OpenAI previews privacy-focused system for detecting AI misuse
OpenAI previews Private Safety Processing, detecting cross-interaction AI misuse without exposing customer prompt content, rolling out in September.
OpenAI previewed Private Safety Processing for API and enterprise customers, a system that analyzes patterns across related interactions to flag potential misuse while restricting OpenAI personnel from accessing underlying content. It builds on Zero Data Retention (ZDR) deployments, keeping content on customer-controlled infrastructure or a planned option using customer-controlled encryption keys, with prompts and responses not retained after processing. A technical white paper and rollout are planned for September; images flagged as potential CSAM are the retention exception.
- Analyzes patterns across related interactions, unlike per-request safeguards
- Works with ZDR: prompts and responses not retained after processing
- Customer-controlled encryption keys storage option in development
- Technical white paper and rollout planned for September
- Customers can investigate alerts and appeal enforcement decisions
Full article388 words · extracted from helpnetsecurity.com · click to collapse
OpenAI is previewing Private Safety Processing with early customers seeking greater certainty about how their data will be protected as AI systems become more capable. The system identifies patterns across related interactions while restricting OpenAI personnel from accessing the underlying content. The company plans to start rolling it out and publish a technical white paper in September.
“No AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes,” OpenAI wrote.
For eligible API customers using Zero Data Retention (ZDR), prompts and model responses are not retained after a request is processed. An exception applies to images flagged as potential CSAM, which may be retained for manual review and reporting. OpenAI says enterprise customer data is not used to train its models unless customers opt in.

Content Access Controls (Source: OpenAI)
ZDR deployments keep content on infrastructure controlled by the customer. OpenAI is developing another option that would store it on the company’s infrastructure using customer-controlled encryption keys. In both configurations, automated systems can identify potential misuse and return limited safety signals without revealing prompts or responses.
Safety analysis across interactions
Private Safety Processing builds on automated protections used in ZDR and other deployments. Existing safeguards evaluate requests individually, while the new system analyzes related activity to detect patterns of potential misuse.
“In healthcare, protecting massive amounts of sensitive data and ensuring its accuracy and integrity are fundamental to earning the trust of clinicians and patients. Having the chance to work directly with OpenAI’s product, engineering, policy, and leadership teams to help shape those practices has made for an unparalleled partnership. That level of collaboration on trust and security is uncommon. They listen, they take action, and that gives us confidence in OpenAI. That level of partnership on trust and security is just not common,” said Zach Powers, CISO, Abridge.
The system can analyze data stored on customer-controlled infrastructure or through OpenAI’s planned encrypted storage option. When it detects a potential risk, the company receives a defined signal indicating the type of activity involved. That information can inform enforcement decisions.
Customers can investigate alerts using information available in their own systems and share relevant details with OpenAI to appeal a decision, clarify legitimate activity or support an investigation into verified abuse.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/20/openai-private-safety-processing-zdr/