OpenAI announced this week that it will continue offering Zero Data Retention (ZDR) to eligible API customers even as its frontier models take on longer, more autonomous tasks, and it’s previewing a new mechanism called Private Safety Processing to make that promise technically sustainable.
The move lands at a moment when enterprise buyers are increasingly wary of AI vendors that demand broad data-retention rights in exchange for stronger abuse monitoring.
ZDR has long guaranteed that OpenAI does not retain prompts or responses after a request completes, and that customer content stays invisible to OpenAI staff and out of model training pipelines unless a customer opts.
OpenAI Launches Private Safety Processing
The catch is that existing ZDR-compatible safety tooling evaluates each interaction in isolation. That works for one-off chat exchanges, but it breaks down as models handle multi-step agentic work.
OpenAI points out that the most dangerous behaviors an agent that keeps acting after being told to stop, bad actors probing safeguards across multiple accounts, or threats disguised as legitimate research often only become visible when several interactions are analyzed together, not one at a time.
Some rival frontier-model deployments have reportedly required customers to allow providers to retain sensitive content just to enable this kind of longitudinal monitoring, a trade-off many regulated organizations can’t accept.
Private Safety Processing extends OpenAI’s existing automated safety checks across related interactions rather than judging each one in isolation, and it’s engineered so that OpenAI personnel never see the underlying prompts or responses. In a standard ZDR deployment, customer content stays entirely on infrastructure the customer controls.
OpenAI is also building a second option in which content sits in OpenAI-provided storage but is encrypted with keys that the customer alone holds; OpenAI staff have no copy of those keys.
When the automated system flags a pattern of potential misuse, OpenAI receives only a narrowly defined safety signal enough to decide whether enforcement action is warranted, but not the actual content.
Customers can investigate flagged activity using their own logs and can voluntarily share details with OpenAI if they want to appeal a decision or support an abuse investigation.
“What’s notable here isn’t the encryption scheme; key-holder architectures are well understood it’s that OpenAI is publicly conceding that per-session abuse detection can’t scale to agentic AI without either sacrificing privacy or sacrificing safety.
Private Safety Processing is OpenAI’s attempt to prove those two goals aren’t mutually exclusive, but until the September white paper details attestation and signal-leakage boundaries, enterprise security teams should treat this as a promising architecture, not a verified control,” says a threat-intelligence perspective on the rollout.
Crucially, Private Safety Processing is currently being tested only with select early customers, including Glean, Databricks, Abridge, and Microsoft, and it is not a self-service toggle.
OpenAI has not yet disclosed which customers or endpoints qualify for ZDR eligibility, nor has it published the technical specifics needed to independently verify claims regarding key custody, attestation, or signal leakage.
Glean CISO Sunil Agrawal offered a supportive read, saying OpenAI’s no-training commitment and ZDR give enterprises confidence to build on the platform even as capabilities grow.
OpenAI says it plans to begin rolling out Private Safety Processing and publish a technical white paper in September 2026, alongside continued engagement with customers on implementation details.
The announcement arrives alongside other OpenAI moves this week, including a reported temporary slowdown in scaling and a two-week pause in reinforcement learning that observers have linked to positioning ahead of a potential IPO, though OpenAI frames them purely as trust-building steps.
Security teams evaluating frontier-model vendors should watch the September disclosure closely before treating this preview as a settled control.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.