OpenAI is previewing a new privacy feature called Private Safety Processing that lets its safety systems flag risky patterns across multiple AI interactions without exposing the underlying content to company staff. The announcement extends the lab’s Zero Data Retention offering for API customers.
Under ZDR, OpenAI promises not to retain prompts or model responses after a request is processed. OpenAI staff cannot review customer content, and enterprise data enters model training only with an explicit customer opt-in. The catch was that some frontier deployments required providers to hold sensitive content so safety teams could monitor it, a conflict for banks, hospitals, and other regulated buyers.
Private Safety Processing aims to break that compromise. For ZDR setups, the content never leaves infrastructure under the customer’s control. Where OpenAI provides storage, the data is encrypted with keys held by the customer, and OpenAI personnel never receive those keys. Automated systems can return narrow signals about suspicious activity, such as repeated probing of safeguards or an agent continuing to act after being told to stop, without anyone reading the prompts.
OpenAI says the preview is being tested with early customers and will roll out in September alongside a technical white paper. Glean’s chief information security officer, Sunil Agrawal, backed the approach, saying enterprise AI adoption depends on customer control of data.