Safety

AI-generated text

OpenAI previews Private Safety Processing to enable cross-interaction safety while preserving Zero Data Retention

OpenAI announced Private Safety Processing, a system that can detect patterns of misuse across related interactions without giving OpenAI staff access to customers' underlying prompts or responses.

OpenAI previews Private Safety Processing to enable cross-interaction safety while preserving Zero Data Retention

OpenAI has announced a preview of Private Safety Processing (PSP), a system intended to detect patterns across related interactions while preventing OpenAI personnel from accessing the underlying customer content. The company says the feature is compatible with Zero Data Retention (ZDR) deployments.

What is Zero Data Retention (ZDR)?

Under Zero Data Retention, eligible API customers receive a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. According to OpenAI, customer content is not available to OpenAI staff for review, and enterprise customer data is not used to train models unless the customer explicitly opts in.

Why cross-interaction context matters for safety

OpenAI argues that the most serious AI safety risks often cannot be seen from a single interaction. Harmful intentions or misuse can become apparent only when multiple interactions are considered together — for example, when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Similar risks may emerge over the course of an agentic task, for instance if a system continues to act after being instructed to stop.

As AI systems handle longer and more complex tasks, that broader context becomes increasingly important to distinguish legitimate activity from misuse and to ensure agents stay within their intended authority.

How Private Safety Processing works

Private Safety Processing builds on automated protections already used in ZDR and other deployments. While existing ZDR-compatible systems evaluate interactions individually, PSP extends protections across related interactions so automated systems can detect patterns without OpenAI personnel having access to retained customer content. The approach works with both storage models:

  • In ZDR deployments, customer content remains on infrastructure controlled by the customer.
  • When customers choose OpenAI-provided storage, content is encrypted with keys controlled by the customer; OpenAI personnel do not hold copies of those keys and therefore cannot access the raw content.

Automated systems can identify potential misuse and send a narrowly defined safety signal to OpenAI indicating the type of activity involved, without exposing the underlying prompts or responses. That signal can be used to decide whether enforcement action is needed, while OpenAI staff still do not receive the customer content.

Customer investigation and cooperation

Customers can investigate alerts and enforcement decisions using information available in their own systems. If they wish to appeal, clarify legitimate activity, or assist an investigation into verified abuse, they may choose to share relevant information with OpenAI.

Testing, feedback, and planned rollout

Private Safety Processing is currently being tested with early customers. OpenAI says it is sharing this preview because customers have made clear they need predictability about how their content will be protected as AI systems become more capable.

OpenAI plans to begin rolling out Private Safety Processing and to publish a technical white paper in September. The company says it will keep customers informed throughout the process, explaining implications for existing commitments and providing time and support to plan ahead.

Legal obligations and exceptions

OpenAI notes that, like other frontier model providers, it is legally required to report apparent child sexual abuse material (CSAM). Images flagged as potential CSAM will continue to be retained for manual review and reporting purposes even in Zero Data Retention deployments, as they are today.

Customer quote

“Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.”

— Sunil Agrawal, Chief Information Security Officer, Glean

Conclusion

Private Safety Processing aims to enable automated detection of multi-interaction risk patterns without granting OpenAI staff access to customer content, preserving the commitments of Zero Data Retention. OpenAI says it will continue to refine technical and operational details in collaboration with customers and partners.