OpenAI introduces a preview of Private Safety Processing to ensure zero data retention.

OpenAI introduces a preview of Private Safety Processing to ensure zero data retention.

      OpenAI has informed its enterprise clients that its commitment to not retaining their data will extend to the upcoming generation of models. The company clarified this stance in a post titled “Offering Zero Data Retention for Frontier Models,” where it introduced Private Safety Processing. This system is designed to detect misuse across multiple related interactions simultaneously, and OpenAI assures that its staff does not access the underlying prompts or responses.

      Zero data retention (ZDR) is available for qualifying API customers, meaning OpenAI does not retain their prompts or the responses generated by the model after processing a request. Its employees are unable to retrieve that content for review. Additionally, enterprise data is not utilized to train the models unless a customer explicitly opts in. These four commitments are what the new system aims to safeguard.

      The purpose of Private Safety Processing

      OpenAI asserts that it has reached a limitation with current ZDR-compatible safety systems, which evaluate each interaction individually. The company noted that “the most serious AI safety risks are not always visible in a single interaction.” It argues that harmful intent often only becomes apparent when several exchanges are examined together.

      The announcement outlines the behaviors OpenAI wishes to identify. Malicious actors may repeatedly test safeguards, coordinate their actions across different accounts, or disguise threats as regular inquiries. Also mentioned is a specific failure concerning agents: instances where a system diverges from the user’s intent and continues to act even after being instructed to stop. British and US testers observed an agent impersonating identities in tests conducted earlier this month.

      Data storage specifics

      In ZDR deployments, customer data is stored on infrastructure owned by the customer. OpenAI is also developing a second option where data remains on its infrastructure but under encryption keys controlled by the customer. According to OpenAI, its personnel do not retain copies of these keys, thus preventing access to the content.

      Flagging is conducted through automated reviews, which, when triggered, provide OpenAI with a narrowly defined signal identifying the type of activity involved. OpenAI then decides whether to take action, and its staff remain unable to access the content. Customers handle alerts via their own systems and have the option to submit material voluntarily for appeals or to assist with abuse investigations.

      Anthropic takes a different stance

      Although the post does not name a competitor, it implicitly contrasts with another position. OpenAI mentioned that “some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring.” This requirement, the company argues, conflicts with many organizations' security responsibilities and may violate commitments made to those they serve.

      In a different approach, Anthropic announced last week that it will enforce a 30-day data retention policy for its most advanced models. The company acknowledged that this policy "will be unpopular with customers who have come to expect zero retention" and indicated potential business risks, especially if competitors do not adopt similar measures. Anthropic believes retention is crucial for detecting attacks that span multiple requests.

      Both companies recognize the same issue: dangerous behaviors manifest across multiple requests rather than within individual interactions. However, they disagree on how to address it. The Wall Street Journal speculated that OpenAI's preview may be aimed at attracting Anthropic customers dissatisfied with the new retention requirement.

      Retention policies are a contentious topic beyond AI, as demonstrated by Flock Safety, which recently reduced its data retention period to seven days following numerous police misuse cases.

      Current testing of the system

      OpenAI has stated that the preview is currently being tested with early customers, including Microsoft and Databricks, as reported by Bloomberg. The post also mentions Glean and Abridge as companies involved in the development. Sunil Agrawal, Glean's chief information security officer, expressed confidence in building on the models, thanks to OpenAI's no-training commitment and ZDR.

      During a briefing, OpenAI’s head of product policy, Aleah Houze, provided an example scenario. If an individual queries about a software vulnerability in one conversation and later asks about remote access and security tools in another, each interaction seems like ordinary research. However, when considered together, they might reveal an attempted cyber attack, according to Houze.

      What the initiative does not include

      The system is intended solely for eligible enterprise and API customers; Axios noted that it does not apply to consumer ChatGPT plans. The data settings for Free, Plus, Go, and Pro users remain unchanged, as ZDR has never been applicable to those tiers.

      A specific exception is outlined in a footnote within the announcement: US law mandates that OpenAI report any signs of child sexual abuse material (CSAM). The company will retain images flagged as potential CSAM for manual review and reporting, even in zero data retention scenarios, similar to current practices.

      The September rollout

      Specific technical details are not yet public. OpenAI intends to begin the rollout of Private Safety Processing in September and will provide a white paper at that time. Until the paper is released, one claim stands unverified: that the system analyzes patterns across interactions without

Other articles

OpenAI introduces a preview of Private Safety Processing to maintain zero data retention. OpenAI introduces a preview of Private Safety Processing to maintain zero data retention. OpenAI is showcasing Private Safety Processing, a system that it claims detects misuse during interactions while maintaining zero data retention. Google has upgraded Gemini Live with its own Deep Research enhancements. Google has upgraded Gemini Live with its own Deep Research enhancements. Gemini Live can now initiate Deep Research reports using voice commands, operate on them in the background, and allow you to discuss the results once they are prepared. Motorola's sleek new charging puck enters the ranks of Android's compact magnetic accessories. Motorola's sleek new charging puck enters the ranks of Android's compact magnetic accessories. Leaked photos show Motorola’s Moto Snap magnetic wireless charger, which could provide the Qi2-enabled Edge 70 Max with a charging accessory similar to Pixelsnap. Prosus is investing $100 million in Navi, at a reduced valuation compared to its previous intentions. Prosus is investing $100 million in Navi, at a reduced valuation compared to its previous intentions. Navi, the Indian fintech founded by Sachin Bansal, has secured $100 million from Prosus in its initial institutional funding round. According to reports, this funding values the company at approximately $1.3 billion in anticipation of an IPO. Comcast is converting millions of routers into motion sensors. Comcast is converting millions of routers into motion sensors. Comcast is activating WiFi Motion, a complimentary feature that transforms millions of Xfinity routers into motion sensors without cameras, which has sparked concerns about privacy. Samsung has scheduled August 27 for the launch of its next Galaxy S phone, with indications suggesting it will be the S26 FE. Samsung has scheduled August 27 for the launch of its next Galaxy S phone, with indications suggesting it will be the S26 FE. Samsung is organizing a Galaxy Event on August 27, and all indications suggest the Galaxy S26 FE will be featured. Here's what the company's invitation and teaser disclose, along with everything we currently know about Samsung's upcoming Fan Edition smartphone.

OpenAI introduces a preview of Private Safety Processing to ensure zero data retention.

OpenAI is introducing Private Safety Processing, which they claim detects misuse during interactions while ensuring that there is no data retention.