OpenAI has launched a preview version of 'Private Safety Processing,' which enhances safety monitoring while maintaining zero data retention.



On August 19, 2026, local time, OpenAI released a preview version of ' Private Safety Processing ,' which enhances security monitoring while maintaining its ' Zero Data Retention (ZDR) ' policy of not retaining user prompts or AI responses.

Offering Zero Data Retention for frontier models | OpenAI
https://openai.com/index/offering-zero-data-retention-for-frontier-models/

ZDR is a policy to protect user data by explicitly promising eligible API customers that OpenAI will not retain prompts or model responses after processing requests. With ZDR, customer content will not be available for review by OpenAI personnel, and enterprise customer data will not be used to train AI models unless the customer explicitly opts in.

While existing ZDRs evaluated each interaction individually, OpenAI has announced 'Private Safety Processing,' a new safety monitoring system that allows them to identify patterns across all related interactions without accessing the underlying content. A preview version of Private Safety Processing will also be released.




With ZDR in place, customer content will be stored on infrastructure managed by the customer. We are also developing an option to store customer-encrypted content on OpenAI's infrastructure. In either case, the automated system will be able to identify potential misuse and return limited security signals without disclosing prompts or responses not based on OpenAI personnel.

The newly introduced Private Safety Processing is a system built on the automated protection features used in ZDR and other deployments. While existing ZDR evaluates individual interactions, Private Safety Processing extends these protection features to the entire related interaction, allowing the automated system to identify patterns without OpenAI personnel having access to customer content.

Private Safety Processing allows access to customer content regardless of where it is stored, whether it is on customer-managed infrastructure or storage provided by OpenAI. If the content is stored on OpenAI's storage, it is encrypted using keys managed by the customer. However, OpenAI personnel do not possess copies of these keys and therefore cannot access the user's content.

Once a risk is identified, OpenAI receives a limited signal indicating the type of activity involved, similar to its operational security systems. This signal is used to determine whether legal action is required. Even if a risk is detected, OpenAI personnel will not be able to access customer content.

Customers can use information available in their own systems to investigate alerts and enforcement decisions. They can also choose to share relevant information with OpenAI if they wish to appeal, clarify legitimate activities, or assist in investigations into verified fraudulent activity.

OpenAI explains, 'Private Safety Processing is currently being tested with early customers. As the performance of our AI system improves, we have received strong feedback from customers who want more predictability about how their content will be protected, so we have decided to release a preview version.'




in AI,   Security, Posted by logu_ii