News

OpenAI previews Private Safety Processing to keep Zero Data Retention as Anthropic requires logs

OpenAI is previewing Private Safety Processing, a cross-session safety monitor that runs while prompts and responses stay under Zero Data Retention. The rollout and a technical white paper are planned for September. Anthropic still requires 30-day logs on its covered models.

OpenAI previews Private Safety Processing to keep Zero Data Retention as Anthropic requires logs

OpenAI wants to watch for abuse across many API conversations without keeping the conversations themselves. The preview is called Private Safety Processing, and it is meant to sit on top of Zero Data Retention.

The company laid it out in its own post. TechCrunch and Axios picked it up. The change is for eligible API customers. Consumer ChatGPT is not getting a new toggle.

Zero Data Retention already means OpenAI does not keep prompts or model responses after a request is processed. Personnel cannot pull that content for review, and enterprise data is not used to train models unless the customer opts in. Axios is explicit that Free, Plus, Go, and Pro stay as they are.

One carve-out sits under the retention promise. Images flagged as potential CSAM are still retained for review even under ZDR. That exception is not new, but it is the place where "we keep nothing" is not literally true.

The new piece is cross-session. Existing ZDR-compatible safety systems judge each interaction on its own, which means someone can spread a harmful task across many separate calls and stay under the per-request bar. Private Safety Processing is built to assess the inputs and outputs of multiple related conversations rather than one. TechCrunch describes that as long-horizon monitoring designed to catch patterns deliberately split across sessions.

OpenAI describes two storage arrangements for the content the system reasons over. In the first, content stays on customer-controlled infrastructure, the ZDR case. In the second, still in development, content sits on OpenAI infrastructure but is encrypted with keys the customer holds, and OpenAI says its own personnel do not have those keys.

When the automated review flags something, OpenAI says it receives only a "narrowly defined signal" naming the type of activity, not the underlying content. Staff still cannot open the conversation. If OpenAI decides enforcement may be warranted, it approaches the customer, and the customer may choose to share data at its own discretion to appeal or assist an investigation.

The rollout and a technical white paper are planned for September. Until that paper lands, the exact way the system inspects content across sessions without exposing it to staff is a claim, not a documented design.

OpenAI's own post names Glean, Databricks, Abridge, and Microsoft among the partners shaping the work, and quotes Glean's chief information security officer. Bloomberg, via The Next Web, separately names Microsoft and Databricks among the preview customers. Those are design partners, not proof the cryptography holds.

Anthropic still requires 30-day retention on its "covered models," the Mythos-class systems and future models with similar capabilities. Human review runs through a controlled access path, and a small set of approved reviewers write to a tamper-proof log. Anthropic has itself said the policy "will be unpopular with customers who have come to expect zero retention."

OpenAI's pitch is the mirror image: keep retention at zero and move the safety check to a signal that never carries the content. One vendor says meaningful safety monitoring on frontier models needs retained logs. The other says it can do the monitoring across sessions while retaining nothing legible to its own staff. The cross-session mechanism that would let anyone referee that fight is exactly what is not published until September.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free