini app data regions GA
Anthropic: Model overview · Claude Opus 5 · Pricing · Enterprise · Regional compliance · Model training policy · Retention for covered models · Certifications
Microsoft: M365 Copilot enterprise · Copilot privacy · Anthropic subprocessor · Anthropic models in apps · Partner Center, June 2026
Perplexity: Enterprise pricing · Enterprise security · Data retention and privacy
xAI: Models · Pricing · Grok Business · Organizations and SSO · API security FAQ
Other: GPT-5.6 long context on Amazon Bedrock · OpenAI zero-data-retention for frontier models · Gemini API changelog
Pricing and policies change. Verify current terms with each vendor before purchase.
