7 Sources
[1]
OpenAI chases Anthropic's biz customers with zero data retention pledge
OpenAI appears to have found a way to balance AI model safety with commitments to retain no customer data, a feat rival Anthropic hasn't yet managed. For orgs concerned about who has access to their data, this could be a game-changer. The free-spending AI biz on Wednesday announced Private Safety
[2]
OpenAI bets zero data retention can survive frontier AI
OpenAI has previewed Private Safety Processing, a system that hunts for misuse across several interactions at once. The company says zero data retention survives it, and that its own staff never see the content. Anthropic, meanwhile, now wants 30 days of logs. OpenAI has told enterprise customers
[3]
OpenAI wants to monitor AI abuse without forcing customers to hand over their data
Its new Private Safety Processing system takes a different approach from Anthropic, which requires 30-day retention for some advanced models OpenAI wants to get better at spotting people abusing its frontier AI models without asking privacy-conscious customers to give up Zero Data Retention. In an
[4]
OpenAI introduces new safety tool to protect user privacy
Under ZDR, OpenAI does not save a customer's prompts or the AI's responses once a task is finished. No OpenAI employee can view the content, and unless a company chooses to opt in, none of that data is used to train AI models. OpenAI on Thursday announced a new safety framework called Private
[5]
OpenAI tests private safety processing for Zero-Retention AI
OpenAI is testing a safety system called Private Safety Processing that can detect patterns of misuse across multiple AI interactions without giving its employees access to customers' prompts and responses. It is currently testing the system with early customers and plans to start rolling it out in
[6]
OpenAI's Zero Data Retention explained: What it means for your data
OpenAI hopes to win back the trust of businesses in handling their highly confidential data. On August 20th, the company reiterated its Zero Data Retention (ZDR) policy with respect to its eligible API users and presented a novel concept of Private Safety Processing, which aims to identify the
[7]
OpenAI tests new AI safety system to spot cyber threats while keeping customer data private: Here is how it works
It aims to detect possible cyber threats across multiple AI conversations while keeping customer data private. OpenAI is testing a new safety system that aims to detect possible cyber threats across multiple AI conversations while keeping customer data private. The new system is called Private
Share
Copy Link
OpenAI unveiled Private Safety Processing, a system that detects AI misuse patterns across multiple interactions while maintaining Zero Data Retention commitments. Unlike Anthropic's 30-day retention requirement, OpenAI's approach keeps enterprise data on customer-controlled infrastructure with automated monitoring that never exposes prompts or responses to company personnel.
OpenAI announced Private Safety Processing on Wednesday, a mechanism designed to monitor AI abuse while preserving Zero Data Retention commitments for eligible API customers
1
2
. The system addresses a critical limitation in current AI safety approaches by detecting misuse patterns across multiple interactions without giving OpenAI personnel access to customer data3
. Under Zero Data Retention, OpenAI does not save customer prompts or model responses once a request is processed, and enterprise data never trains models unless customers opt in4
. This privacy-preserving AI framework matters because organizations handling sensitive information face growing pressure to protect data while ensuring AI safety.
Source: Digit
The system extends automated protections across related interactions, allowing OpenAI to detect misuse patterns that only become visible when multiple exchanges are analyzed together
1
. Existing ZDR-compatible safety systems evaluate each interaction individually, creating blind spots for coordinated probes, repeated guardrail testing, and harmful intent disguised as legitimate research2
. Private Safety Processing fills this gap by identifying suspicious behavior across accounts and sessions. When automated systems flag potential misuse, OpenAI receives only a limited signal about the activity type, never the underlying prompts or responses5
. Customers investigate alerts through their own systems and can voluntarily share material to appeal decisions or support abuse investigations.Customer data stays on customer-controlled infrastructure in ZDR deployments. OpenAI is building a second option where content sits on OpenAI infrastructure under encryption keys the customer holds, with OpenAI personnel holding no copy of those keys
1
2
. Aleah Houze, OpenAI's head of product policy, provided a worked example where someone asks about software weaknesses in one conversation, then later queries about remote access and security detection tools. Read separately, each looks routine, but together they may indicate an attempted cyber attack2
.
Source: The Register
Anthropic now requires 30-day data retention for its most capable models, including Mythos 5 and Fable 5, even for organizations using Zero Data Retention
1
. The company acknowledged this policy "will be unpopular with customers who have come to expect zero retention" and expects real risks to its business, especially if competitors do not follow2
. Anthropic allows human review when content is flagged by automated trust and safety systems for potential harm, retaining model inputs and outputs for up to two years when usage violations are detected1
. Both companies describe the same problem—dangerous behavior shows up across requests rather than inside any one of them—but disagree on the remedy. The Wall Street Journal read OpenAI's preview as a bid for business from Anthropic customers unhappy with the change2
.OpenAI is testing Private Safety Processing with early customers including Microsoft and Databricks, with companies like Glean and Abridge shaping the work
2
. Sunil Agrawal, Glean's chief information security officer, said OpenAI's no-training commitment and Zero Data Retention give his firm confidence to build on the models. The system targets eligible enterprise and API customers, not consumer ChatGPT plans on Free, Plus, Go and Pro tiers2
3
. OpenAI plans to begin rolling out Private Safety Processing and publish a technical white paper in September3
5
.One explicit exception exists: images flagged as potential child sexual abuse material can still be retained for legally required manual review and reporting, even under Zero Data Retention
3
5
. OpenAI's human intervention scenario is narrow, limited to when child exploitation material is detected1
. Matthew Green, associate professor of computer science at Johns Hopkins University, observed that "private inference isn't private enough," noting AI agent workflows often rely on sensitive data when acting on behalf of users, and while private inference may protect some data flowing to and from AI agents, many gaps remain in the system1
.Related Stories
For Indian businesses, the question centers on who controls enterprise data after sending it to an AI provider. India's Digital Personal Data Protection Act, 2023 makes the Data Fiduciary responsible for processing carried out by a Data Processor on its behalf, requiring contracts and reasonable security safeguards
5
. The relevant processing provisions take effect on May 13, 2027. The Reserve Bank of India is considering data-governance requirements for regulated entities through its draft "Guidance on Regulatory Expectations for Data Governance" covering data lifecycle management and third-party arrangements, though it remains a draft. Zero retention does not by itself make an AI deployment compliant with Indian law, but it can reduce the amount of customer data that an enterprise allows an AI provider to retain5
.
Source: Digit
Keeping AI interactions and data flows private has become a major concern across the industry. Apple has its Private Cloud Compute, Google has its Private AI Compute, Nvidia offers Confidential Computing, and even Meta talks up its Private Processing for AI
1
. Much of the interest in running local AI models reflects a desire to keep sensitive data safe from potentially prying service providers and adversaries. This comes as cybersecurity firms and enterprises increasingly see cases of AI agents exploiting loopholes or taking unintended shortcuts to escape testing environments. Frontier AI labs such as Anthropic, Meta, OpenAI, and China's Moonshot recently disclosed increased cases of rogue agents capable of lying, blackmailing, secretly modifying code, phishing, and creating fake online identities4
. Watch for technical details in September's white paper to determine whether cross-session safety monitoring can work without weakening existing ZDR protections that privacy-conscious organizations rely on.Summarized by
Navi
[2]
[3]
14 Aug 2026•Business and Economy

25 Jun 2025•Policy and Regulation

16 Apr 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology