Artificial Intelligence
Written by: Neelakshi Chakraborty, Reporter, CDO Magazine
Updated 6:23 AM EDT, August 25, 2026

Photo credit: Unsplash.com
OpenAI is previewing Private Safety Processing, a new approach intended to help eligible API customers maintain Zero Data Retention protections while enabling automated safety systems to detect risks across related interactions.
Zero Data Retention gives eligible API customers a commitment that OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train OpenAI models unless customers explicitly opt in.
Safety Monitoring Across Interactions
OpenAI said existing ZDR-compatible safety systems evaluate each interaction individually. Private Safety Processing is designed to extend those protections across related interactions, allowing automated systems to identify patterns without giving OpenAI personnel access to retained customer content.
The company said some serious AI safety risks may become visible only across multiple interactions. These include repeated attempts to probe safeguards, coordination across accounts, disguised threats, or risks that emerge during an agentic task, such as a system continuing to act after being told to stop.
Customer-Controlled Content
For ZDR deployments, customer content remains on infrastructure the customer controls. OpenAI is also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. OpenAI said its personnel do not have a copy of those keys and cannot access the underlying content.
When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved. The company said this signal can be used to determine whether enforcement is necessary, but OpenAI personnel do not receive access to customer content even when it is flagged.
Why It Matters
OpenAI said some recent frontier-model deployments have required customers to allow AI providers to retain sensitive content for safety monitoring. For many organizations, the company said, such requirements can conflict with security obligations or commitments to the people they serve.
Private Safety Processing is currently being tested with early customers. OpenAI said it plans to begin rolling it out and share a technical white paper in September.
OpenAI said it will continue working with customers on the technical and operational details of the approach. The company said customer feedback is helping it build stronger safeguards while keeping information under customer control.
Industry leaders have welcomed the move. Sunil Agrawal, Chief Information Security Officer at Glean, emphasized the importance of data sovereignty for enterprise tools:
“Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.”