OpenAI Previews Private Safety Processing for ZDR API Customers

OpenAI has previewed Private Safety Processing, a safety-monitoring approach designed for frontier-model API customers using Zero Data Retention (ZDR). The company says the system is being tested with early customers and plans to begin rolling it out in September alongside a technical white paper.
Eligible ZDR customers receive a commitment that OpenAI does not retain prompts or model responses after a request has been processed. The content is not available for review by OpenAI personnel, and enterprise customer data is not used to train models unless the customer explicitly opts in.
Safety signals without staff access to content
OpenAI says existing ZDR-compatible safeguards assess each interaction independently. Private Safety Processing is intended to extend automated protections across related interactions, because potentially harmful intent may emerge only over repeated requests, coordinated activity, safeguard probing, or a longer agentic task.
For ZDR deployments, customer content remains on infrastructure controlled by the customer. OpenAI is also developing an option for content stored on its infrastructure and encrypted with keys controlled by the customer. OpenAI personnel do not hold copies of those keys and therefore cannot access the underlying material.
When the automated system identifies a risk, OpenAI receives a narrowly defined signal about the type of activity involved. That signal can inform an enforcement decision, but it does not provide personnel with the flagged prompts or responses. Customers can investigate alerts through information in their own systems and may voluntarily share relevant material when appealing, clarifying legitimate activity, or supporting an investigation into verified abuse.
Balancing frontier-model controls and enterprise obligations
The preview addresses a tension for organizations handling financial records, health data, confidential plans, and proprietary research. Some frontier-model deployments have required providers to retain sensitive content for safety monitoring, which OpenAI says can conflict with security obligations and commitments to the people those organizations serve.
The company has already highlighted the need for stronger controls as cyber capabilities advance; OpenAI cyber-capability safety controls frames the broader safety challenge around frontier-model deployment and its implications for organizations adopting advanced AI.
OpenAI notes one exception to its ZDR approach: images flagged for potential child sexual abuse material can continue to be retained for manual review and legally required reporting, including in ZDR deployments.
For businesses, the practical task is to evaluate whether the proposed architecture, alert information, customer-controlled encryption keys, and escalation procedures meet internal privacy, security, and regulatory requirements before extending AI systems into longer and more autonomous workflows.

