OpenAI previews Private Safety Processing to preserve zero data retention as agentic tasks grow longer
OpenAI is previewing a new safety system called Private Safety Processing, designed to let the company keep offering Zero Data Retention (ZDR) to enterprise API customers even as it expands monitoring for risks that only become visible across multiple interactions rather than a single prompt.
What's new
OpenAI restated its baseline commitment before describing the new system: "Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed," and customer content isn't available to OpenAI personnel for review or used to train models without explicit opt-in.
The gap the new system addresses: existing ZDR-compatible safety tooling evaluates each interaction in isolation, but some of the most serious risks — coordinated abuse across accounts, safeguard-probing spread across sessions, or an agent quietly continuing a task after being told to stop — only show up when interactions are viewed together. Private Safety Processing is built to close that gap without breaking the ZDR promise:
- It extends automated pattern-detection across related interactions, not just single ones, while keeping the underlying content out of reach of OpenAI staff.
- For ZDR deployments, customer content stays on infrastructure the customer controls. OpenAI is also building an option to store content on its own infrastructure but encrypted with customer-controlled keys, so "OpenAI personnel do not have a copy of those keys, so they cannot access the underlying content."
- When automated systems flag a risk, OpenAI receives only a narrow signal about the type of activity — enough to decide on enforcement — without access to the flagged content itself. Customers can investigate using their own logs, or choose to share information with OpenAI to appeal a decision or support an abuse investigation.
- The system is "currently being tested with early customers." OpenAI plans to begin rolling it out, alongside a technical white paper, in September.
Glean's CISO Sunil Agrawal is quoted endorsing the approach: enterprise adoption "depends solely on customer control of data, with no direct or derivative use beyond the chosen service."
Context
The announcement lands as data retention has become a competitive and regulatory flashpoint among frontier labs. Anthropic recently began requiring 30-day data retention for some of its newer frontier models, a change that overrode prior zero-data-retention agreements for those systems — a move that drew pushback from privacy- and compliance-sensitive enterprise customers. OpenAI's framing here is explicit about that tension: as agentic AI systems take on longer, more complex tasks, safety teams have leaned on retaining more content for monitoring, which "conflict[s] with their security obligations or commitments to the people they serve" for many organizations.
Why it matters
Data retention terms are becoming a genuine differentiator in enterprise AI procurement, not just fine print. By previewing a technical path to keep ZDR intact while still catching multi-interaction abuse patterns, OpenAI is positioning itself against rivals now requiring broader retention for safety reasons — a direct response to a specific enterprise objection rather than a generic privacy statement. Whether Private Safety Processing actually holds up under real adversarial testing, and whether the September rollout stays on schedule, will determine if this becomes a genuine advantage or just a preview that quietly slips.
Corroborating sources
- Openai
https://openai.com/index/our-commitment-to-zero-data-retention
“Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed.”