OpenAI Proposes Private Safety Processing to Preserve ZDR for Frontier Models

Private Safety Processing is designed to detect patterns across related interactions while keeping eligible API customer content inaccessible to OpenAI personnel.

The tension between no retention and long-horizon safety

On August 19, OpenAI previewed Private Safety Processing, an approach intended to preserve Zero Data Retention for eligible frontier-model API customers. ZDR means prompts and responses are not retained after processing. The new design extends automated safeguards from individual requests to patterns across related interactions without giving OpenAI personnel access to the underlying content.

Content remains in customer-controlled infrastructure, or could be stored by OpenAI under customer-controlled encryption keys. Automated systems return only a narrowly defined safety signal when they detect potential misuse. Customers can investigate alerts with evidence in their own systems and choose whether to share material for an appeal or abuse investigation.

What remains unverified

The system is in early-customer testing, with a technical white paper planned for September. Detection quality, false positives, key operations, deletion assurance and regulatory fit have not been independently demonstrated in this announcement. Potential CSAM images remain a legal-reporting exception and may be retained for manual review. Enterprises should examine data flow, exceptions, enforcement and appeal terms—not rely on the ZDR label alone.

Official source