The Information Machine
Concluded·following since 19 Aug 2026·Day 4·11 sources·updated 21 Aug 2026

OpenAI's Private Safety Processing design

The gist

OpenAI reaffirms ZDR for frontier models, previews Private Safety Processing

Enterprise API customers at the frontier tier have faced a requirement to allow data retention for safety monitoring; this system attempts to preserve ZDR while still detecting cross-interaction misuse. The approach involves design tradeoffs around durable identifiers and metadata that remain unresolved ahead of the planned September rollout.

The full picture

OpenAI is extending Zero Data Retention to frontier models and previewing Private Safety Processing, a system that aims to allow cross-interaction safety monitoring without exposing customer content to OpenAI staff. ZDR guarantees that prompts and responses are not retained after processing and that enterprise data is not used for model training unless customers opt in. OpenAI stated that some recent frontier-model deployments required customers to allow their AI provider to retain sensitive content for safety monitoring, and that for many organizations such requirements conflict with their security obligations. Private Safety Processing uses automated processes and customer-controlled encryption keys to detect misuse patterns across related interactions; when a risk is flagged, OpenAI receives only a narrow category-and-severity signal, not the underlying content, and customers can choose to share content for appeals or investigations. The system is in early customer testing, with a full rollout and technical white paper planned for September 2026.

How it developed
21 August 2026

Reporting published August 21 found that OpenAI's Private Safety Processing follows a different technical route from Anthropic's customer-hosted log approach, providing the first concrete point of technical contrast between the two providers' strategies for the enterprise privacy-safety tradeoff.

Private Safety Processing, announced August 19, uses automated processes and customer-controlled encryption keys to flag misuse patterns across interactions while sending OpenAI only a category-and-severity signal, not the underlying content.

20 August 2026

Analysis notes OpenAI's Private Safety Processing takes a different technical route from Anthropic's customer-hosted log approach

A technical analysis published August 20 found that Private Safety Processing, OpenAI's system for detecting cross-interaction misuse patterns announced August 19, faces a design challenge: linking related interactions requires durable identifiers, which could create metadata exposure or be evaded by attackers fragmenting activity across accounts. The analysis also noted OpenAI is extending Zero Data Retention to frontier models where the feature was previously unavailable, and that Anthropic requires 30-day retention for its Claude Fable 5 and Claude Mythos 5 covered models while still offering ZDR for other eligible API usage.

19 August 2026

OpenAI announces ZDR reaffirmation for frontier models and previews Private Safety Processing, with full rollout and white paper planned for September 2026

17 August 2026

Report describes a ChatGPT feature for Mac logging keystrokes, clicks, and app switches as unencrypted plain text

Sources
6 more sources
The daily email

Want this in your inbox?

I send a short email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free