The tension between no retention and long-horizon safety
On August 19, OpenAI previewed Private Safety Processing, an approach intended to preserve Zero Data Retention for eligible frontier-model API customers. ZDR means prompts and responses are not retained after processing. The new design extends automated safeguards from individual requests to patterns across related interactions without giving OpenAI personnel access to the underlying content.
Content remains in customer-controlled infrastructure, or could be stored by OpenAI under customer-controlled encryption keys. Automated systems return only a narrowly defined safety signal when they detect potential misuse. Customers can investigate alerts with evidence in their own systems and choose whether to share material for an appeal or abuse investigation.
What remains unverified
The system is in early-customer testing, with a technical white paper planned for September. Detection quality, false positives, key operations, deletion assurance and regulatory fit have not been independently demonstrated in this announcement. Potential CSAM images remain a legal-reporting exception and may be retained for manual review. Enterprises should examine data flow, exceptions, enforcement and appeal terms—not rely on the ZDR label alone.