Security1 distinct publisher3 min readUpdated
Zero Data Retention promised nothing was kept. The new preview keeps nothing and still analyses across sessions, which means contracts and DPIAs written around retention need new language.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Zero Data Retention promised nothing was kept. The new preview keeps nothing and still analyses across sessions, which means contracts and DPIAs written around retention need new language.
OpenAI is previewing a system it calls Private Safety Processing with early customers, and says it will begin rolling it out and publish a technical white paper in September [1][3]. The mechanism matters less for what it detects than for what it does to the wording of every Zero Data Retention contract already signed: it establishes a class of data that is analysed by machine, retained by nobody, and not readable by OpenAI staff [2][10].
The contradiction being patched is an old one. ZDR, as sold to eligible API customers, means prompts and model responses are not retained after a request is processed [5]. Abuse detection wants history. Existing safeguards evaluate requests individually, while the new system analyses related activity to find patterns of potential misuse [11]. OpenAI's answer is to leave content where the customer already controls it and run analysis there [8], with a second option in development that stores content on OpenAI infrastructure under customer-controlled encryption keys [9]. In both configurations, according to the company, automated systems return limited safety signals without revealing prompts or responses [10]. When a risk is detected, OpenAI receives a defined signal indicating the type of activity involved, which can inform enforcement decisions [13].
Which makes explicit what was always true: ZDR is a no-retention guarantee, not a no-analysis guarantee [1]. That distinction stayed theoretical while safeguards worked one request at a time. It stops being theoretical when the output is a cross-session behavioural signal about a named customer, because the signal is a new artefact, derived from customer content, held by the vendor, and capable of triggering account action [13].
There is also an existing carve-out that DPIA authors should already have logged: images flagged as potential CSAM may be retained for manual review and reporting [6]. Any document that treats ZDR as absolute is wrong on its own terms.
The appeals design is where the operational burden lands. Because OpenAI personnel are restricted from the underlying content [2], customers investigate alerts using information available in their own systems and decide what to share in order to appeal a decision, clarify legitimate activity, or support an investigation into verified abuse [14]. Read that as a logging requirement rather than a courtesy: an organisation that cannot reconstruct the session behind a signal cannot contest it [2].
OpenAI repeats that enterprise customer data is not used to train its models unless customers opt in [7], and frames the programme as collaborative, writing that "no AI lab can address emerging risks alone" [4]. Abridge CISO Zach Powers is quoted saying the level of partnership on trust and security is uncommon, citing direct work with OpenAI product, engineering, policy and leadership teams [12].
What to watch is the September white paper [3]: whether the signal taxonomy is published, how long signals persist, whether OpenAI characterises them as personal data, and how key control in the planned encrypted-storage option is evidenced to an auditor rather than asserted [9]. Until that lands, the preview is a description of intent, not something a procurement team can attach to a schedule [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable.
The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content.
OpenAI wrote: "No AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes."
In both configurations, automated systems can identify potential misuse and return limited safety signals without revealing prompts or responses.
Existing safeguards evaluate requests individually, while the new system analyses related activity to detect patterns of potential misuse.
When the system detects a potential risk, OpenAI receives a defined signal indicating the type of activity involved, and that information can inform enforcement decisions.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-sourced account, specification pending
Every technical assertion traces to one trade-press write-up of an OpenAI announcement. The mechanism claims, personnel access restriction, cross-interaction pattern analysis, signal-only egress, are described but not demonstrated, and the technical white paper that would allow scrutiny is scheduled rather than published. There is no independent testing, no third-party audit reference and no second publisher in the cluster.
Preview stage with one named participant
Adoption evidence is limited to a preview with unnamed early customers plus one named collaborator, Abridge, in healthcare. General rollout is announced for September and no customer counts, deployment volumes or eligibility breadth beyond 'eligible API customers' are disclosed.
Assurances outrun verifiable detail
The framing, privacy-preserving abuse detection where the vendor cannot see content, is stronger than what the supplied material can substantiate: the mechanism is unpublished, the deployment is a preview, and the one supporting voice is a design partner. The reporting itself is restrained and includes the CSAM retention exception, which limits the overstatement, but the gap between 'no personnel access' as a marketing property and as a verified property is real.
Vendor announcement plus partner testimonial
The narrative originates with OpenAI at a moment when regulated-industry enterprise buyers are the growth constraint, and the only external voice is a collaborating customer whose CISO is quoted praising the partnership. The publisher is trade press relaying the announcement, with no adversarial or independent counterweight in the cluster.
Announcement is reliable, properties are not yet checkable
Confidence is moderate: it is well established what OpenAI has said and when, and the report is internally consistent and specific. What cannot be assessed from the supplied material is whether the described guarantees hold in implementation, how broadly the preview reaches, or how enforcement and appeals behave in practice.
leadership
Disney swaps raises for discounted stock and a full health-plan re-enrollment1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026