OpenAI Previews Private Safety Processing to Strengthen AI Security Without Breaking Zero Data Retention
OpenAI is previewing Private Safety Processing, a system designed to detect risky patterns across AI interactions while keeping customer content protected under Zero Data Retention commitments.
Xcademia Team
Xcademia Research Team

Introduction
OpenAI is previewing Private Safety Processing, a new approach designed to strengthen safety monitoring for frontier AI models while maintaining its Zero Data Retention (ZDR) commitments for eligible API customers.
The company says the approach is intended to address a growing challenge in enterprise AI: increasingly capable models can perform longer and more complex tasks, but some potential misuse may only become visible when multiple interactions are considered together.
Under ZDR, OpenAI says eligible API customers receive a commitment that their prompts and model responses are not retained after a request is processed. Customer content is also not available to OpenAI personnel for review, and enterprise customer data is not used to train OpenAI models unless customers explicitly opt in.
Why OpenAI Says AI Safety Needs More Context
Traditional safety systems that are compatible with ZDR can evaluate individual interactions. OpenAI says this can become more challenging as AI systems take on longer workflows and more autonomous tasks.
A potentially harmful intention may not be obvious in a single request. Instead, it could emerge through a series of interactions.
OpenAI identifies several scenarios where broader context can matter, including repeated attempts to probe safeguards, activity coordinated across accounts, and threats disguised as legitimate research.
The company also points to agentic tasks as another challenge. An AI system may continue performing actions after a user has instructed it to stop, creating a situation where the wider sequence of interactions is important for understanding what happened.
The announcement therefore focuses on a central tension in enterprise AI: safety systems may need more context, while organisations increasingly require strict controls over sensitive data.

How Private Safety Processing Works
Private Safety Processing builds on automated protections already used in ZDR-compatible deployments.
Instead of evaluating interactions only in isolation, the system is designed to identify patterns across related interactions.
A key part of the approach is the separation between customer content and safety signals.
OpenAI says customer content can remain on infrastructure controlled by the customer in ZDR deployments. The company is also developing an option where content can be stored on OpenAI infrastructure while remaining encrypted with keys controlled by the customer.
According to OpenAI, its personnel do not have copies of customer-controlled encryption keys in that model and therefore cannot access the underlying content.
When the automated system identifies potential risk, OpenAI receives a narrowly defined signal describing the type of activity involved.
The signal can then be used to determine whether enforcement is necessary.
Importantly, OpenAI says its personnel do not receive access to the customer content even when activity is flagged.

What OpenAI Personnel Can See
The announcement draws a clear distinction between the information used for automated safety processing and the underlying customer content.
If a potential risk is identified, OpenAI says it receives a limited signal rather than the customer's prompts or responses.
This means the safety system can potentially indicate that a particular type of activity has been detected without exposing the underlying content to OpenAI personnel.
Customers can investigate alerts and enforcement decisions using information available within their own systems.
If an organisation believes activity was legitimate, wants to appeal an enforcement decision, or needs to support an investigation into verified abuse, it can choose to share relevant information with OpenAI.
This preserves customer control over when additional information is disclosed.
Two Storage Models
OpenAI describes two approaches associated with Private Safety Processing.
Customer-Controlled Infrastructure
For ZDR deployments, customer content remains on infrastructure controlled by the customer.
The safety system can still process relevant information to identify potential misuse while keeping the underlying content within the customer's environment.
OpenAI-Provided Storage
OpenAI is also developing an option where customer content can be stored on OpenAI infrastructure.
In this model, the content is encrypted using keys controlled by the customer. OpenAI says its personnel do not possess copies of those keys, preventing them from accessing the underlying content.
Additional details were not disclosed in the announcement about the full technical implementation of this storage option.

Designed for Sensitive Enterprise Data
OpenAI says the approach is being shaped with customers across different industries, regions, and organisation sizes.
The company highlights organisations handling sensitive information such as financial records, health data, confidential business plans, and proprietary research.
For these organisations, data protection can be connected to regulatory obligations, customer trust and protection of proprietary information.
The announcement includes comments from representatives of Glean, alongside references to Databricks, Abridge and Microsoft as organisations involved in the broader customer collaboration.
Glean's Chief Information Security Officer, Sunil Agrawal, said enterprise AI adoption depends on customer control of data and highlighted OpenAI's no-training commitment and ZDR approach.
The company did not provide additional technical details about the specific implementation of Private Safety Processing at each named organisation.
Private Safety Processing Is Still Being Tested
Private Safety Processing is currently being tested with early customers.
OpenAI says it plans to begin rolling out the technology and publish a technical white paper in September.
The company says it will continue working with customers on the technical and operational details and intends to provide updates about how the approach affects existing commitments.
Additional details were not disclosed in the announcement about the final rollout schedule, availability across specific API products, or the complete technical specifications of the system.
What This Could Mean for Enterprise AI
The following section is analysis based on the announcement, not a statement of additional OpenAI product commitments.
The development highlights a broader industry shift toward building AI safety systems that can operate alongside stricter enterprise data controls.
As AI applications become capable of handling longer workflows, evaluating each interaction independently can make it harder to identify patterns that emerge over time. Organisations therefore face a difficult balance between providing safety systems with sufficient context and limiting access to sensitive information.
Private Safety Processing represents an attempt to separate these two requirements.
The basic model is straightforward: automated systems can analyse relevant activity, while the organisation maintains control over the underlying content and decides whether additional information should be shared.
For enterprises, this could make privacy architecture an increasingly important part of AI safety design rather than a separate compliance consideration.
It also reflects growing demand for AI systems that can support security monitoring without requiring providers to gain broad visibility into customer data.
However, the announcement is a preview, and important implementation details remain to be clarified. The upcoming technical white paper should provide a better basis for evaluating how the system operates in practice.
The Bigger Enterprise AI Security Picture
The announcement illustrates a broader challenge facing frontier AI providers.
More capable models can perform increasingly complicated tasks, which can create more complex safety scenarios. At the same time, enterprise customers are handling information that may be subject to contractual, regulatory and internal security requirements.
A safety architecture that requires unrestricted provider access to customer content may not be suitable for every organisation.
OpenAI's proposed approach attempts to address this by separating three areas:
Customer content, which remains protected and controlled by the customer.
Automated safety processing, which analyses activity for potential misuse.
Limited safety signals, which can be used for enforcement without exposing the underlying content to OpenAI personnel.
Whether this model can provide the required safety coverage while maintaining strict privacy controls will become clearer as testing progresses and more technical information is published.
What Happens Next
OpenAI says Private Safety Processing is currently being tested with early customers.
The company plans to begin rolling out the approach and publish a technical white paper in September.
Until more implementation details are released, organisations evaluating the technology will need to distinguish between the commitments already described for eligible ZDR customers and the capabilities that remain under development.
The announcement nevertheless signals an important direction for enterprise AI: safety monitoring and data privacy do not necessarily have to be treated as mutually exclusive design goals.
Source: OpenAI
About the Author