
OpenAI announced in a blog post today (August 20) that it is expanding its Zero Data Retention service to eligible frontier model API customers. Automated systems can identify risk patterns across interactions.
According to the blog post cited by IT Home, OpenAI emphasized that it does not retain prompts or model responses after request processing is complete. Employees cannot review customer content, and enterprise data is not used to train models unless customers explicitly opt in.
OpenAI noted that as models take on longer and more complex tasks, some serious security risks may not emerge until after multiple rounds of interaction. Existing security systems compatible with ZDR generally evaluate interactions individually, making it difficult to identify behavioral patterns spanning conversations or accounts, or involving persistent attempts to probe security mechanisms.
To address this issue, OpenAI is introducing Private Safety Processing as a preview. The mechanism uses automated systems to analyze risk patterns in related interactions without allowing OpenAI employees to access the underlying content.

The system applies to content in infrastructure controlled by customers themselves, as well as content stored by OpenAI. In the latter case, customer content is encrypted with customer-controlled keys. OpenAI employees do not possess these keys and therefore cannot access the underlying prompts and responses.
When the system identifies a risk, OpenAI receives only limited security signals describing the type of activity involved, which it uses to determine whether any action is necessary.
Even when content is flagged, employees still cannot view customer content. Customers can investigate alerts and make response decisions through their own systems. If they need to appeal, explain legitimate activity, or assist in verifying confirmed abuse, they may choose to provide relevant information to OpenAI.
OpenAI said that Private Safety Processing is currently being tested with early customers. The company plans to begin rolling out the capability in September and publish a technical white paper. OpenAI said it will subsequently inform customers in advance about updates, their impact on existing commitments, and the time and support needed for customer planning.
