OpenAI has reaffirmed its Zero Data Retention (ZDR) policy for eligible API customers and previewed Private Safety Processing. This new system aims to strengthen safeguards across interactions while remaining compatible with ZDR.
According to OpenAI, ZDR ensures that customer prompts and model responses are not retained after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train models unless customers explicitly opt-in. The company plans to start rolling out Private Safety Processing and share a technical white paper in September.
Key Points
- OpenAI reaffirms Zero Data Retention for eligible API customers.
- Private Safety Processing is being previewed to enhance AI safety.
- ZDR means OpenAI does not retain prompts or model responses after processing a request.
- Customer content under ZDR is not available to OpenAI personnel for review.
- Enterprise customer data is not used for model training unless customers opt-in.
- Private Safety Processing identifies patterns across related interactions without exposing content to OpenAI personnel.
- OpenAI plans to roll out Private Safety Processing and release a white paper in September.
Context
OpenAI states that as models undertake longer and more complex tasks, some risks may only become apparent across multiple interactions. Existing ZDR-compatible safety systems evaluate each interaction individually. Private Safety Processing is designed to address this by identifying patterns across related interactions, according to OpenAI. This system operates without giving OpenAI personnel access to the underlying content.
For ZDR deployments, customer content remains on infrastructure controlled by the customer. OpenAI is also developing an option for content storage on its own infrastructure, encrypted with customer-controlled keys. In both scenarios, automated systems can identify potential misuse and return limited safety signals without exposing prompts or responses to OpenAI personnel.
Why It Matters
This development indicates OpenAI's effort to balance advanced AI safety measures with customer data privacy and control. It addresses concerns from organizations that handle sensitive information and have security obligations that conflict with data retention requirements for safety monitoring.
What To Do
- Eligible API customers should review the reaffirmed Zero Data Retention policy.
- Customers interested in enhanced safety features should watch for updates on Private Safety Processing.
- Prepare for the rollout of Private Safety Processing and the release of its technical white paper in September.
- Note that images flagged for potential child sexual abuse material will continue to be retained for review and reporting, even in ZDR deployments.
