Skip to content
major Security verified update

OpenAI clarifies Private Safety Processing: automated abuse detection across conversations without retaining data

confirmed by 2 independent sources updated August 20, 2026

OpenAI clarified that Private Safety Processing automatically detects AI misuse across multiple conversations without human review and without retaining data. The system extends Zero Data Retention and contrasts with the 30-day data retention at Anthropic; a white paper is due to be released in September.

OpenAI clarified how Private Safety Processing works, a system running in preview for selected API customers. According to the company, the system automatically detects misuse of AI models across multiple related conversations at once, rather than only within a single session as the existing Zero Data Retention (ZDR) does. Monitoring takes place without human review of conversation content — if the system detects suspicious activity, it sends OpenAI only a narrowly defined signal about the type and severity of the activity, without giving the company access to the actual inputs or outputs. According to the company, this also makes it possible to detect distributed attempts at misuse, where a user splits harmful requests (such as malware development) across multiple sessions to evade detection within a single conversation. If the signal indicates that intervention is needed, OpenAI contacts the customer to request additional context; the customer can then share data at their own discretion. According to OpenAI, a technical white paper on the system is due to be released in September.

OpenAI also reaffirmed that the Zero Data Retention policy remains in effect for eligible API customers using frontier models. ZDR operates through automated agents that monitor abuse within a single session without retaining customer data; Private Safety Processing extends this principle to analysis across multiple conversations. According to the company, customer data remains on their own infrastructure or is stored in encrypted form, with the customer holding the keys. Aleah Houze, head of product policy at OpenAI, said that risks often become apparent only over the course of multiple conversations.

The approach taken by OpenAI contrasts with the policy at Anthropic, which retains customer data for 30 days for safety review for so-called “covered models” — including models in the Mythos series and future models with similar capabilities. This policy was announced in July and raised concerns among some customers working with sensitive data. Anthropic also states that human review of data is possible only through controlled access involving a small number of approved reviewers and that each such session is recorded in an immutable log; for other models, Anthropic largely adheres to ZDR.

What changed

Why it matters

For companies weighing OpenAI and Anthropic products for working with sensitive customer data, this provides a more concrete comparison of approaches to safety and privacy: automated detection without retaining data at OpenAI versus 30-day retention for selected Anthropic models. The choice affects how companies set up compliance for applications built on these APIs, especially in regulated industries. The forthcoming white paper is expected to clarify the technical details.

What was added since the original report

Verified updates

  1. New verified information

    Private Safety Processing specifically monitors the detection of AI model misuse, not just safety testing; The system extends Zero Data Retention with the ability to analyze multiple conversations at once; Monitoring is fully automated without human review of conversation content; Direct competitive comparison with the policy at Anthropic – 30-day data retention; The technology uses 'narrowly defined signals' for enforcement without direct access to data

    • Private Safety Processing specifically monitors the detection of AI model misuse, not just safety testing
    • The system extends Zero Data Retention with the ability to analyze multiple conversations at once
    • Monitoring is fully automated without human review of conversation content
    • Direct competitive comparison with the policy at Anthropic – 30-day data retention
    • The technology uses 'narrowly defined signals' for enforcement without direct access to data

Relevant practical impact

What this means

01

For a business

Companies choosing an API provider for working with sensitive data now have a more concrete comparison: OpenAI offers automated abuse detection across multiple conversations without retaining data, while Anthropic retains data for 30 days for safety review for selected models.

Risks and compliance
What to decide Companies considering OpenAI or Anthropic APIs for processing sensitive data can compare their retention and abuse monitoring policies and wait for the technical white paper on Private Safety Processing, which is due to be released in September.
More business impacts →
AI safety API security AI safety compliance data retention abuse detection enterprise OpenAI privacy Private Safety Processing

Check the original

Event sources

confirmed by 2 independent sources · 3 publishers, 2 independent. We count feeds from the same owner only once.

3
OpenAI News primary source · first detected Offering Zero Data Retention for frontier models TechCrunch AI independent context OpenAI seeks to one-up Anthropic with new customer privacy protections The Decoder (daily AI news) independent context OpenAI builds safety system that catches misuse without storing customer data