Private Safety Processing is intended to address that problem by evaluating patterns across related interactions. OpenAI describes the technology as a form of longer-horizon monitoring that can analyze inputs and outputs across sessions through an automated system rather than relying on employees to inspect the underlying conversations.
When the system identifies potential misuse, it can provide OpenAI with a limited indication of the type of activity detected. The company describes this as a “narrowly defined signal,” which can then inform a decision about whether enforcement is warranted. OpenAI may contact the customer for additional context, while the customer can decide whether to provide the company with further data.
The architecture is designed to separate safety monitoring from access to customer content. In ZDR deployments, the underlying information can remain on infrastructure controlled by the customer. OpenAI is also developing an alternative configuration in which encrypted content could reside on its infrastructure while the customer retains the encryption keys. Under that arrangement, OpenAI would not hold those keys.
The approach creates a notable distinction between OpenAI and Anthropic as both companies confront the problem of detecting harmful activity that unfolds over multiple requests. Anthropic retains prompts and outputs for 30 days when customers use its Covered Models, including organizations that had previously operated under Zero Data Retention. Anthropic says the retention period allows its safeguards to identify attacks or misuse that may only become apparent after examining multiple interactions.
Anthropic also permits human review of customer information in certain circumstances. The company says access occurs “through a controlled access path” involving “a small set of approved reviewers,” with review sessions recorded in a system reviewers cannot alter or suppress.
OpenAI is pursuing the same broader objective without requiring eligible customers to surrender ZDR. That distinction could matter for organizations that adopted zero-retention arrangements specifically to minimize the amount of sensitive information held by an AI provider.
Private Safety Processing remains at an early stage, however. OpenAI has not yet publicly shown whether the system can match the abuse-detection capabilities of approaches that retain customer content, and further technical details about its privacy architecture have yet to be released.
Zero Data Retention also has an exception for certain safety and legal obligations. OpenAI says images identified as potential child sexual abuse material may be retained when manual review and reporting are legally required.
OpenAI plans to begin rolling out Private Safety Processing and release a technical white paper in September. The additional documentation should provide customers with more detail about how the company intends to identify misuse spanning multiple interactions while preserving the data-retention protections available through ZDR.
This analysis is based on reporting from digitaltrends.
Images courtesy of gizmodo.
This article was generated with AI assistance and reviewed for accuracy and quality.