The Current

OpenAI Previews 'Private Safety Processing' to Keep Zero Data Retention Intact

The company says it can monitor for misuse across multiple interactions without exposing customer content to its staff.

useful policy · for smb · August 20, 2026

OpenAI announced on August 19, 2026 a preview of what it calls Private Safety Processing, a system designed to strengthen safety monitoring for API customers while preserving its Zero Data Retention (ZDR) offering. Under ZDR, OpenAI says it does not retain a customer's prompts or model responses after a request is processed, personnel cannot review that content, and enterprise data is not used for training unless a customer opts in. According to OpenAI, existing ZDR-compatible safety systems evaluate each interaction individually, but some risks only become visible across multiple related interactions—such as bad actors probing safeguards, coordinating across accounts, or agents continuing to act after being told to stop. Private Safety Processing is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content. Content remains either on infrastructure the customer controls or, in a developing option, on OpenAI infrastructure encrypted with customer-controlled keys that OpenAI staff do not hold. When a risk is flagged, OpenAI says it receives a narrowly defined signal about the type of activity, not the content itself. OpenAI quoted Glean CISO Sunil Agrawal supporting the approach. The company said it is testing with early customers and plans to begin rolling out the feature and publish a technical white paper in September.

  • Announced August 19, 2026; rollout and technical white paper planned for September
  • ZDR customers' content stays on customer-controlled infrastructure or is encrypted with customer-held keys
  • OpenAI says it receives only a narrow safety signal when risk is flagged, not the underlying content
  • Currently being tested with early customers

What it means for you

If you or your business uses OpenAI's API (the developer connection, not the regular ChatGPT app) under a Zero Data Retention agreement, this is OpenAI saying it can keep that no-retention promise even as it adds more safety monitoring. In plain terms: they want to catch misuse patterns across many requests without any human at OpenAI reading your actual data. It's a preview, not a shipped feature.

Try this

If you handle sensitive data through the OpenAI API, ask your provider or account contact whether you're on ZDR and how Private Safety Processing will apply to you when it rolls out in September.

Who should care

Businesses building on the OpenAI API that handle regulated or confidential data—financial, health, legal, or proprietary research—especially those already on a Zero Data Retention agreement.

Skip this if

You only use ChatGPT through the app or website, or you don't run your own applications on OpenAI's API. This is an enterprise API detail and doesn't change anything for everyday users.