6 Sources
[1]
OpenAI bets zero data retention can survive frontier AI
OpenAI has previewed Private Safety Processing, a system that hunts for misuse across several interactions at once. The company says zero data retention survives it, and that its own staff never see the content. Anthropic, meanwhile, now wants 30 days of logs. OpenAI has told enterprise customers that its promise not to keep their data will survive the next generation of models. The company set out the position on Wednesday in a post titled "Offering Zero Data Retention for frontier models". In it, it previewed Private Safety Processing. The system looks for misuse across several related interactions at once, and OpenAI says its own staff never see the prompts or responses underneath. Zero data retention, or ZDR, is an option for eligible API customers. OpenAI does not keep their prompts or model responses once it has processed a request. Its personnel cannot pull that content up for review. Enterprise data does not train the models either, unless a customer opts in. Those four promises are what the new system is meant to protect. What Private Safety Processing is for The company's case rests on a limit it says it has hit. Today's ZDR-compatible safety systems judge each interaction on its own. "The most serious AI safety risks are not always visible in a single interaction," OpenAI wrote in the announcement. Harmful intent, it argues, often shows itself only when several exchanges are read together. The post lists the patterns OpenAI wants to catch. Bad actors probe safeguards repeatedly. They coordinate across accounts. They dress threats up as routine research. The post also names a failure specific to agents. A system drifts from the user's intent, then carries on acting after someone tells it to stop. British and US testers watched an agent fake identities in tests earlier this month. Where the data sits In ZDR deployments, customer content stays on infrastructure the customer controls. OpenAI is building a second option too. Content would sit on OpenAI infrastructure, under encryption keys the customer holds. OpenAI personnel hold no copy of those keys, the company says, so they cannot reach the content. Automated review does the flagging. When it fires, OpenAI receives what it calls a narrowly defined signal, naming the type of activity involved. The company then decides whether to enforce. Its staff still cannot open the content. Customers investigate alerts through their own systems. They can also hand material over voluntarily, to appeal a decision or to help an abuse investigation. Anthropic reached the opposite answer The post names no rival, but it describes one. "Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring," OpenAI wrote. For many organisations, it added, that requirement collides with their own security duties. It can also cut against promises they have made to the people they serve. Anthropic set out the other position last week. It will require 30-day data retention on its most capable models. The policy "will be unpopular with customers who have come to expect zero retention", the company wrote in its risk report. It expects real risks to its business, it said, especially if competitors do not follow. Retention is essential to catch attacks that span multiple requests, it argues. Both firms describe the same problem. Dangerous behaviour shows up across requests rather than inside any one of them. They disagree on the remedy. The Wall Street Journal read the preview as a bid for business from Anthropic customers unhappy with the change. Retention windows are contested well outside AI. Surveillance firm Flock Safety cut data retention to seven days this month, after dozens of police abuse cases. Who is testing it OpenAI says the preview runs with early customers. Bloomberg reported that those include Microsoft and Databricks. The post also names Glean and Abridge among the companies shaping the work. Sunil Agrawal, Glean's chief information security officer, said OpenAI's no-training commitment and ZDR give his firm the confidence to build on the models. Aleah Houze, OpenAI's head of product policy, gave reporters a worked example at a briefing. Someone asks about a weakness in a company's software in one conversation. Later, in another, the same person asks about remote access and about which security tools can spot it. Read separately, each looks like ordinary research. "But when you look at them together in the broader context, you might detect that somebody is actually attempting a cyber attack," Houze said. What the scheme does not cover The system targets eligible enterprise and API customers. Axios reported that it does not reach consumer ChatGPT plans. Data settings for Free, Plus, Go and Pro users stay as they are. ZDR never applied to those tiers. One carve-out sits in the announcement's own footnote. US law requires OpenAI to report apparent child sexual abuse material. It keeps images flagged as potential CSAM for manual review and for reporting, even in zero data retention deployments, exactly as it does today. The September test The technical detail is not public. OpenAI plans to start rolling out Private Safety Processing in September. It will publish a white paper at the same time. Until that paper lands, one claim in particular sits outside anyone else's reach: that the system traces patterns across interactions while nobody at OpenAI reads them. The preview also arrives in a busy month for the company's safety machinery. OpenAI is rewriting its safety rules after the Hugging Face breach. Earlier in August it said it had slowed its next model over critical cyber risk. European buyers have their own reason to read the September paper closely. Provider-side retention is awkward to sign off under GDPR, and under the sectoral rules covering health and financial records. That is the exact category of data OpenAI says its customers handle. A crop of European startups now sells companies control over their AI on that argument alone.
