OpenAI has previewed Private Safety Processing, a system that keeps zero data retention (ZDR) intact for enterprise customers while still catching misuse. Instead of judging one exchange at a time, it looks for dangerous patterns spread across several related interactions, and the company says nobody on its staff can read what sits underneath. The rollout is set for September 2026, alongside a technical white paper.

What a single exchange misses

Today's ZDR-compatible safety systems evaluate each interaction on its own. OpenAI argues that this is where the limit lies: the most serious risks rarely announce themselves in one request.

The patterns it wants to catch include probing safeguards repeatedly to find a gap, splitting the same goal across several accounts, and dressing harmful intent up as ordinary research. There is also a failure mode specific to agents, where a system drifts away from the user's intent and keeps acting even after being told to stop.

OpenAI's product policy lead offered reporters a worked example. In one conversation, someone asks about a weakness in a company's software. In another, the same person asks about remote access and about which security tools would notice it. Read separately, each looks like normal research. Read together, they start to look like preparation for a cyber attack. A per-request check has no way to line them up.

Held, but never read

So how do you judge across sessions without looking inside them? That is the substance of the announcement.

In a ZDR deployment, customer content stays on infrastructure the customer controls. OpenAI is preparing a second option as well: the content sits on OpenAI infrastructure, encrypted with keys only the customer holds. OpenAI staff hold no copy of those keys, so the data is there but closed.

The judging itself is automated. When something fires, what reaches OpenAI is a narrowly defined signal naming the category of activity, with no prompts or responses attached. OpenAI then decides whether to act, and its people still cannot open the content. Customers investigate alerts inside their own systems, and may hand material over voluntarily to appeal a decision or to support an abuse investigation.

Anthropic landed on the opposite answer

Faced with the same problem, Anthropic reached the reverse conclusion. It now requires 30-day retention of prompts and outputs on its most capable models, with no carve-outs for customers whose contracts assumed zero retention.

Anthropic has acknowledged that the policy is unwelcome, while arguing that retention is essential to catch attacks that stretch across multiple requests. The company is expected to offer an option later this year that lets enterprises keep that data on their own cloud instead.

Both firms read the problem the same way: dangerous behaviour shows up in the relationship between requests rather than inside any one of them. They differ on the remedy. Anthropic wants to find it by keeping the data; OpenAI wants to find it without keeping the data. Which premise a company can live with will depend heavily on the kind of data it handles.

Who it covers, and who it does not

Private Safety Processing is aimed at eligible enterprise and API customers. It does not extend to consumer ChatGPT. Data settings for Free, Plus, Go and Pro users are unchanged, and ZDR was never part of those tiers to begin with.

One exception is spelled out in a footnote to the announcement. US law requires OpenAI to report apparent child sexual abuse material, so images flagged as potential CSAM are retained for human review and reporting even in zero data retention deployments, exactly as they are today.

Testing is running with early customers, and Glean and Abridge are named among the companies that shaped the work. Glean's chief information security officer said the no-training commitment and ZDR are what give the firm confidence to build on OpenAI's models. Microsoft and Databricks have been reported as part of the test group.

The proof arrives in September

What is public so far is the position and the outline; the technical detail is not out yet. The claim that a system can trace relationships across interactions while nobody at OpenAI reads them is one that cannot be checked until the September white paper lands.

European buyers have a practical reason to read it closely. Provider-side retention is hard to sign off under GDPR and under the sectoral rules covering health and financial records, and that is precisely the category of data OpenAI says its customers work with. The recent crop of European startups selling control over where AI data sits is the flip side of the same pressure.

The preview also closes out a month of safety-side activity at OpenAI. Earlier in August the company said it had paused part of the development of its next model over the possibility of critical cyber risk. The stricter the risk assessment, the sharper the question of what has to be observed to run it. Private Safety Processing is an attempt to answer that question with as little observation as possible.

Summary

OpenAI will begin offering Private Safety Processing in September 2026, a system that detects misuse across multiple interactions while preserving zero data retention. Detection is automated, and what reaches OpenAI is a signal naming the category of activity rather than the prompts or responses themselves. A second option will place content on OpenAI infrastructure under customer-held encryption keys. The approach stands opposite Anthropic's mandatory 30-day retention, and its real effectiveness cannot be judged until the white paper arrives in the same month.