TL;DR: OpenAI has previewed Private Safety Processing, a mechanism that spots misuse patterns spanning several linked interactions while keeping its Zero Data Retention commitment intact. Rollout begins in September alongside a technical white paper, aimed squarely at customers whose security obligations rule out letting a provider retain sensitive content.
Under Zero Data Retention, eligible API customers get an undertaking that prompts and responses are discarded once a request completes, that staff cannot read them, and that enterprise data trains no models without an explicit opt-in. The difficulty is that today’s ZDR-compatible checks judge each exchange in isolation, and some of the more serious risks only become legible when several are viewed together — someone probing safeguards repeatedly, coordinating across accounts, dressing up a threat as research, or an agent that keeps acting after being told to stop.
Two storage arrangements are on offer. Content can stay on infrastructure the customer runs, or sit with OpenAI encrypted under keys the customer holds and OpenAI has no copy of. Either way, automated systems examine the material and emit a narrow signal describing the category of activity, which OpenAI uses to decide whether enforcement is warranted. Staff never see the underlying prompts, flagged or otherwise. Customers investigate alerts from their own logs and choose what, if anything, to share when appealing or supporting an abuse inquiry. One carve-out stands: material flagged as potential child sexual abuse imagery is still retained for review and legal reporting, as it is now.
The framing is a direct answer to a live objection. Some recent frontier deployments have made safety monitoring conditional on the provider keeping sensitive content — a condition that fails on contact with UK financial services procurement, NHS data governance and legal professional privilege alike. Resultsense reported this week on Southampton dropping Turnitin over training-data concerns; the underlying worry is the same one, arriving from the opposite direction.
Early testing is under way with named collaborators including Databricks, Microsoft and Abridge. Glean’s chief information security officer, Sunil Agrawal, argued that enterprise adoption turns entirely on customers controlling their data, with no derivative use beyond the service they bought.
Looking forward: The white paper due in September is the document worth waiting for. Until the signal taxonomy is public, buyers cannot judge how much a “narrowly defined signal” actually discloses about content the vendor has promised never to read.