[2]
OpenAI wants to monitor AI abuse without forcing customers to hand over their data
Its new Private Safety Processing system takes a different approach from Anthropic, which requires 30-day retention for some advanced models OpenAI wants to get better at spotting people abusing its frontier AI models without asking privacy-conscious customers to give up Zero Data Retention. In an August 19 announcement, OpenAI introduced Private Safety Processing, a system designed to detect suspicious behavior across multiple interactions while preserving ZDR for eligible API customers. OpenAI says its existing ZDR safeguards evaluate requests individually, making patterns spread across several interactions harder to detect. Private Safety Processing is supposed to fill that gap without giving OpenAI employees access to the underlying prompts or responses. Recommended Videos For now, the system is being tested with early customers. Axios reports that it's aimed at enterprise and API customers rather than individual ChatGPT subscribers. How does Private Safety Processing work Instead of inspecting one request at a time, the system can look for suspicious patterns across related interactions. When it detects possible misuse, OpenAI receives a limited signal about the activity rather than the customer's underlying content. With Zero Data Retention deployments, that content stays on infrastructure controlled by the customer. OpenAI is also developing another setup where encrypted content can live on its infrastructure while customers hold the encryption keys. OpenAI itself wouldn't possess those keys. Why Anthropic chose another route Anthropic has made a different tradeoff. For its Covered Models, prompts and outputs are retained for 30 days, including for organizations that previously used Zero Data Retention. Anthropic says that window helps its safeguards catch attacks that only become apparent across multiple requests. OpenAI is trying to solve the same safety problem while keeping ZDR intact for eligible customers. For businesses that adopted ZDR specifically to limit how long an AI provider can hold their content, those are materially different propositions. What zero retention still leaves out Private Safety Processing is still an early preview, and OpenAI hasn't yet publicly demonstrated that it can provide abuse detection equivalent to approaches that retain customer content. The technical details behind those privacy protections also aren't public yet. There's an explicit exception. OpenAI says images flagged as potential child sexual abuse material can still be retained for legally required manual review and reporting, even under Zero Data Retention. OpenAI plans to begin rolling out Private Safety Processing and publish a technical white paper in September. That should give customers a much better idea of whether cross-session safety monitoring can work without weakening the existing ZDR protections they rely on.
[3]
OpenAI introduces new safety tool to protect user privacy
Under ZDR, OpenAI does not save a customer's prompts or the AI's responses once a task is finished. No OpenAI employee can view the content, and unless a company chooses to opt in, none of that data is used to train AI models. OpenAI on Thursday announced a new safety framework called Private Safety Processing, aimed at closing the gap between its zero data retention (ZDR) commitments and the growing need to monitor AI systems for misuse across multiple interactions. Under ZDR, OpenAI does not save a customer's prompts or the AI's responses once a task is finished. No OpenAI employee can view the content, and unless a company chooses to opt in, none of that data is used to train AI models. ZDR is popular with organisations that handle sensitive information, such as those with strict confidentiality rules or legal obligations to protect user data. However, OpenAI says this level of privacy has created a blind spot. Existing ZDR-compatible safety tools assess each interaction in isolation, making it harder to catch threats that only become apparent when several interactions are considered together -- such as bad actors probing safety guardrails repeatedly, coordinating misuse across multiple accounts, or masking harmful intent as legitimate research. Currently, OpenAI's safety tools review each interaction on their own. That makes these bigger, connected patterns harder to catch. This is the issue Private Safety Processing aims to fix, the company said in a blog post. It is built to notice suspicious patterns across multiple interactions without ever showing the actual content to OpenAI staff. For ZDR customers, their data will keep living on infrastructure they control. OpenAI is also building a second option of data being stored on OpenAI's own systems, but locked with encryption keys that only the customer holds. In both cases, automated systems will scan for warning signs and send out limited alerts, while keeping actual conversations private. This comes as cybersecurity firms and enterprises increasingly see cases of AI agents exploiting loopholes or taking unintended shortcuts to escape testing environments. Frontier AI labs such as Anthropic, Meta, OpenAI, and China's Moonshot recently disclosed increased cases of rogue agents that are capable of lying, blackmailing, secretly modifying code, phishing, and creating fake online identities.
