OpenAI announced a new way to protect the data of business customers using its most advanced models. The proposal aims to uphold its commitment to Zero Data Retention, while adding security controls capable of detecting risks that only appear after several interactions.
What Zero Data Retention means
With Zero Data Retention (ZDR), eligible API customers receive a clear promise: OpenAI does not retain their messages or the model’s responses once the request has been processed. In addition, the content is not available for OpenAI staff to review.
Business customer data is also not used to train the models unless the organization explicitly authorizes it. For companies handling financial, medical, legal, or strategic information, this difference can be decisive.
The challenge? The security of an isolated interaction does not always tell the whole story.
Private Safety Processing analyzes context without revealing content
OpenAI is testing Private Safety Processing, a system designed to identify risk patterns across several related interactions. The tool aims to detect signals that could go unnoticed if each request were analyzed separately.
For example, someone might try to get around safety barriers through repeated queries, coordinate actions across multiple accounts, or present dangerous activity as routine research. Problems can also arise when an AI agent continues carrying out a task after the user has instructed it to stop.
Current ZDR-compatible systems evaluate each interaction individually. The new proposal expands that analysis to a set of interactions, but without giving OpenAI staff access to the original content.
The central idea is simple: improve safety without making customer privacy the price of entry.
How the data is protected
In ZDR implementations, customer content remains in infrastructure controlled by the organization itself. OpenAI is also developing an alternative for storing the information in its own infrastructure, but encrypting it with customer-managed keys.
In that second scenario, OpenAI would not have a copy of the keys. As a result, its employees could not access the underlying content, even if automated systems detected possible risky activity.
When a problem is identified, OpenAI would receive only a limited signal about the type of activity involved. That signal could be used to decide whether a measure needs to be applied, but it would not include the messages or responses that triggered the alert.
Customers could review alerts and compliance decisions from their own systems. If they believe legitimate activity was flagged by mistake, want to file an appeal, or need to collaborate on an investigation into confirmed abuse, they could voluntarily share the relevant information.
A response to business demands
Some recent deployments of advanced models have required customers to allow their providers to retain sensitive content in order to monitor safety. For many organizations, that condition conflicts with their regulatory obligations and the commitments they have made to their own users.
OpenAI’s proposal attempts to resolve that tension. Companies could retain greater control over their data while still allowing automated systems to look for signs of misuse in long, complex tasks.
This becomes especially important as models move beyond simply answering questions and begin operating as agents. An agent can plan, use tools, and carry out actions over a longer period. In that context, an apparently normal decision can take on a different meaning when viewed alongside everything that happened before.
The technology is still being tested
Private Safety Processing is currently being tested with early customers. OpenAI plans to begin rolling it out in September and publish a technical document with more details about how it works.
The company says it is working with organizations across different industries, regions, and sizes to define the system’s technical and operational aspects. The business users mentioned include Glean, which considers the commitment not to train models on customer data and ZDR to be important conditions for adopting AI.
As always, there is a difference between a privacy promise and its real-world implementation. Before incorporating these kinds of systems into critical processes, companies will need to review what data is stored, who controls the keys, what signals are generated, and how they can appeal an automated decision.
Even so, the announcement points in an important direction: AI safety does not have to depend exclusively on the provider being able to read its customers’ data. If this approach works as promised, organizations could gain more advanced controls without giving up control over their information.
Original source
https://openai.com/index/our-commitment-to-zero-data-retention
