OpenAI is previewing Private Safety Processing, a new safety architecture designed to identify misuse patterns across related API interactions without giving OpenAI personnel access to the underlying customer content. The system builds on the company's existing Zero Data Retention (ZDR) commitments, which promise that eligible enterprise customers' prompts and model responses are not retained after a request is processed and are not used for model training unless customers explicitly opt in.

Today's ZDR-compatible safety systems evaluate each interaction individually. Private Safety Processing extends those automated protections across multiple related interactions, allowing systems to detect coordinated probing, repeated safeguard testing, or emerging misalignment during agentic tasks — all while keeping customer content on infrastructure the customer controls or on OpenAI infrastructure encrypted with customer-controlled keys.

What's new

  • Cross-interaction safety signals: Automated systems can now identify patterns across related interactions without exposing prompts or responses to OpenAI personnel.
  • Two deployment models: Content remains on customer-controlled infrastructure (ZDR deployments) or on OpenAI infrastructure encrypted with customer-held keys; OpenAI does not hold a copy of those keys.
  • Narrow enforcement signals: When a risk is detected, OpenAI receives only a narrowly defined signal indicating the type of activity — similar to existing safety systems — not the underlying content.
  • Customer-controlled appeals: Customers investigate alerts using their own systems and choose whether to share relevant information with OpenAI for appeals or verified abuse investigations.
  • Timeline: Private Safety Processing is currently being tested with early customers; OpenAI plans to start rolling it out and publish a technical white paper in September.

Why it matters

As frontier models take on longer, more complex, and agentic tasks, the most serious safety risks — coordinated attacks, repeated probing, or gradual misalignment — often become visible only across multiple interactions. Until now, organizations with strict data sovereignty requirements (financial services, healthcare, defense, legal) faced a choice: accept data retention for safety monitoring or forgo advanced model capabilities. Private Safety Processing aims to remove that trade-off, letting enterprises keep ZDR guarantees while gaining cross-turn safety coverage.

Glean CISO Sunil Agrawal, quoted in the announcement, said enterprise AI adoption depends on customer control of data with no direct or derivative use beyond the chosen service, and that OpenAI's no-training commitment and ZDR give Glean confidence to build with OpenAI.

Our take

The preview signals that OpenAI recognizes ZDR alone is no longer sufficient for the safety posture enterprises now demand — cross-turn context is becoming table stakes. The real test will be whether the narrowly defined safety signals provide enough fidelity for effective enforcement without becoming a de facto content access channel, and whether the September white paper delivers the technical specificity security teams need for compliance audits.

Sources