Zero Data Retention Left OpenAI Blind to Multi-Step Abuse
OpenAI built Zero Data Retention so that eligible API customers could stop the company from keeping their prompts or model responses once a request finishes processing, and that promise still holds today for customer content, with no OpenAI staff review and no training use unless a customer opts in. The catch is what that promise costs on the safety side. OpenAI's own August 19 announcement states plainly that as models take on longer, multi-step agentic tasks, the riskiest behavior - a bad actor probing safeguards, coordinating across several accounts, disguising an attack as legitimate research, or an agent that keeps acting after being told to stop - only shows up when you look across multiple interactions, not inside any single one.
Existing ZDR-compatible safety checks evaluate each interaction in isolation, so they were structurally unable to catch that pattern. OpenAI goes further, noting that "some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring" - a direct, if unnamed, jab at rivals who solved this by keeping more data, not less. For a bank, hospital group or law firm bound by strict data-handling obligations, that trade-off was never acceptable, which is exactly the gap OpenAI says Private Safety Processing is meant to close.
The Fix Moves Safety Checks Behind the Customer's Own Keys
Private Safety Processing, still in preview as of August 19, 2026, extends OpenAI's individual-interaction safety checks to look across related interactions for patterns without giving OpenAI personnel access to the underlying customer content. The mechanism works two ways depending on where the content sits. If it lives on a customer's own infrastructure under a true ZDR deployment, OpenAI never touches it at all. If it sits on OpenAI-provided storage, the content is encrypted with keys the customer controls, and OpenAI staff simply do not hold those keys, so the underlying data stays unreadable to them either way.
When the system spots a risk, OpenAI does not receive the flagged prompt, the response or the reasoning behind the flag. It receives only what the company calls "a narrowly defined signal indicating the type of activity involved," which is enough to decide whether enforcement action is warranted but not enough to read what actually happened. Customers can investigate any flag or enforcement action using their own systems, and they can choose to voluntarily share more with OpenAI only if they want to appeal a decision or support an investigation - the disclosure stays opt-in on the customer's side, not automatic on OpenAI's.
Glean, Databricks, Abridge and Microsoft Are Already Testing It
Four named organizations are already testing Private Safety Processing ahead of a wider release: Glean, Databricks, Abridge and Microsoft. Sunil Agrawal, Glean's Chief Information Security Officer, gave OpenAI the strongest on-record endorsement so far: "Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI's no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust." That is an enterprise customer publicly vouching for a system that has not yet shipped.
One exception survives every version of this design: OpenAI is legally required to report apparent child sexual abuse material, so images flagged for potential CSAM continue to be retained for manual review and reporting even inside ZDR deployments, exactly as they are today. Private Safety Processing does not touch that carve-out. OpenAI says general rollout, alongside a technical white paper explaining the mechanism in more depth, is planned for September 2026 - meaning what ships next month, shaped further by customer feedback in the meantime, could differ from what is being tested now.
The September White Paper Is the Real Test, Not This Announcement
Nobody outside OpenAI has independently verified the encryption and key-control claims behind Private Safety Processing, which is the gap an EU or UK compliance team should hold open until September. The "narrowly defined signal" OpenAI describes is, by design, opaque to the customer receiving it - useful for deciding whether to act on a flag, but not detailed enough to satisfy a GDPR Article 28 processor-obligation review or an auditor asking exactly what was inferred from encrypted content and how. Until the promised technical white paper lands, the honest answer to "can we verify this" is no, not yet.
The announcement also lands three days after OpenAI's CFO discussed a potential 2027 IPO and days after ChatGPT Ads expanded into Europe, and taken together the pattern is an OpenAI visibly courting regulated-industry trust ahead of scaled commercial growth. That does not make Private Safety Processing a marketing exercise - the customer roster and the mechanism are real - but it does mean the burden of proof belongs on OpenAI's white paper, not on this announcement. Any vendor's "zero data retention" claim should now be read with one follow-up question: how, specifically, does it handle safety monitoring across sessions.
Read next: OpenAI's Enterprise Revenue Passed Consumer in July | IBM Bets Its Consulting Arm on One AI Vendor