[4]
OpenAI tests private safety processing for Zero-Retention AI
OpenAI is testing a safety system called Private Safety Processing that can detect patterns of misuse across multiple AI interactions without giving its employees access to customers' prompts and responses. It is currently testing the system with early customers and plans to start rolling it out in September. For Indian businesses, the question is who controls enterprise data after a company sends it to an AI provider. India's Digital Personal Data Protection Act, 2023 makes the Data Fiduciary responsible for processing carried out by a Data Processor on its behalf. The Act also requires a contract between them and reasonable security safeguards. The relevant processing provisions are scheduled to take effect on May 13, 2027. The Reserve Bank of India is also considering data-governance requirements for regulated entities. Its draft "Guidance on Regulatory Expectations for Data Governance" covers data lifecycle management and third-party arrangements. It remains a draft. The RBI has not yet made it a binding regulation. What does Private Safety Processing do? OpenAI's existing Zero Data Retention option allows eligible API customers to keep prompts and model responses out of OpenAI's retained data. Private Safety Processing extends those protections across related interactions. OpenAI says its automated systems can identify patterns that may indicate misuse, including activity that only becomes visible across multiple requests. The system does this without exposing the underlying content to OpenAI employees. Customers can keep that content on infrastructure they control. OpenAI is also developing an option that stores the content on OpenAI infrastructure but encrypts it with keys controlled by the customer. OpenAI says its personnel will not have those keys. When the system detects a risk, OpenAI receives a limited signal about the type of activity involved. It does not receive the underlying prompts or responses. Customers can review alerts through their own systems and choose to share relevant information with OpenAI when they appeal an enforcement decision or support an investigation into verified abuse. OpenAI says images flagged as potential child sexual abuse material (CSAM) will continue to be retained for manual review and reporting, including in Zero Data Retention deployments. Anthropic takes a different approach Anthropic requires 30-day retention for prompts and outputs submitted to its designated Covered Models. The policy covers its Mythos-class models and future models that Anthropic designates as Covered Models. Anthropic says it uses the retained data for safety monitoring and review. The policy applies even to organisations that otherwise use zero data retention. Anthropic says those organisations must enable retention to use Covered Models. It automatically deletes the data after 30 days, subject to limited exceptions. Anthropic keeps some customer content so its safety teams can review patterns of misuse. OpenAI's new system is designed to detect those patterns while keeping the underlying content outside its employees' access. What does this mean for Indian companies? Zero retention does not by itself make an AI deployment compliant with Indian law. It can, however, reduce the amount of customer data that an enterprise allows an AI provider to retain. Section 8 of the DPDP Act places responsibility on the Data Fiduciary for processing carried out by its Data Processor. That means an enterprise still has to assess its vendor's data handling, retention and deletion arrangements. The Act's relevant processing provisions are not yet in force. The RBI's draft guidance points in the same direction for regulated entities. It addresses third-party data arrangements and controls across the data lifecycle, but it does not require AI vendors to offer zero data retention. For Indian customers, Private Safety Processing is therefore a product and contracting choice, not a requirement under current Indian data-protection law. MediaNama has asked OpenAI whether Indian customers will be able to use Private Safety Processing when the rollout begins, and whether any India-specific terms or restrictions will apply.
[5]
OpenAI's Zero Data Retention explained: What it means for your data
OpenAI hopes to win back the trust of businesses in handling their highly confidential data. On August 20th, the company reiterated its Zero Data Retention (ZDR) policy with respect to its eligible API users and presented a novel concept of Private Safety Processing, which aims to identify the wrongdoers without anyone from OpenAI having a look at your inputs. Sounds contradictory? Well, it kind of is. Here's why. Also read: AI Pro vs AI Plus for students: Google's free offer isn't the same everywhere What Zero Data Retention already promised This is nothing new. This service has been around for some time now as an alternative for enterprise API users who do not want OpenAI to store their prompts or outputs after the request is done. No one from OpenAI is supposed to see that content, and it is not used for training future iterations of the model unless a user chooses to opt-in. This was always the starting point for industries dealing with health, financial information, or confidential business plans when considering the use of OpenAI's API over the free ChatGPT. There is, however, one exception that has not been altered. Content marked as possible child sexual abuse material is always stored as per US law requirements. The problem OpenAI says it's solving The problem is this. The current safety systems which are compliant with ZDR are point-in-time and evaluate each interaction separately. However, some