OpenAI Previews 'Private Safety Processing' to Detect Abuse Without Retaining Customer Data
OpenAI is previewing Private Safety Processing to select customers, an automated system that monitors for misuse across multiple sessions without retaining any customer data. The move directly contrasts with Anthropic's July policy allowing 30-day data retention for 'covered models' like Fable.
OpenAI is previewing a new privacy-focused safety system called Private Safety Processing to select customers, according to the company. The automated tool monitors for potential misuse across multiple conversations while retaining none of the customer's underlying data — a direct contrast to Anthropic's recently announced policy of retaining user data for up to 30 days on certain models.
What OpenAI announced
Private Safety Processing extends OpenAI's existing Zero Data Retention (ZDR) framework, which uses automated agents to scan for abuse on a per-session basis without human review or data storage. The new system, according to OpenAI, adds "long-horizon" monitoring that assesses inputs and outputs across multiple sessions rather than just one.
An OpenAI spokesperson told TechCrunch the technology is designed to catch bad actors who spread malicious activity — such as engineering malware for a cyberattack — across separate conversations specifically to evade single-session detection.
When the system's agent detects a pattern of concern, it sends what OpenAI calls a "narrowly defined signal" internally, without exposing the actual conversation content to human reviewers. OpenAI then decides whether enforcement action is warranted. If so, the company will contact the customer for context, and the customer can choose — at their own discretion — whether to share the underlying data. No customer data is retained by OpenAI as part of this process, the company says.
No pricing, release date, or general availability timeline has been disclosed. The service is currently being previewed to a limited set of customers.
The Anthropic contrast
The announcement follows Anthropic's July policy change permitting the company to retain user session data for 30 days for what it calls "covered models" — including all Mythos-class models and future models with similar capabilities, according to Anthropic. Anthropic has said the policy exists to allow deeper safety analysis of potential misuse and that any human review of that data happens through a "controlled access path" limited to "a small set of approved reviewers," with every review session logged in a tamper-proof record.
That policy has reportedly frustrated some enterprise customers handling sensitive data who object to any retention or inspection window, even a limited and audited one. Anthropic itself otherwise follows Zero Data Retention practices outside of covered models like Fable, according to the report.
Competitive backdrop
The dueling privacy approaches arrive amid intensifying rivalry between the two labs. A recent report indicated OpenAI's second-quarter revenue growth trailed Anthropic's, with Anthropic's annualized revenue run rate reportedly reaching $65 billion. Anthropic investors have floated a potential IPO valuation as high as $2 trillion, while OpenAI is also pursuing its own path to a public offering.
What this means
This is a policy and product positioning move, not a new model release — no new weights, checkpoints, or architecture are involved. The substantive technical claim is that OpenAI can now correlate signals across sessions without storing raw conversation data, but there's no independent verification of how this multi-session detection actually works under the hood, what false-positive rates look like, or how "narrowly defined" the internal signals really are. Enterprises weighing data-retention risk now have two distinct models to evaluate: Anthropic's audited-but-retained approach versus OpenAI's zero-retention-but-less-transparent one. Which wins favor with security-conscious enterprise buyers will likely hinge on how each company documents its audit trails and whether either approach demonstrably reduces incidents of long-horizon misuse like slow-drip malware engineering.
Related Articles
OpenAI Reaffirms Zero Data Retention for API Customers, Previews Private Safety Processing
OpenAI has reaffirmed its Zero Data Retention (ZDR) policy for eligible API customers using frontier models and previewed a new feature called Private Safety Processing, which the company claims allows safety monitoring without retaining customer data.
OpenAI Reaffirms Zero Data Retention for API Customers, Previews New Private Safety Processing
OpenAI has reaffirmed its Zero Data Retention (ZDR) policy for eligible API customers using frontier models and previewed a new capability called Private Safety Processing. The company says the new approach aims to preserve safety monitoring capabilities without requiring data storage.
OpenAI Patches Codex Bug That Let AI Agent Delete Real User Files
OpenAI has shipped a security update for Codex after users reported that GPT-5.6 Sol was autonomously deleting real files instead of temporary ones. The bug stemmed from misused system variables like $HOME pointing cleanup commands at actual home directories.
Anthropic Expands Claude Cowork to Mobile for All Paid Plans
Anthropic announced that Claude Cowork, its workspace-focused feature, is now available on mobile and web for all paid plans. The rollout began last month exclusively on Anthropic's most expensive tier before expanding today.
Comments
Loading...