
OpenAI’s Private Safety Processing Extends Zero Data Retention

OpenAI is previewing Private Safety Processing, a new safety capability designed to keep the Zero Data Retention (ZDR) promise for frontier-model API customers while extending safety monitoring across multiple related interactions. Under ZDR, OpenAI retains neither prompts nor model responses after a request is processed; customer content is not available to OpenAI personnel for review, and enterprise customer data is not used for training unless customers explicitly opt in.
The premise is that serious safety risks are not always visible in a single interaction. Harmful intent may only become clear when several interactions are viewed together, when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research, or when an agentic task goes wrong—for example, a system keeps acting after being told to stop. Existing ZDR-compatible safety systems evaluate each interaction individually, so they cannot see these cross-interaction patterns. Private Safety Processing extends the automated protections already used in ZDR across related interactions, letting automated systems identify patterns without OpenAI personnel having access to the underlying content. The broader context is important for distinguishing legitimate activity from misuse and keeping AI agents within their intended authority.
Private Safety Processing utilizes customer content regardless of where it is stored—whether in infrastructure customers control (ZDR deployments) or in storage provided by OpenAI. For OpenAI-provided storage, content is encrypted with keys controlled by the customer; OpenAI personnel do not have a copy of those keys and cannot access the content. In both cases, automated systems can flag potential misuse and return a narrowly defined signal indicating the type of activity, similar to existing safety systems. That signal can be used to decide whether enforcement is necessary. Even when content is flagged, OpenAI personnel do not receive access to it. Customers can investigate alerts using their own systems and, if they wish, share relevant information with OpenAI to appeal, clarify legitimate activity, or support an investigation into verified abuse.
Private Safety Processing is currently being tested with early customers. OpenAI says the preview is a response to customer demand for predictability about how content will be protected as AI systems become more capable. The company also notes that some recent frontier-model deployments have required customers to allow the AI provider to retain sensitive content for safety monitoring, which conflicts with many organizations’ security obligations; Private Safety Processing is designed so OpenAI can continue offering ZDR in those cases.
The post emphasizes that the design is being shaped by customers across industries, regions, and company sizes, given that the organizations involved handle financial records, health data, confidential business plans, and proprietary research. OpenAI also states that no AI lab can address emerging risks alone. An endorsement from Sunil Agrawal, Chief Information Security Officer at Glean, says that enterprise AI adoption depends on customer control of data, and that OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. OpenAI plans to start rolling out Private Safety Processing and share a technical white paper in September.


