OpenAI says it is preparing a system that can look for harmful patterns across a customer's related AI interactions without giving the company's personnel access to the underlying prompts or responses. The proposal is aimed at a real tension in enterprise AI: safety monitoring often benefits from context across time, while regulated customers may be unable to let a provider retain that context.

The company calls the system Private Safety Processing. In its 19 August announcement, OpenAI described it as a preview being tested with early customers—not a generally available product and not yet a technical standard that outsiders can independently evaluate. A white paper and the start of rollout are promised for September.

Zero Data Retention, or ZDR, is available to eligible API customers. OpenAI says prompts and model responses are not kept after a request is processed, are not available to its personnel for review, and are not used for model training unless an enterprise customer opts in. The company argues that this request-by-request approach becomes less adequate as agents perform longer tasks and as misuse may only become visible across several interactions.

What the proposed system would do

Under the design OpenAI outlined, customer content can stay on infrastructure controlled by the customer. The company is also developing an option to store encrypted content on OpenAI infrastructure with keys controlled by the customer. Automated systems would analyse related activity and return a narrowly defined risk signal, while OpenAI personnel would not receive the content itself—even when the system flags an interaction.

Customers would investigate alerts using records in their own systems. If they wanted to appeal an enforcement decision or help investigate verified abuse, they could choose to disclose the relevant material. This division is meant to keep the provider from routinely seeing sensitive health, financial, legal or proprietary data.

There is an important exception. OpenAI says images flagged as possible child sexual abuse material will continue to be retained for manual review and legally required reporting, including in ZDR deployments. The broader claim is therefore zero retention for ordinary prompt and response data, not an absolute promise covering every category of content under every legal obligation.

What the announcement does not establish

The post does not provide the architecture, threat model, false-positive rate, audit method or key-management details needed for an independent security assessment. It also does not say which frontier models or customer configurations will be eligible at launch. Until the technical paper and product terms arrive, claims about privacy and safety performance remain company claims.

For enterprise buyers, the useful questions are concrete: Who controls the encryption keys? What metadata survives a request? What exact signal reaches the provider? How are enforcement errors appealed? Can the design be audited? Private Safety Processing could be a meaningful way to reconcile monitoring with confidentiality, but the August announcement is the beginning of that case, not its conclusion.

Primary record

Reporting note

This article was reported from the linked public records. Company and institutional claims are attributed; Qstage's interpretation is stated separately.