Safety & Security

OpenAI Previews Private Safety Processing to Keep Zero Data Retention

OpenAI is phasing in Private Safety Processing, letting automated systems detect misuse across customer interactions without staff ever seeing the underlying prompts or responses.

Offering Zero Data Retention for frontier models
Offering Zero Data Retention for frontier modelsAI-generated
By Elena Vasquez4 min read

Updated

Why it matters

  • OpenAI began rolling out Private Safety Processing to API customers in phases as of a September 22, 2026 update.
  • Under ZDR, OpenAI does not retain prompts or responses after processing, and enterprise data is not used for training without explicit opt-in.
  • Private Safety Processing uses customer-held encryption keys on OpenAI storage and returns only narrow safety signals — OpenAI personnel never see flagged content.

OpenAI is rolling out Private Safety Processing to API customers, expanding access in phases as of a September 22, 2026 update. The system exists to solve a specific tension: the company wants to keep offering Zero Data Retention (ZDR) for frontier models even as those models take on longer, more complex tasks where safety risks only become visible across multiple interactions.

The stakes are concrete for enterprise buyers. Under ZDR, eligible API customers get a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train OpenAI models unless customers explicitly opt in.

But existing ZDR-compatible safety systems evaluate each interaction individually. That leaves a gap. As OpenAI explains, "the most serious AI safety risks are not always visible in a single interaction." Potentially harmful intentions may only become clear when multiple interactions are viewed together — for instance, when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Risks can also develop during agentic tasks, such as when a system "becomes misaligned with the user's intent by continuing to act after being told to stop."

The market context matters here. Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, those requirements conflict with their security obligations or commitments to the people they serve. OpenAI's customers handle financial records, health data, confidential business plans, and proprietary research — categories where retention requirements can collide with regulatory obligations and customer trust.

Private Safety Processing is designed so OpenAI can continue to offer ZDR anyway.

How the system works

Private Safety Processing builds on the automated protections already used in ZDR and other deployments. It extends those protections across related interactions, letting automated systems identify patterns without OpenAI personnel having access to retained customer content.

The system processes customer content regardless of where it is stored. In ZDR deployments, content remains on infrastructure the customer controls. OpenAI is also developing an option where content is stored on OpenAI infrastructure but encrypted with keys controlled by the customer. OpenAI personnel do not hold copies of those keys, so they cannot access the underlying content.

When the automated systems identify a risk, OpenAI receives a narrowly defined signal indicating the type of activity involved — similar to the signals its existing safety systems produce today. That signal determines whether enforcement is necessary. Even flagged content is not exposed to OpenAI personnel.

Customers keep control of the investigation process. They can examine alerts and enforcement decisions using information available in their own systems. If they want to appeal, clarify legitimate activity, or support an investigation into verified abuse, they can choose to share relevant information with OpenAI.

OpenAI is currently testing Private Safety Processing with early customers. The company says it is sharing the preview now because customers "need predictability about how their content will be protected as AI systems become more capable."

Built with customers, not just for them

OpenAI frames the effort as collaborative, shaped by customers "across industries, regions, and company sizes." The company's own principles state that "no AI lab can address emerging risks alone," and Private Safety Processing is positioned as evidence of that approach — building stronger safeguards while keeping customer information under customer control.

The rollout comes with promised transparency. In the original announcement, OpenAI said it planned to start rolling out Private Safety Processing and share a technical white paper in September. The September 22 update confirms the phased rollout is underway, and the company says it will keep sharing updates early, explain what they mean for existing commitments, and give customers time and support to plan ahead.

OpenAI describes this as "just the beginning" of its work on collaborative approaches to privacy and safety. Developers can find implementation details in the company's developer guide.

For enterprise AI buyers, the signal is significant: the industry's largest provider is arguing that strong safety monitoring and strict data retention limits are not mutually exclusive. Whether encrypted, signal-based monitoring satisfies regulated industries — healthcare, finance, and government buyers who have held back on frontier models over data concerns — will determine how far ZDR deployments can scale as agentic systems take on longer, higher-stakes work.

Original: developers.openai.com

Share this article:

More from Elena Vasquez

Elena Vasquez

Show full bio

Market editor covering media and advertising at AI In Context.

137 articles

Related articles

  1. OpenAI's Long-Horizon Model Broke Out of Its Sandbox to Post to GitHub
  2. OpenAI cancels GPT-6.1 release, calls model too insecure to ship
  3. OpenAI Blocks GPT-6.1 Astra Release Over Deceptive Behavior
  4. OpenAI Trains GPT-5 Mini-R to Obey the Instruction Hierarchy
  5. OpenAI Explains How Its Safety Pipeline Missed GPT-4o Sycophancy

« Previous articleNext article »