OpenAI has previewed Private Safety Processing, a new system designed to spot patterns of misuse across multiple interactions while remaining compatible with its Zero Data Retention service for API customers.

Zero Data Retention currently guarantees that OpenAI does not retain eligible customers' prompts or responses after a request is processed, and does not use enterprise data for training without explicit opt-in. One exception applies regardless of ZDR status: content flagged for potential child sexual abuse material is retained for manual review and reporting, as legally required. Existing ZDR-compatible safety systems otherwise assess each interaction in isolation, which OpenAI says limits their ability to catch risks that only become visible across a sequence of interactions, such as repeated probing of safeguards, coordinated abuse across accounts, or an AI agent that continues acting after being told to stop.

Under the new system, customer content stays either on infrastructure the customer controls or, in an option OpenAI is also developing, on OpenAI's own infrastructure but encrypted with keys held by the customer. Automated systems analyse patterns across interactions and can flag a narrowly defined signal, such as the type of activity involved, without giving OpenAI staff access to the underlying content. Customers can then investigate flagged activity themselves, and may choose to share content with OpenAI if they want to appeal a decision or support an abuse investigation.

Private Safety Processing is currently being tested with early customers, with OpenAI citing feedback from organisations including Glean, Databricks, Abridge and Microsoft. The company plans to begin a wider rollout, alongside a technical white paper, in September.


AI Contracts Decoded: What Fortune 500 Legal Veterans Know That You Don’t
When Microsoft refuses to negotiate indemnification with their biggest customers, what does that mean for your AI vendor contracts? When IBM data shows 97% of AI breaches stem from compliance failures—most being supply chain-related—who holds liability? When employees download shadow AI tools with zero cybersecurity controls, what recourse does your company have? None. Cathy Mulrow-Peattie brings perspective most outside counsel lack: Fortune 500 in-house experience at MasterCard and Omnicom, General Counsel at an AI startup, now advising enterprises. She starts with business goals before technology, technology before contracts—because she’s been in the hot seat when governance fails. You’ll learn: • Why 10-year AI contracts create risk and 90-day pilots with exit strategies are essential • The IP paradox: machine-generated outputs aren’t copyrightable but terms of use matter • How LLM providers retain “certain uses” of your data and when private instances become mandatory • Why contractual risk allocation to key vendors is your only viable strategy Key topics: Supply chain due diligence • The 97% compliance failure rate • Shadow AI liability traps • Benchmarking gaps • Hallucination disclaimers • GDPR/CCPA requirements • NY DFS Part 500 • Acceptable use policies • Dark web data sourcing • Evolutionary AI governance For: CISOs, CIOs, Chief Legal Officers, and compliance leaders navigating AI vendor relationships Contractual realities from someone who’s negotiated with Microsoft, advised Fortune 500s, and managed governance failures.
Share this post
The link has been copied!