OpenAI says its most capable models will stay available with a hard privacy promise for eligible API customers: prompts and responses are not retained after a request is processed and stay off-limits to OpenAI staff. Enterprise customer data is not used for training unless the customer opts in.1
The harder part is what the company previewed alongside that promise on August 19. Private Safety Processing is an automated system designed, in OpenAI's words, to "identify patterns across related interactions without giving OpenAI personnel access to the underlying content."1
Why it matters: OpenAI has spent August committing to much heavier safety monitoring. The company says its expanded monitoring consumes roughly 20 percent of the inference compute being monitored.3 Monitoring wants to see everything; enterprise customers in finance and health want their data seen by no one. Some recent frontier deployments, OpenAI notes, have made retaining sensitive content a condition of safety monitoring. For many organizations, the company writes, "such requirements conflict with their security obligations or commitments to the people they serve."1 This is its attempt to hold both promises at once.
How it works, per OpenAI: customer content stays on infrastructure the customer controls, or, in an option still in development, in OpenAI storage encrypted with keys only the customer holds. Automated systems scan for misuse across related interactions. When something is flagged, OpenAI receives a "narrowly defined signal" naming the type of activity. OpenAI personnel never see the content itself, even during enforcement. Customers investigate alerts using their own systems and choose what to share if they appeal or support an abuse investigation.1
The company's rationale is that the most serious risks are not always visible in a single interaction: bad actors probing safeguards over time, coordinating across accounts or an agentic task drifting out of bounds — OpenAI's example is a system "continuing to act after being told to stop."1 As it put the trade-off on X: "safety systems also need to identify risks across related interactions."2
