OpenAI is previewing a safety system built to operate inside its strictest privacy commitment: automated tools that flag suspicious behavior across multiple interactions without any OpenAI employee ever seeing the underlying prompts. The tool, called Private Safety Processing, is designed to close a gap in Zero Data Retention (ZDR), OpenAI’s existing promise that eligible API customers’ prompts and responses are deleted after each request and never reviewed by staff or used to train models without consent.
That promise has a known weakness. ZDR-compatible safety checks so far have evaluated each interaction alone, missing risks that only become visible when several related interactions are compared. The gap has forced a real trade-off on enterprise buyers, who have had to choose between adopting the most capable models, some of which pushed providers to retain more content for safety monitoring, and keeping airtight data controls paired with a thinner safety net. OpenAI’s new system is built to make that choice disappear, at least on paper.
Intent is often invisible in a single message. OpenAI says harmful patterns tend to surface only once related interactions are viewed together: bad actors probing the same safeguard repeatedly, coordinating activity across multiple accounts, or dressing up a prohibited request as routine research. A comparable risk can develop mid-task, when an autonomous agent keeps acting after a user has told it to stop.
Private Safety Processing extends the automated checks already used in ZDR deployments across that wider window of related activity, rather than judging each interaction in isolation. Customer content stays exactly where it already sits: on infrastructure the customer controls, or, for customers who prefer OpenAI-hosted storage, encrypted with keys the customer holds and OpenAI staff cannot access. When the system flags a pattern, OpenAI receives only a narrow signal describing the type of activity involved. The customer investigates using its own logs and decides whether to share further detail if it wants to appeal an enforcement decision or support an abuse investigation.
Sunil Agrawal, who serves as chief information security officer for Glean, the enterprise search company, said enterprise adoption depends on customers keeping full control of their data, with no secondary use beyond the service they signed up for. He credited OpenAI’s no-training policy and ZDR with giving Glean the confidence to build on the platform. OpenAI also named Databricks, Abridge, and Microsoft among the customers who helped shape the design, a roster that skews toward regulated data: proprietary research, confidential business plans, health data, and financial records.
OpenAI is currently testing Private Safety Processing with a small group of early customers. It is not yet generally available to all API users. OpenAI plans to begin rolling it out, and to publish a technical white paper describing the underlying methods, in September. Until that paper lands, every claim about how the pattern-matching works on content OpenAI itself cannot read is OpenAI’s own description of its own system.
One exception survives every version of the promise. OpenAI is legally required, like every other major model provider, to flag likely child sexual abuse material the instant its systems detect it. Images OpenAI’s systems flag as potential CSAM stay in the system for human review and mandatory reporting, even under Zero Data Retention.
Security teams negotiating frontier-model contracts should treat the September white paper, not this preview, as the real decision point. It is the first moment outside researchers can test whether pattern detection on encrypted, unreadable content works as described rather than merely as announced.
OpenAI, company announcement published August 19, 2026.