Summary

OpenAI reaffirms Zero Data Retention (ZDR) for eligible API customers and previews Private Safety Processing: continuous, automated, cross-interaction abuse detection that never touches customer content. Only detection statistics (vectors, counts) are retained; prompts and completions are never stored or read. It can run on customer-held encryption keys, and disclosures are non-linkable to customers by design; standard abuse monitoring remains available for non-ZDR customers. OpenAI positions this as safety without retention, building on its agentic-evals privacy work, with pilots for select customers and an in-depth white paper planned for September. TechCrunch frames it as an attempt to one-up Anthropic on enterprise privacy.

Why it matters
For regulated enterprise deployments, this tackles a tension that used to force a binary choice: ZDR meant giving up abuse detection. Continuous cross-interaction abuse monitoring is now claimed to coexist with never reading or storing customer content, and the customer-held-key variant is the most privacy-conservative design a major lab has surfaced. Caveats: it is a preview with select-customer pilots, and the technical white paper only lands in September — verify the privacy claims before architecting compliance around them.
Technical details
Zdr reaffirmed for eligible API customers on frontier models
Private Safety Processing continuous automated cross-interaction abuse detection without content access · statistics (vectors, counts) retained; prompts/completions never stored or read · can run on customer-held encrypted keys · disclosures non-linkable to customers by design
Availability preview, pilots with select customers; white paper planned September 2026
Positioning safety-without-retention; builds on agentic-evals privacy work; framed vs Anthropic (TechCrunch 8/19)
Tags
openaiprivacyzdrcomplianceguardrailsenterprisesafety