of the more dangerous risks of AI, such as an organized jailbreak that spans several interactions or the continued activity of an autonomous agent even after it is ordered to cease doing so, can be detected only in the context of multiple interactions. Also read: Rewriting the rules of workplace learning: Inside Workday's bet on the future of L&D Rival companies have addressed this problem by encouraging their clients to allow the AI company to keep sensitive material in order to conduct the checks. OpenAI believes that such an approach is unacceptable for most of its enterprise clients. Private Safety Processing Here's the new system. It expands safety monitoring to cover relevant interactions without granting OpenAI's personnel access to the raw material itself. For ZDR instances, all of the data remains on infrastructure controlled by the customer. OpenAI is also developing a system that will store the content on OpenAI's servers but in an encrypted form that will allow only the customer, not OpenAI, to decrypt it. The automated systems will monitor the use for signs of misuse. In cases where there appear to be problems, OpenAI gets a "narrowly defined signal," essentially meaning "this user has triggered signal X." The enforcement actions are based on that signal alone. Should a customer wish to challenge such a finding, they can submit the necessary material themselves rather than allowing OpenAI to retrieve it. What this doesn't mean This is not to say that OpenAI cannot take action against your data. This means that OpenAI employees will not look at it casually, and the automated flagging process will be done without viewing the content, unless you provide it to OpenAI voluntarily during the appeals process. This system is not operational yet. OpenAI is currently testing this with some early adopters and will be launching it in September. Why this matters beyond OpenAI's enterprise clients But this is one example in a much larger trend happening everywhere there are significant AI research laboratories at the moment where companies are attempting to repair their enterprise reputations after several privacy missteps while also convincing regulators and the public at large that artificial intelligence can be trusted to act more independently. It will be interesting to see what happens once this goes live.
[6]
OpenAI tests new AI safety system to spot cyber threats while keeping customer data private: Here is how it works
It aims to detect possible cyber threats across multiple AI conversations while keeping customer data private. OpenAI is testing a new safety system that aims to detect possible cyber threats across multiple AI conversations while keeping customer data private. The new system is called Private Safety Processing, and is being tested with some early customers, including Microsoft and Databricks. OpenAI plans to make it available and publish a technical paper about it in September. The move comes as businesses increasingly use advanced AI models for complex tasks and handle sensitive information. OpenAI says the new system can identify risks that may not be visible when conversations are checked one at a time. It is designed to provide stronger safety checks without giving OpenAI access to customer content. What is OpenAI's Private Safety Processing? Private Safety Processing is designed to look for possible security threats across multiple interactions with an AI model. OpenAI says this is important because some risks may only become clear when several conversations are viewed together. Aleah Houze, OpenAI's head of product policy, said increasingly powerful AI models need a different approach to safety. "We're seeing with more capable frontier models that often, risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions," Houze said during a press briefing, as quoted by Bloomberg. For example, a person may ask about a weakness in a company's software in one conversation. Later, they may ask about remote access or security tools. Looking at these questions separately may not reveal a threat. Together, they could point to a possible cyberattack. Also read: Samsung Galaxy event date announced: Here is when Galaxy S26 FE will launch How does Private Safety Processing protect customer data Private Safety Processing builds on the safety systems already used for customers with zero data retention, or ZDR. These systems normally check each interaction separately. The new system can check related interactions to identify patterns. OpenAI says its automated systems can do this without giving its employees access to customer content. Also read: OpenAI pauses some AI training after Hugging Face incident, strengthens safeguards for advanced models Customer data can remain in infrastructure controlled by the customer or in storage provided by OpenAI. When OpenAI provides the storage, the data is encrypted with keys controlled by the customer. OpenAI employees do not have copies of these keys. If the system detects a possible risk, OpenAI receives only a limited signal. The company says its employees still cannot see the customer content, even if an interaction is flagged. Customers can review alerts and enforcement decisions through their own systems. They can also choose to share relevant information with OpenAI if they want to appeal a decision or help investigate confirmed abuse.
Share
Copy Link
OpenAI announced Private Safety Processing, a system designed to detect misuse across multiple interactions without accessing customer content. The move contrasts sharply with Anthropic's 30-day data retention policy and aims to preserve Zero Data Retention for enterprise API customers while addressing frontier AI safety risks.

