OpenAI Previews Private Safety Processing for Zero Data Retention
In brief
- Private Safety Processing detects misuse across interactions without exposing customer prompts or responses to OpenAI personnel.
- Zero Data Retention customers' content stays on their infrastructure or encrypted with keys they control.
- System identifies potential misuse via limited signals describing severity and category, not underlying content.
- Rollout begins in September with technical white paper to follow.
How Private Safety Processing Works
Private Safety Processing expands existing safeguards by allowing automated systems to identify potentially harmful patterns across related interactions rather than evaluating each request in isolation. The system is intended to address risks that may only become apparent across multiple interactions, including repeated attempts to bypass safeguards and coordinated misuse across accounts.
When the system identifies potential misuse, OpenAI receives a limited signal describing the category and severity of the activity, but underlying prompts and responses are not shared with OpenAI personnel. This design keeps customer content protected while enabling safety monitoring.
Data Retention and Encryption Options
Under Zero Data Retention, OpenAI does not retain eligible customers' prompts or model responses after a request is processed. For these deployments, customer content remains on infrastructure controlled by the customer.
OpenAI is also developing an option where content can be stored on its infrastructure while encrypted with keys controlled by the customer. OpenAI personnel would not have access to those encryption keys or the underlying customer content. This hybrid approach gives enterprises flexibility in how they manage data residency and security.
Rollout and Enterprise Privacy
Enterprise customer data is not used to train OpenAI models unless customers explicitly opt in. Private Safety Processing is currently being tested with early customers.
OpenAI plans to begin rolling it out in September and publish a technical white paper detailing the system. The preview reflects growing pressure on AI providers to balance safety monitoring with customer privacy, especially as autonomous systems and multi-turn interactions become more common in enterprise deployments.


