OpenAI is offering an alternative to Anthropic’s 30-day data retention policy with a safety system designed to detect multi-session AI abuse without giving OpenAI personnel access to customers’ underlying prompts or responses.
The AI company introduced a preview of Private Safety Processing on Wednesday, an automated safeguard designed to detect threats across related interactions while preserving Zero Data Retention (ZDR) protections for eligible API and enterprise customers.
The move creates an immediate competitive wedge against key rival Anthropic, which recently instituted a mandatory 30-day data retention rule for its top-tier models.
Traditional ZDR protocols evaluate individual prompts in isolation, wiping the exchange immediately after processing. However, as artificial intelligence handles broader autonomous tasks, bad actors can evade detection by fragmenting harmful requests across several distinct sessions.
“We’re seeing with more capable frontier models that often risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions,” Aleah Houze, Head of Product Policy at OpenAI, said per Axios. “So, an example of this would be somebody might be asking about the weakness in a company’s software in one conversation, and then later in another conversation they might ask about remote access or what security tools can detect.”
Anthropic took a different route by mandating 30-day data storage on covered models like Mythos 5 and Fable 5, acknowledging in a recent risk report that while the move would be “unpopular with customers who have come to expect zero retention,” the lab views it as essential to detect coordinated multi-request attacks.
Automating abuse detection without human eyes
Private Safety Processing can examine interaction patterns on customer-controlled infrastructure or in OpenAI-provided storage encrypted with keys controlled by the customer. If suspicious behavior is detected, OpenAI receives a narrowly defined signal identifying the type of activity involved, but not the underlying prompts or responses.
“No AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes,” OpenAI wrote in its announcement.
Corporate partners in highly regulated environments have praised the architectural balance. Zach Powers, CISO at healthcare AI firm Abridge, noted: “In healthcare, protecting massive amounts of sensitive data and ensuring its accuracy and integrity are fundamental to earning the trust of clinicians and patients. Having the chance to work directly with OpenAI’s product, engineering, policy, and leadership teams to help shape those practices has made for an unparalleled partnership. That level of collaboration on trust and security is uncommon. They listen, they take action, and that gives us confidence in OpenAI.
Deployment timeline, exceptions, and boundaries
OpenAI noted that Private Safety Processing is confined strictly to eligible API and enterprise customers. The ZDR framework does not apply to consumer ChatGPT tiers, including Free, Plus, Go, and Pro plans.
Additionally, OpenAI maintains an explicit legal carve-out across its platforms: images flagged for potential child sexual abuse material (CSAM) remain subject to retention for manual review and reporting. OpenAI plans to begin rolling out Private Safety Processing and publish a technical white paper in September, providing more detail about the system’s technical and operational design.
Read more: As AI systems become more capable of finding and exploiting vulnerabilities, OpenAI is urging security teams and managed providers to accelerate defensive automation while maintaining clear limits on agent access.





