OpenAI tests private safety for AI models
OpenAI is testing `Private Safety Processing`, a system designed to detect risks across multiple interactions without allowing its employees to read customer content. The feature is intended to preserve zero data retention for companies using AI models on long, complex tasks.

OpenAI is testing a system that can detect risk patterns across multiple conversations without accessing customer messages. The proposal aims to preserve zero data retention for organizations using its most advanced models on long, complex tasks.
The system is called Private Safety Processing and is being tested with initial customers. OpenAI expects to begin rolling it out and publish a technical paper in September.
What zero data retention means
Zero data retention, known as ZDR, gives certain API customers a specific guarantee: OpenAI does not retain their prompts or model responses once each request has been processed.
Company content is also not used to train the models unless the customer explicitly authorizes it. OpenAI employees cannot review those prompts and responses either.
Until now, ZDR-compatible safety systems have analyzed each interaction separately. That works when the risk is contained in a single request, but it falls short when the problem only becomes visible across a complete sequence.
The risk may be in the sequence
Someone may ask apparently normal questions and reveal harmful intent only after several interactions. They may also repeatedly test the model's limits, coordinate actions across multiple accounts, or present a threat as legitimate research.
The problem can also arise in tasks performed by AI agents. For example, an agent might continue acting after the user has told it to stop, or gradually drift away from the original intent.
Private Safety Processing aims to identify these patterns across related conversations using automated systems. OpenAI would receive only a limited signal about the type of activity detected, not the prompts or responses that generated it.
Where the data is stored
In a ZDR implementation, content can remain on infrastructure controlled by the customer. OpenAI is also developing an alternative that would store the data on its own infrastructure, encrypted with keys controlled by the customer.
OpenAI says its employees would not have a copy of those keys. As a result, they could not access the underlying content even if an automated system flagged it as potentially problematic.
Customers could investigate alerts and enforcement decisions using the information available in their own systems. If they need to appeal, clarify legitimate activity, or cooperate in an investigation into confirmed abuse, they could voluntarily share the relevant data.
What changes for businesses
Some recent deployments of advanced models have required organizations to allow the provider to retain sensitive content for safety monitoring. For sectors such as healthcare, finance, and research, that condition can conflict with their legal and security obligations.
OpenAI's proposal aims to resolve that tension: keep data under the customer's control while analyzing risk signals that are not always visible in a single request.
That does not mean privacy is absolute or that the system is already available to everyone. The feature is still being tested, and its technical and operational details remain under development.
For businesses, the key question will be how it works in practice: what signals it generates, what actions they can trigger, and how much control the customer retains over investigations. OpenAI says it will continue to report on changes and allow time to prepare deployments before expanding the system.