OpenAI Zero Data Retention and Private Safety Processing announcement
TL;DR
OpenAI introduced Zero Data Retention (ZDR) for eligible API customers, guaranteeing that prompts and model responses are not stored after processing, and previewed Private Safety Processing, which can detect risky patterns across interactions without giving OpenAI personnel access to the underlying data.
Zero Data Retention (ZDR) guarantees
- No prompt or response storage: OpenAI does not retain any customer content after a request is completed.
- No internal review access: Customer data is unavailable to OpenAI personnel for manual inspection.
- No training use without opt‑in: Enterprise data is excluded from model training unless the customer explicitly chooses to contribute.
- Customer‑controlled infrastructure: For ZDR deployments, all content remains on infrastructure owned by the customer.
- Encrypted OpenAI storage option: OpenAI is developing a storage solution where data is encrypted with keys that only the customer controls, preventing OpenAI staff from decrypting the content.
Why safety systems must evolve
- Multi‑interaction risk: Harmful intent often emerges only when multiple interactions are examined together, such as coordinated probing of safeguards or agents continuing actions after being told to stop.
- Longer, more complex tasks: As models handle extended tasks, contextual information across calls becomes essential for distinguishing legitimate use from abuse.
- Conflict with security obligations: Some frontier‑model deployments previously required providers to retain content for safety monitoring, which clashes with many organizations' regulatory and trust requirements.
Private Safety Processing overview
- Pattern detection without data retention: Extends existing ZDR safety mechanisms to analyze sequences of related interactions while keeping the raw content inaccessible to OpenAI staff.
- Works with any storage location: Operates on data stored on the customer’s own infrastructure or on OpenAI‑provided storage encrypted with customer‑controlled keys.
- Limited safety signals: When a risk is detected, OpenAI receives a narrowly defined signal (e.g., type of suspicious activity) that can trigger enforcement decisions without exposing the underlying prompts or responses.
- Customer‑led investigation: Alerts and enforcement outcomes are visible only within the customer’s systems; customers may choose to share relevant details with OpenAI for appeals or abuse investigations.
- Early‑customer testing: The feature is currently being piloted with select customers, and a technical white paper is planned for release in September.
Customer collaboration and trust
- Principles‑driven development: The initiative aligns with OpenAI’s stated principles that AI safety requires collaboration with external partners.
- Industry‑specific sensitivity: Participants handle highly confidential data such as financial records, health information, and proprietary research, making data control critical for regulatory compliance and competitive advantage.
- Enterprise endorsement: Sunil Agrawal, CISO of Glean, stated that “Enterprise AI adoption depends solely on customer control of data… OpenAI’s no‑training commitment and ZDR give Glean confidence to build with OpenAI.”
Next steps and rollout plan
- September rollout: OpenAI intends to begin broader deployment of Private Safety Processing and publish a detailed white paper.
- Ongoing communication: Customers will receive regular updates, explanations of how the new system interacts with existing commitments, and support for planning and integration.
- Feedback loop: OpenAI will continue to incorporate customer input to refine technical and operational aspects of the privacy‑preserving safety approach.
Sources
Related
- Dispatch
- Dispatch
- Dispatch
- Dispatch
- Dispatch