The more companies rely on AI, the more two requirements collide. Safety teams need to connect multiple interactions to detect misuse, while enterprises do not want a provider to retain their prompts and outputs. OpenAI’s Private Safety Processing preview is an attempt to separate those two jobs.

On August 19, OpenAI announced the preview for eligible API customers using Zero Data Retention (ZDR). ZDR means that prompts and model responses are not retained after a request is processed. It does not mean that no data can ever be kept under any circumstance: eligibility, endpoint coverage, and legal exceptions still matter.

The reader question is therefore not “Does OpenAI now see nothing?” It is “What source content stays where, what derived signal is returned, and what new evidence can a customer inspect?”

A signal can cross interactions without exposing the source

OpenAI says automated systems will look for misuse patterns across related interactions and return only limited safety signals to the customer. The company also says its personnel will not review the underlying prompts and responses. For ZDR deployments, OpenAI describes customer content as remaining on infrastructure controlled by the customer, while it is developing an option to hold content on OpenAI infrastructure encrypted with customer-controlled keys.

A locked archive separates original interactions from the limited safety signal sent to a monitor

The preview is about separating source content from the signal needed for a safety decision.

Those statements describe an architecture direction, not a complete operating specification:

Question What the announcement establishes What is still open
Source content Eligible ZDR requests are designed not to retain prompts and responses after processing. Which models and endpoints qualify in a specific contract?
Safety detection Related interactions can be analyzed for misuse patterns. How accurate are the signals, and what are the false-positive paths?
Customer output The customer receives a limited safety signal rather than the original conversation. What fields, retention, and access controls apply to that signal?
Customer-controlled keys OpenAI says an encrypted customer-infrastructure option is in development. How are keys created, rotated, revoked, and audited?
Human review OpenAI says personnel do not review the underlying prompts and responses in the described flow. Which legal or safety exceptions can retain material for review?

Why agents make this harder

For a short question-and-answer exchange, one request may be enough to spot a risk. Agents are different. They plan in stages, call tools, fail, and try again. An individual message can look harmless while the sequence suggests a different pattern.

Enterprises also feed agents source code, internal documents, and research material they would rather not leave with a provider. If safety requires broad retention, adoption becomes harder. If a provider sees no relationship between interactions, repeated misuse can be easier to miss. Axios described OpenAI’s announcement as a contrast with Anthropic’s approach of requiring data logs for some use cases. That is context about different design choices, not a complete comparison of both companies’ policies.

Do not read this as complete privacy

This is an early-customer test, not a finished product guarantee. A company considering it needs to verify the eligible models and endpoints, the exact contents of the safety signal, where source content stays, and how customer-controlled keys are managed.

OpenAI also notes an important exception: images suspected to involve child sexual abuse may be retained for manual review and reporting as required by law, including in ZDR deployments. A limited safety signal is not the same as a complete audit trail either. Whether to automate blocking, how to handle appeals, and what evidence an independent auditor can inspect are separate design decisions.

Private Safety Processing asks a useful question: can a provider detect long-running misuse patterns without retaining the original content? The direction is meaningful, but the answer will come from signal quality, exception handling, customer control, and independent verification—not from the announcement alone.