OpenAI is previewing a way to keep zero data retention and still get cross-conversation safety monitoring, closing the trade-off that has kept regulated industries stuck in pilot mode.
Ask a CISO at a bank or hospital system what has kept frontier AI models out of anything touching real customer data, and you will hear some version of the same standoff. Zero data retention or safety monitoring, pick one. Get a promise that your AI vendor never even looks at your prompts, and you lose the pattern detection that catches someone probing your systems across a dozen separate conversations. Get that protection, and you have just agreed to let the vendor hold onto the sensitive records you were trying to keep off their servers in the first place. That forced choice has kept whole regulated industries confined to low-stakes pilots instead of production use. OpenAI says it has found a way around it.
What changed
OpenAI announced on August 19 that it is previewing a system called Private Safety Processing, built to work alongside the Zero Data Retention (ZDR) terms it already offers eligible API customers. ZDR already means OpenAI does not retain a customer's prompts or responses after a request finishes, and that data is never used for training unless the customer opts in. The gap OpenAI is trying to close is that existing ZDR-compatible safety checks only ever look at one interaction at a time, which misses risks that only show up when you connect several interactions together, like someone asking about a company's software vulnerabilities in one conversation and remote access tools in another.
Private Safety Processing runs automated pattern detection across those related interactions without giving OpenAI's own staff access to the underlying content. Customer data stays either on infrastructure the customer controls, or on OpenAI's infrastructure encrypted with keys the customer holds, so OpenAI itself cannot read it. When the system flags something, OpenAI receives only a narrow signal describing the type of activity involved, not the actual prompts or responses. Customers can investigate the flag on their own systems and choose to share more if they want to appeal or support an abuse investigation.
The system is currently being tested with early customers. OpenAI says it plans a broader rollout, along with a technical white paper, in September 2026. Glean's Chief Information Security Officer, Sunil Agrawal, is quoted in the announcement saying the approach lets OpenAI advance safety "without compromising the privacy and control that sustain enterprise trust."
Why it matters
This is a procurement decision showing up in public, and it is happening right as OpenAI's biggest rival moves the opposite direction. Axios reports that Anthropic has instituted a 30-day retention requirement for business customers using its most capable models, arguing in a risk report that holding onto data is necessary to catch attacks that unfold across multiple requests. OpenAI is betting it can get the same detection without asking customers to hand over the data at all.
If you are the person signing off on which AI vendor your company standardizes on, that is no longer an abstract security debate. It is a checkbox that decides whether legal will let a frontier model touch anything sensitive. A vendor that can offer both zero retention and cross-conversation safety monitoring removes the reason compliance teams have used to keep frontier AI confined to sandboxed, low-value work.
The honest caveat
None of this is shipped yet. It is a preview running with a handful of early customers, and the real test, a public technical white paper and a real rollout, is still a month out. It also only applies to eligible enterprise and API customers; anyone on OpenAI's Free, Plus, Go, or Pro consumer plans sees no change at all. And there is a trust question underneath the trust question: you still cannot see how the detection system works, only the signal it produces when something trips it. OpenAI is asking enterprises to trade "we can see your data" for "trust our system to police your data without either of us looking at it," which is a real improvement, but it is still an ask.
Anthropic is betting that safety needs the receipts. OpenAI is betting it can have both. Enterprises evaluating the two do not have to resolve that argument themselves, they just get to watch which bet gets validated first.