Skip to content

Product2 publishers3 min readPublished Updated

OpenAI turns zero retention into a sales pitch with Private Safety Processing

The preview watches for abuse across multiple sessions while keeping none of the customer's data, aimed at enterprises unhappy with Anthropic's 30-day retention for covered models.

The Product Desk · Product desk

Photograph accompanying OpenAI turns zero retention into a sales pitch with Private Safety Processing
Photo: anthropic.com

What happened

  • OpenAI announced a privacy-centric safety approach and is previewing a service to select customers called Private Safety Processing, an automated system that watches for potential abuse while retaining none of the customer's data.
  • Anthropic's data retention policy, announced in July, enables it to keep user data, including all sessions and the conversations within them, for 30 days for "covered models", which the company says include all Mythos-class models and "future models with similar capabilities"; it was designed to let the lab sift and analyze potential impropriety.
  • Anthropic also largely abides by Zero Data Retention, except when it comes to "covered models", such as Fable.
  • Anthropic's retention policy has aggravated some customers and deeply concerned some enterprises that handle large amounts of sensitive data and do not want it harbored or inspected by the AI lab.
  • OpenAI, like most other AI companies, adheres to Zero Data Retention, which uses agents within the OpenAI API to monitor for abuse on a per-session basis so customer data is not retained and scanning happens without human intervention.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

OpenAI is previewing a service for select customers called Private Safety Processing, an automated system that monitors for potential abuse while retaining none of the customer's data [1]. The timing is the point: Anthropic's policy, announced in July, lets it keep user data, including all sessions and the conversations in them, for 30 days for what it calls covered models [2], and TechCrunch reports the policy has aggravated some customers who handle sensitive data and do not want it held or inspected by the lab [4].

Both labs already work largely under Zero Data Retention, where agents inside the API check for abuse on a per-session basis without the company keeping the data or a human reading it [5]. Anthropic also largely abides by ZDR, with covered models as the exception [3]. So the argument is not about retention in general. It is about the one carve-out that safety teams say they need and that legal teams keep flagging.

OpenAI describes Private Safety Processing as a widening of ZDR's scope: long-horizon monitoring that assesses inputs and outputs across multiple conversations rather than one, again run by an agent [6]. The stated reason is straightforward. A spokesperson told TechCrunch that a bad actor trying to engineer malware could spread requests across sessions to avoid detection, and that the system can analyze those conversations for signs of abuse without human review [7].

What leaves the customer's estate is a signal, not a transcript. If the system triggers, it may send what OpenAI calls a narrowly defined signal warning of a specific type of activity, after which OpenAI decides whether enforcement is necessary [8]. From there it contacts the customer for context, and the customer may choose to share data at its discretion [9]. Anthropic's answer to the same problem is procedural rather than architectural: it says human review of customer data can happen, but only through a controlled access path involving a small set of approved reviewers, with every session recorded in a tamper-proof log that reviewers cannot suppress or modify [10].

That is the real procurement question, and it is not obvious which side wins it. One vendor removes the data from reach and hands you an alert you cannot audit. The other keeps the data for a bounded window and offers a logged, restricted path to it. A bank's security team and its general counsel will not necessarily rank those the same way.

The commercial pressure behind the move is visible. A recent report showed OpenAI's second-quarter growth was slower than Anthropic's [11], Anthropic's annualized revenue run rate is reportedly $65 billion [12], Anthropic investors have suggested an IPO at $2 trillion [13], and OpenAI is working on its own IPO [14]. Safety tooling is now something you can put in a bid response.

Watch for the details the announcement does not carry. TechCrunch's account names no preview customers and gives no general availability date [15], and there is no published taxonomy of what a narrowly defined signal contains or how often one fires. Watch whether Anthropic extends anything like cross-session processing to covered models rather than defending the 30-day window on process grounds [2][10], and whether enterprise contracts start specifying signal contents and false-positive handling the way they now specify retention periods.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories