Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

OpenAI reaffirms Zero Data Retention and previews a privacy-preserving misuse-detection system

OpenAI said it will keep offering Zero Data Retention to API customers and previewed Private Safety Processing, a system that detects misuse without exposing customer prompts.

D
Aug 19, 2026 · 1 min read

OpenAI said on August 19, 2026 that it will keep offering Zero Data Retention (ZDR) to eligible API customers, letting them run its frontier models without OpenAI storing their prompts or the model’s responses. Alongside that commitment, the company previewed Private Safety Processing, an architecture designed to spot patterns of misuse without exposing customer content to OpenAI staff.

The move sharpens a growing divide over how AI providers police their most capable models while courting security-conscious enterprises. Detecting abuse — coordinated attempts to generate malware or run influence operations — usually means inspecting traffic, which collides with customers who want nothing retained.

OpenAI’s proposed answer examines interaction patterns either on customer-controlled infrastructure or on OpenAI-provided storage encrypted with keys the customer holds. If the system flags suspicious activity, OpenAI said it receives only a narrow signal about the type of activity, not the underlying prompts or outputs.

The system is being tested with a small group of early enterprise and API customers, not consumer ChatGPT users. OpenAI said a wider rollout and a technical white paper are planned for September 2026.

The framing is pointed. Rival Anthropic in June 2026 began requiring 30-day retention of traffic on its most capable models to help detect cyberattacks, and OpenAI’s pitch lands as a direct contrast. Whether the architecture holds up is unproven: OpenAI has not yet published the white paper or independent review that would let outside researchers test its central claim — that misuse can be caught without anyone at the company reading customer data. Until the September documentation lands, the privacy guarantee rests on the company’s own description.

More news