OpenAI is expanding privacy protections for eligible API customers with Zero Data Retention for its frontier AI models, while also testing a new Private Safety Processing system that checks for harmful activity without giving company personnel access to customer prompts or model responses.
Under Zero Data Retention, OpenAI says it does not retain prompts or outputs after processing a request, customer content remains unavailable for employee review, and enterprise data does not train its models unless a customer explicitly opts in.
The policy targets companies working with financial records, health information, confidential business plans, proprietary research, and other sensitive data where storage periods and internal access require strict controls.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Private Safety Processing adds automated monitoring
OpenAI says some forms of misuse only become clear across several related interactions, especially when users repeatedly test safeguards, coordinate activity across accounts, or carry out longer agent-based tasks.
“Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content.”
OpenAI says customer-controlled Zero Data Retention deployments keep content on infrastructure managed by the customer, while another planned option will store encrypted content on OpenAI infrastructure using customer-controlled keys.
When automated systems identify potential misuse, OpenAI receives a limited safety signal describing the category and severity of the activity rather than the original prompts or responses.
Customers can review alerts through their own records and choose whether to share additional information during an appeal or verified abuse investigation.
OpenAI is testing Private Safety Processing with early customers and plans to begin rolling it out in September, alongside a technical white paper covering its architecture and safeguards.
Discussion