OpenAI has introduced Private Safety Processing, a system that promises to detect AI misuse across multiple interactions while preserving Zero Data Retention (ZDR) for eligible enterprise API users
1
. The announcement on August 19 marks a significant departure from industry approaches to AI safety and data governance, particularly as Anthropic recently mandated 30-day data retention for its most capable models1
. Under ZDR, OpenAI does not save customer prompts or model responses once a request is processed, and no OpenAI employee can view that content3
. Enterprise data does not train the models either, unless a customer opts in1
.OpenAI says its existing ZDR-compatible safety systems evaluate each interaction individually, creating a blind spot for threats that only become visible across related exchanges
1
. The company's case rests on patterns it wants to catch: bad actors probing safeguards repeatedly, coordinated probes across accounts, and threats disguised as routine research1
. The system also targets agent drift, where autonomous agents continue acting after users tell them to stop1
. British and US testers watched an agent fake identities in tests earlier this month1
. Frontier AI labs including Anthropic, Meta, OpenAI, and China's Moonshot recently disclosed increased cases of rogue agents capable of lying, blackmailing, secretly modifying code, phishing, and creating fake online identities3
.Instead of inspecting one request at a time, Private Safety Processing looks for suspicious patterns across related interactions
2
. When it detects possible misuse, OpenAI receives a narrowly defined signal about the type of activity involved, not the underlying content1
. In ZDR deployments, customer content stays on customer-controlled infrastructure1
. OpenAI is building a second option where content sits on encrypted OpenAI infrastructure, but customers hold the encryption keys that OpenAI personnel cannot access1
. Automated review handles the flagging, and customers investigate alerts through their own systems1
. Aleah Houze, OpenAI's head of product policy, gave reporters a worked example: someone asks about a software weakness in one conversation, then later asks about remote access and which security tools can spot it. Read separately, each looks ordinary, but together they might indicate a cyber attack attempt1
.Anthropics approach to the same problem differs sharply. The company now requires 30-day data retention on its most capable models, including for organizations that previously used Zero Data Retention
1
. Anthropic acknowledged in its risk report that this policy "will be unpopular with customers who have come to expect zero retention" and expects real risks to its business, especially if competitors do not follow1
. Both firms describe the same problem—dangerous behavior showing up across requests rather than inside any one of them—but disagree on the remedy1
. The Wall Street Journal read OpenAI's preview as a bid for business from Anthropic customers unhappy with the change1
.OpenAI says the preview runs with early customers including Microsoft and Databricks, according to Bloomberg
1
. The company also named Glean and Abridge among those shaping the work1
. Sunil Agrawal, Glean's chief information security officer, said OpenAI's no-training commitment and ZDR give his firm the confidence to build on the models1
. The system targets eligible enterprise and API customers, not consumer ChatGPT plans1
. Axios reported that data settings for Free, Plus, Go and Pro users stay as they are, since ZDR never applied to those tiers1
. OpenAI plans to start rolling out Private Safety Processing and publish a technical white paper in September2
.Related Stories
One carve-out sits in the announcement's own footnote: US law requires OpenAI to report apparent child sexual abuse material, and images flagged as potential CSAM can still be retained for legally required manual review and reporting, even under Zero Data Retention
1
2
. OpenAI has not yet publicly demonstrated that Private Safety Processing can provide abuse detection equivalent to approaches that retain customer content, and the technical details behind those privacy protections are not public yet2
.For Indian businesses, the question centers on who controls enterprise data after a company sends it to an AI provider
4
. India's Digital Personal Data Protection Act, 2023 makes the Data Fiduciary responsible for processing carried out by a Data Processor on its behalf and requires a contract between them and reasonable security safeguards4
. The relevant processing provisions are scheduled to take effect on May 13, 20274
. The Reserve Bank of India is also considering data-governance requirements for regulated entities through its draft "Guidance on Regulatory Expectations for Data Governance," which covers data lifecycle management and third-party arrangements, though it remains a draft4
. Zero retention does not by itself make an AI deployment compliant with Indian law, but it can reduce the amount of customer data that an enterprise allows an AI provider to retain4
.The technical white paper arriving in September should clarify whether cross-session safety monitoring can work without weakening existing ZDR protections
2
. Watch for how enterprises with strict confidentiality requirements respond to the new option, particularly those handling health, financial information, or confidential business plans5
. The competitive dynamic between OpenAI and Anthropic on data retention policy will likely shape industry standards for AI safety monitoring and data confidentiality. Retention windows are contested well outside AI—surveillance firm Flock Safety cut data retention to seven days this month after dozens of police abuse cases1
. How regulators and enterprise customers respond to these competing approaches will determine whether privacy-preserving safety monitoring becomes the industry norm or remains a niche offering.Summarized by
Navi
[1]
[2]
16 Apr 2025•Technology

17 Aug 2026•Technology

07 Oct 2025•Technology

1
Technology

2
Technology

3
Technology
