OpenAI is previewing a system called Private Safety Processing that is designed to detect risky patterns across multiple AI interactions without giving OpenAI personnel access to the underlying customer content. The company says the approach is being built to remain compatible with Zero Data Retention for eligible API customers.
That matters because stronger AI agents can create a tension between two enterprise requirements. Safety systems benefit from understanding behaviour across a sequence of interactions, while organisations handling sensitive information may be unable or unwilling to let an AI provider retain those prompts and responses for later review.
How the proposed system works
Under OpenAI's current Zero Data Retention controls, eligible API customers can have customer content excluded from abuse-monitoring logs, and compatible endpoints do not retain application state in the normal way. OpenAI's API documentation also makes clear that ZDR is not a blanket switch for every product and endpoint; some features that require stored state are not eligible.
Private Safety Processing is intended to add cross-interaction analysis without throwing away that privacy boundary. OpenAI says customer content can remain on infrastructure controlled by the customer. It is also developing an option where content is stored on OpenAI infrastructure but encrypted with keys controlled by the customer.
Automated systems can then identify patterns across related interactions and return a limited safety signal. OpenAI says its personnel would not receive the prompts or responses even when a risk is flagged. Customers would retain their own records and could choose what information to share if they wanted to appeal an enforcement decision or assist an investigation.
The important word is preview. Private Safety Processing is being tested with early customers, not announced as a generally available feature with a final technical specification.
ZDR still has boundaries
OpenAI describes Zero Data Retention as a promise for eligible API customers that prompts and model responses are not retained after processing. It also says enterprise customer data is not used to train its models unless a customer explicitly opts in.
The platform documentation is more precise about where that promise applies. ZDR requires approval, and certain API capabilities that need persistent application state remain ineligible. For example, features that deliberately store a response for later use cannot simultaneously promise that no state is retained.
There is also a legal exception in OpenAI's announcement for apparent child sexual abuse material. Images flagged for potential CSAM can still be retained for manual review and required reporting, including in ZDR deployments.
OpenAI says it plans to begin rolling out Private Safety Processing and publish a technical white paper in September. Until that arrives, customers should treat the announcement as architecture and direction rather than a replacement for the current endpoint-by-endpoint data-control documentation.
The useful signal is that OpenAI is trying to avoid making privacy and safety a binary choice for enterprise deployments. If the system works as described, cross-session safeguards could become stronger without creating a general-purpose archive of sensitive customer conversations that staff can inspect. The September technical material will be the point to look for details about threat models, guarantees, supported deployments and operational limitations.
Reporting notes