OpenAI is previewing Private Safety Processing for its frontier large language models (LLMs) in a move to give enterprise customers more control over how their data is handled while allowing it to monitor for potentially risky activity.
Private Safety Processing allows the AI model developer to support Zero Data Retention (ZDR), whereby a service provider processes a customer’s data in real-time and discards it immediately rather than storing it for a period of time. The company stated:
“OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train our models unless customers explicitly opt-in.”
The move comes as OpenAI pushes deeper into the enterprise market, where data privacy and control are key requirements for organizations deploying increasingly capable models in sensitive workflows. It also comes amid reports that OpenAI is preparing for a potential initial public offering (IPO), putting greater focus on its ability to turn enterprise demand into commercially sustainable growth.
Balancing AI Safety With Data Privacy
The announcement made a not-so-subtle dig at competitor Anthropic, noting that “[s]ome recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring.” While model providers may need access to more context to identify misuse, such policies can restrict some enterprises from adopting AI services where retaining sensitive customer data would conflict with their security policies, regulatory requirements, or commitments to protecting customer information.
“Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service,” said Sunil Agrawal, Chief Information Security Officer at Glean.
As Ashish Nagar, Co-Founder and CEO at Level AI, told CX Today:
“Enterprises will need control of how their data is being used, where how is it being stored, and how is it being used for model training to create a continuous learning loop.”
OpenAI said it is responding to those concerns. “We are sharing this preview now because we’ve heard our customers loud and clear that they need predictability about how their content will be protected as AI systems become more capable.”
“The organizations we work with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans, and proprietary research. Protecting that information is essential to meeting regulatory obligations, maintaining customer trust, and preserving their competitive advantage.”
The issue is particularly relevant to customer experience teams, which increasingly use AI to process data from customer interactions. Call transcripts, complaints, account information and other customer records can contain sensitive personal and commercial information.
The risk extends beyond formally approved AI deployments. The need for tighter data controls is increasing as enterprise employees turn to AI chatbots and agents for everyday work, potentially moving customer information outside the systems and safeguards controlled by their employers. Customer data can end up in personal or unsanctioned AI tools when employees lack convenient enterprise-approved alternatives, creating a gap between where organizations believe data is being handled and where it actually goes.
OpenAI’s Private Safety Processing system offering addresses part of this concern by giving eligible API customers stronger assurances over how prompts and responses are retained when employees use its models.
Research by data privacy company Incogni indicates that OpenAI carries lower risk than some of its competitors, placing ChatGPT among the most privacy-friendly platforms assessed. The Gen AI and LLM Data Privacy Ranking 2026 gave ChatGPT the second-lowest overall privacy-risk score and found OpenAI offers the clearest information about it handles user data, although Incogni noted that opting out of training does not remove information that has already been incorporated into a model.
Monitoring Longer-Running AI Agents
OpenAI said the Private Safety Processing system, currently being tested with certain early customers, is designed to preserve ZDR commitments while allowing automated systems to detect risks from content that may only become apparent across multiple interactions or during longer-running agentic tasks.
When the system identifies a risk, OpenAI receives a signal indicating the type of activity involved, which it can use to determine whether enforcement is necessary. Customers can investigate alerts and enforcement decisions based on information available in their own systems, but they would need to share relevant information with OpenAI to appeal, clarify legitimate activity, or support an investigation into verified abuse.
For deployments that require ZDR, such as enterprises operating in highly regulated industries, data remains on the enterprise’s infrastructure that they control. OpenAI is also developing an option that uses its infrastructure and stores the data encrypted with keys controlled by the customer.
Both options will allow the system to identify patterns across related interactions without giving OpenAI personnel access to retained customer data, even when the underlying content is flagged, the company said.
“Often, potentially harmful intentions become clear only when multiple interactions are viewed together. Similar risks can arise when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research.”
Risks can also emerge during autonomous tasks if an AI agent becomes misaligned with the user’s intent by continuing to act after it is instructed to stop, or moving beyond its intended authority, as in recent cases of agents breaching external systems.
As autonomous agents take on longer and more complex tasks, this broader context will become increasingly important to distinguish legitimate activity from misuse and help to ensure that AI agents remain within the bounds of their intended operations, the company added.
Tightening Model Safety Controls While Keeping Enterprise Data Under Customer Control
The announcement comes shortly after OpenAI said it had temporarily slowed the pace of model scaling as it strengthened monitoring, alignment and security around increasingly capable frontier models. The company said it had paused reinforcement-learning training on its latest deployment models for two weeks while it hardened research environments and expanded monitoring. Its largest planned frontier reinforcement-learning run remains on hold, while smaller-scale training and evaluations continue.
The move followed an incident in which OpenAI models breached the AI platform Hugging Face during testing, alongside preliminary evidence that an upcoming model could meet the “critical cybersecurity capability” threshold under OpenAI’s Preparedness Framework.
The developments indicate the growing difficulty of monitoring AI systems that can operate for longer periods and interact with external systems. OpenAI’s updated monitoring approach is designed to examine sequences of activity for issues including unauthorised access, data theft, destructive behaviour and attempts to circumvent safeguards.
That same challenge sits at the center of Private Safety Processing, as OpenAI wants enough visibility to detect potentially dangerous patterns while limiting access to the sensitive information enterprises are putting into its models.
The company emphasized that addressing AI safety with effective safeguards requires collaboration with customers and partners of various sizes across different industries and regions, stating that “no AI lab can address emerging risks alone.”
OpenAI plans to start rolling out Private Safety Processing in September and publish a technical white paper detailing the approach.