The Current

OpenAI Previews 'Private Safety Processing' to Keep Zero Data Retention

The company says it can monitor for misuse across multiple interactions without giving its staff access to customer content.

useful policy · for smb · August 19, 2026

OpenAI announced on August 19, 2026 a preview of 'Private Safety Processing,' a system it says extends safety monitoring across related interactions while remaining compatible with its Zero Data Retention (ZDR) offering. According to OpenAI, ZDR gives eligible API customers a promise that the company does not retain prompts or model responses after a request is processed, that customer content is not available to OpenAI personnel for review, and that enterprise data is not used for training unless customers opt in. OpenAI states that existing ZDR-compatible safety systems evaluate each interaction individually, whereas some serious risks only become visible across multiple interactions, such as bad actors probing safeguards or agents continuing to act after being told to stop. Under the new approach, OpenAI says customer content can remain on customer-controlled infrastructure or on OpenAI infrastructure encrypted with keys the customer controls, with OpenAI personnel holding no copy of those keys. When a risk is identified, OpenAI says it receives 'a narrowly defined signal' indicating the type of activity, without access to the underlying content. The company cites Glean CISO Sunil Agrawal endorsing the commitment. OpenAI says the feature is being tested with early customers and plans a broader rollout and technical white paper in September.

  • Preview announced August 19, 2026, with rollout and a technical white paper planned for September
  • Content can stay on customer-controlled infrastructure or be encrypted with customer-held keys OpenAI cannot access
  • OpenAI says it receives only a narrow safety signal, not the underlying prompts or responses

What it means for you

If you use OpenAI's API and worried that stricter safety monitoring might force the company to keep or read your data, OpenAI is saying it can now watch for abuse patterns without its staff seeing your prompts or responses. In plain terms: it is trying to keep its 'we don't retain your data' promise intact even as it tightens misuse detection. For most casual users of ChatGPT this changes nothing — it applies to eligible business API customers.

Try this

If you handle sensitive data through OpenAI's API, ask your provider or account contact whether you qualify for Zero Data Retention and note that Private Safety Processing rolls out in September with a white paper to review.

Who should care

Businesses using OpenAI's API to handle regulated or confidential data — health records, financial data, legal or proprietary material — under data-retention or compliance obligations.

Skip this if

You use ChatGPT casually or through a consumer plan, or you don't send sensitive data through OpenAI's API. This is an enterprise-plumbing update with no consumer impact.