openai

Zero retention stays, safety monitoring gets a signal

Promtime

openai

OpenAI is testing Private Safety Processing, a system it says can detect misuse patterns across related interactions while keeping zero data retention intact for business customers. The company previewed the design on Wednesday, according to Axios, and is running it with early customers ahead of a wider release.

At a glance

  • Under the design, OpenAI's systems return a narrowly defined safety signal to the company rather than the underlying prompts and responses, which stay with the customer or under customer-held encryption keys.
  • Anthropic moved the other way, requiring 30-day data retention from business customers on Fable 5 and Mythos 5, a step it called essential against attacks that span multiple requests.
  • OpenAI said Tuesday it has paused some work on training new models over safety concerns, while Anthropic says it sees no current need for a similar pause on its own training work.

Zero data retention has become a procurement baseline for regulated enterprises, and frontier-model safety monitoring cuts against it directly. OpenAI and Anthropic are now testing opposite answers to the same problem, which likely turns a compliance checkbox into a vendor-selection argument. OpenAI's approach reads as an attempt to keep the guarantee intact while claiming the same cross-conversation visibility that Anthropic says requires stored logs.

Private Safety Processing sends OpenAI a safety signal, not the prompts

OpenAI is testing the system with early customers. It is designed to identify misuse patterns across related interactions while preserving zero data retention protections, with the company receiving a narrowly defined safety signal rather than the underlying prompts or responses. Zero data retention, abbreviated ZDR, means those inputs and outputs are not stored by OpenAI.

Customer data can remain on customer-controlled infrastructure, or be stored by OpenAI under encryption keys that the customer controls. In a post titled "Offering Zero Data Retention for frontier models," OpenAI reaffirmed zero data retention for eligible API customers alongside the preview of Private Safety Processing.

The controls apply to eligible enterprise and API customers. They do not extend to ChatGPT Free, Plus, Go and Pro, whose existing consumer data settings are unchanged by the preview, which is aimed at business deployments rather than subscription accounts.

Aleah Houze says risks emerge across multiple interactions, not one prompt and response

OpenAI says it needs some amount of context over time to detect risks, and that the new system supplies that context without access to sensitive customer data. Aleah Houze, Head of Product Policy at OpenAI, described the shift in a briefing with reporters.

We're seeing with more capable frontier models that often risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions.

Houze gave a concrete case: a user asking in one conversation about a weakness in a company's software, then in a later conversation about remote access or which security tools can detect it. Seeing those signals in a broader context might help OpenAI detect a cyber attack.

Anthropic requires 30-day retention on Fable 5 and Mythos 5

Anthropic has instituted a 30-day data retention policy for business customers who want to use Fable 5 and Mythos 5. The company wrote in a risk report last week that the requirement is essential to detect and prevent sophisticated attacks that span multiple requests.

Anthropic acknowledged in the same report that the requirement would be unpopular with customers accustomed to zero retention and could pose real risks to its business, particularly if competitors do not follow. The two labs also differ on training: OpenAI said Tuesday it has paused some work on training new models to address safety concerns, while Anthropic says it does not see a current need to do the same.

September white paper and rollout

OpenAI plans a broader rollout of Private Safety Processing and a technical white paper in September. Until then the system stays in testing with early customers, and remains limited to eligible enterprise and API accounts. No list of participating customers has been published, and no pricing or contract terms for the preview have been disclosed.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.