cd /news/ai-safety/openai-previews-cross-session-safety… · home topics ai-safety article
[ARTICLE · art-103466] src=runtimewire.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

OpenAI previews cross-session safety checks designed to preserve zero data retention

OpenAI CEO Sam Altman announced Wednesday that OpenAI will preserve zero data retention for eligible API customers while introducing Private Safety Processing, a system designed to detect misuse across multiple related interactions without exposing customer prompts. The company is testing the system with early customers and plans to roll it out in September, alongside a technical white paper. This move positions privacy-preserving monitoring as a competitive feature for enterprise AI adoption.

read4 min views1 publishedAug 19, 2026
OpenAI previews cross-session safety checks designed to preserve zero data retention
Image: Runtimewire (auto-discovered)

Private Safety Processing will trace risk patterns across related API interactions while giving OpenAI only limited safety signals.

By Ryan Merket · Published

Primary source: Sam Altman on X

Why it matters #

Enterprise AI vendors need context across long-running agent tasks to detect abuse, but retaining customer prompts can block adoption. OpenAI is making privacy-preserving monitoring a competitive feature.

Sam Altman (@sama), OpenAI's co-founder and CEO, said Wednesday that OpenAI will preserve zero data retention for eligible API customers as it introduces safety systems capable of detecting misuse across multiple related interactions.

OpenAI calls the system Private Safety Processing. The company is testing it with early customers and plans to begin rolling it out in September, when it also expects to publish a technical white paper.

Altman compressed the sales pitch into five words on X: "we support business privacy!" The underlying announcement addresses a mounting problem for AI vendors and their enterprise customers. Longer agentic tasks can spread risky behavior across many prompts, accounts or sessions, while businesses handling medical records, financial information, proprietary code and internal plans often cannot permit a model provider to retain that material for later review.

How Private Safety Processing works

OpenAI's existing Zero Data Retention program excludes customer content from abuse-monitoring logs for approved organizations using eligible API features. The company's current API data-control documentation says standard abuse-monitoring logs can otherwise contain prompts and responses and are generally retained for up to 30 days.

Existing ZDR-compatible safeguards evaluate interactions individually. Private Safety Processing is intended to recognize patterns across related interactions, including repeated attempts to probe safeguards, activity coordinated across accounts and agents that continue acting after a user tells them to stop.

For ZDR deployments, OpenAI says the underlying prompts and responses will remain on infrastructure controlled by the customer. OpenAI is also developing a configuration in which the content can sit on its infrastructure while encrypted with keys held by the customer. OpenAI personnel would not possess copies of those keys. Automated systems would process the protected content and return a narrowly defined signal describing the category of suspected activity. OpenAI says its personnel would receive that signal, which could support an enforcement decision, without gaining access to the prompts or model responses that produced it.

Customers would retain the records needed to investigate an alert. They could then choose to share relevant material with OpenAI when contesting an enforcement decision, explaining legitimate activity or assisting with an investigation into verified abuse.

Privacy becomes part of the model competition

OpenAI explicitly positioned the design against frontier-model deployments that require customers to permit content retention for safety monitoring. The appeal is commercial as much as technical: a stronger model has limited value inside a regulated company if adopting it forces security teams to surrender control of sensitive data.

OpenAI already says business data from its API and enterprise products is excluded from model training by default, unless a customer opts in. ZDR goes further by limiting retention for abuse monitoring and application state on eligible services. Private Safety Processing is OpenAI's attempt to extend that promise as its models take on work that unfolds across longer time horizons.

The announcement features Glean, Databricks, Abridge and Microsoft as customers helping shape the approach. Glean security chief Sunil Agrawal said enterprise adoption depends on customers retaining control of their information and preventing direct or derivative uses outside the service they selected.

That customer lineup points to the market OpenAI is protecting. Search, data infrastructure, healthcare and workplace software companies routinely process records that cannot be placed into a general-purpose review queue. Preserving ZDR gives those businesses a path to deploy frontier models without rewriting their data-governance commitments around the needs of the model provider.

Zero retention still has boundaries

ZDR is an approval-based API control rather than a blanket promise covering every OpenAI product and feature. OpenAI's documentation lists several capabilities that store application state or remain incompatible with ZDR. Background processing and Code Interpreter, for example, cannot be used under the standard ZDR configuration described in the current documentation.

There is also a legal and safety exception for images flagged as potential child sexual abuse material. OpenAI says those images will continue to be retained for human review and legally required reporting, including in ZDR deployments.

The September white paper will carry the technical burden behind the announcement. It will need to explain how processing is isolated, how customer-controlled keys operate in practice, what information the limited safety signals contain and how the system handles false positives without exposing the underlying content. OpenAI has laid out the product architecture and enforcement flow. Its enterprise privacy pitch now depends on proving that the machinery preserves the boundary Altman advertised.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-previews-cros…] indexed:0 read:4min 2026-08-19 ·