{"slug": "openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge", "title": "OpenAI chases Anthropic's biz customers with zero data retention pledge", "summary": "OpenAI announced Private Safety Processing, a mechanism that scans customer model interactions for safety risks without retaining data, aiming to attract business customers from rival Anthropic. OpenAI's zero data retention (ZDR) pledge contrasts with Anthropic's policy, which retains prompts and outputs for covered models like Mythos 5 and Fable 5 for 30 days for safety review. OpenAI's automated systems will flag potential misuse without exposing data to personnel, with human review only for child exploitation material.", "body_md": "ai and ML\n\n# OpenAI chases Anthropic's biz customers with zero data retention pledge\n\nWith Private Safety Processing, AI biz promises discreet, automated prompt surveillance\n\nOpenAI appears to have found a way to balance AI model safety with commitments to retain no customer data, a feat rival Anthropic hasn't yet managed. For orgs concerned about who has access to their data, this could be a game-changer.\n\nThe free-spending AI biz on Wednesday [announced](https://openai.com/index/offering-zero-data-retention-for-frontier-models/) Private Safety Processing, a mechanism for automatically scanning customer model interactions for safety risks without violating Zero Data Retention (ZDR) commitments.\n\nAnthropic meanwhile has noted that its implementation of ZDR includes a non-zero amount of data retention for [covered models](https://support.claude.com/en/articles/15425695) – currently Mythos 5 and Fable 5. For commercial customers using ZDR [as of June 9, 2026](https://support.claude.com/en/articles/15425996-data-retention-practices-for-covered-models), \"we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered.\"\n\nOpenAI, Anthropic, and various other AI model makers agree some oversight of rapidly advancing model capabilities is a good idea. The devil is in the details, which in the case of Private Safety Processing have not yet been published.\n\nGenerally speaking, both companies have similar policies for commercial customers using lower tier models.\n\n\"For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation,\" Anthropic [says](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data), with exceptions for certain services, ZDR agreements, and legal/policy enforcement.\n\nFor OpenAI [ChatGPT Business customers](https://openai.com/enterprise-privacy/), \"Your workspace admins can control how long your data is retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm.\" That 30-day policy also applies to OpenAI's API in most cases.\n\nWhen Anthropic detects [usage violations](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data), it may retain model inputs and outputs for up to two years and trust and safety classification scores for up to seven years.\n\nThe major distinction now is ZDR and how the two frontier AI companies define that concept.\n\nAnthropic has a ZDR exception for those using its top models.\n\nFor OpenAI ZDR deployments, customers may control the infrastructure or they may choose to store data on OpenAI infrastructure, where OpenAI says it will soon provide customer-controlled encryption keys.\n\n\"In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel,\" the company explains in its post.\n\nAnthropic allows more room for human review when content is flagged by its automated systems. \"By default, no Anthropic personnel can read your retained conversations,\" the company says in its documentation. \"Human review can occur only through a controlled access path—for example, when content is flagged by our automated trust and safety systems for potential harm.\"\n\nOpenAI's human intervention scenario is narrow – in the event child exploitation material is detected.\n\nWith the addition of Private Safety Processing – to be explained in more detail next month, OpenAI insists – whatever data gets stored is unavailable to company personnel.\n\n\"Private Safety Processing builds on the automated protections already used in ZDR and other deployments,\" the AI biz explains. \"Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content.\"\n\nWhat's noteworthy about this beyond the privacy commitment is the company's expanded interest in \"related interactions.\" That suggests OpenAI's safety assessment is looking not just at prompt input and output but tool use and network data signals.\n\nKeeping AI interactions and data flows private has become a major concern. Apple has its Private Cloud Compute. Google has its Private AI Compute. Nvidia offers [Confidential Computing](https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/). Even Meta, not exactly known for its commitment to privacy, talks up its [Private Processing for AI](https://engineering.fb.com/2025/04/29/security/whatsapp-private-processing-ai-tools/). And much of the interest in running local AI models reflects a desire to keep sensitive data safe from potentially prying service providers and adversaries.\n\nOpenAI may have read the room well with its celebration of private model policing, but as Matthew Green, associate professor of computer science at Johns Hopkins University, observed recently, \"[private inference isn't private enough](https://blog.cryptographyengineering.com/2026/06/09/apples-siri-ai-or-more-shouting-into-the-void-about-private-agents/).\"\n\nGreen notes that AI agents – models connected to tools – often rely on sensitive data when they act on our behalf, and while private inference may protect some part of the data flowing to and from AI agents, there are many other gaps in the system.\n\n\"At the risk of saying more obvious things, the difference between a helpful private agent, a corporate advertising bot, and a government spy comes down mainly to a matter of prompting, and maybe a bit of model fine-tuning,\" he wrote. \"Once you combine private data access and the ability to send messages, there is essentially no technical protection that private inference alone can offer.\" ®", "url": "https://wpnews.pro/news/openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge", "canonical_source": "https://www.theregister.com/ai-and-ml/2026/08/20/openai-chases-anthropics-biz-customers-with-zero-data-retention-pledge/5290609", "published_at": "2026-08-20 19:59:00+00:00", "updated_at": "2026-08-20 20:42:51.302582+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-products"], "entities": ["OpenAI", "Anthropic", "Private Safety Processing", "Mythos 5", "Fable 5", "ChatGPT Business"], "alternates": {"html": "https://wpnews.pro/news/openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge", "markdown": "https://wpnews.pro/news/openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge.md", "text": "https://wpnews.pro/news/openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge.txt", "jsonld": "https://wpnews.pro/news/openai-chases-anthropic-s-biz-customers-with-zero-data-retention-pledge.jsonld"}}