OpenAI Zero Data Retention and Private Safety Processing

OpenAI has announced Private Safety Processing, a new system designed to identify safety risks and misuse patterns across multiple interactions while maintaining Zero Data Retention (ZDR) promises. This allows eligible API customers to ensure their prompts and model responses are not retained or reviewed by OpenAI personnel, while still enabling automated safety enforcement.

Zero Data Retention (ZDR) Framework

Zero Data Retention provides a guarantee to eligible API customers that OpenAI does not retain prompts or model responses after a request is processed. Under this framework, customer content is not available for review by OpenAI personnel, and enterprise data is not used for model training unless the customer explicitly opts in.

The Need for Evolving Safety Systems

Traditional ZDR-compatible safety systems evaluate interactions on an individual basis. However, OpenAI states that the most serious AI safety risks often only become visible when multiple interactions are viewed together. Examples of these risks include:

  • Pattern-based misuse: Bad actors probing safeguards or coordinating across accounts.
  • Agentic misalignment: Systems continuing to act after being instructed to stop during complex, multi-step tasks.
  • Disguised threats: Harmful intentions masked as routine research.

As AI models handle longer and more complex tasks, the ability to distinguish legitimate activity from misuse requires broader context than a single interaction provides.

Technical Implementation of Private Safety Processing

Private Safety Processing extends automated protections across related interactions to identify patterns of misuse without exposing content to OpenAI personnel. The system operates under two primary infrastructure models:

  1. Customer-Controlled Infrastructure: Content remains on infrastructure managed by the customer.
  2. OpenAI-Provided Storage: Content is stored on OpenAI infrastructure but is encrypted with keys controlled exclusively by the customer. OpenAI personnel do not possess these keys and cannot access the underlying content.

When the automated system identifies a risk, it generates a narrowly defined signal indicating the type of activity. This signal is used to determine if enforcement is necessary, but OpenAI personnel do not receive access to the customer content, even when it is flagged.

Customer Control and Enforcement

Customers maintain full control over their data and the investigation of alerts. If a customer wishes to appeal an enforcement decision, clarify legitimate activity, or support an investigation into verified abuse, they may choose to share relevant information with OpenAI voluntarily.

Availability and Roadmap

Private Safety Processing is currently in testing with early customers. OpenAI plans to begin rolling out the feature and publish a technical white paper in September 2026.

Sources

Related

  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch
  • Dispatch