90 Days Gen AI Risk Trial -Start Now
Book a demo
Video·Plus $20/mo (480p unlimited); Pro $200/mo (1080p, 10k credits); API $0.10-$0.50/sec·openai.com

Sora

OpenAI's flagship text-to-video model producing synchronized audio, cinematic motion, and cameo likeness features inside ChatGPT Plus/Pro and the standalone Sora app.

Risk Score
High
6/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Sora 2 is OpenAI's text-to-video and image-to-video model, delivering 1080p clips up to 20 seconds with synchronized dialogue and sound effects. It launched broadly in late 2025 and as of January 2026 is gated to paid ChatGPT tiers (Plus, Pro) and the Sora iOS app, with a commercial API tier at roughly $0.10-$0.50 per second depending on resolution and profile. Because Sora inherits OpenAI's enterprise trust posture (SOC 2 Type 2, GDPR DPA, zero-retention API option), core security controls are strong. The acute risks are content-specific: high-fidelity deepfakes, likeness misuse, and copyrighted-character generation. OpenAI shifted to an opt-in regime for real people ('cameos') and is moving toward opt-in for rights-holder characters after pushback from SAG-AFTRA and Japanese studios.

Risk factors

3
  • Consumer-first tool with potential data training on user inputs
  • No clear enterprise controls for data privacy
  • User-generated content may be stored and analyzed

Recommendations

2
  • Implement strict data access policies
  • Evaluate enterprise plan options for better data control

Data handling

Storage
Stored on OpenAI infrastructure (US with EU data residency available for enterprise); videos retained in user library until deleted
Retention
30-day abuse monitoring retention; ChatGPT Business/Enterprise and API with ZDR honor deletion; consumer history kept until user deletes
Training on inputs
Consumer ChatGPT/Sora app uses prompts for training by default unless opted out; Business, Enterprise, Edu, and API are not trained on