Preskočite na glavni sadržaj
OpenAI

19. august 2026.

KompanijaSigurnost

Offering Zero Data Retention for frontier models

Previewing Private Safety Processing, which strengthens safeguards across interactions while remaining compatible with ZDR.

Učitavanje…

Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review1, and enterprise customer data is not used to train our models unless customers explicitly opt-in.

As models take on longer, more complex tasks, some serious risks may only become visible across multiple interactions. Existing ZDR-compatible safety systems evaluate each interaction individually. Today, we’re previewing Private Safety Processing, which is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.

For ZDR deployments, customer content remains on infrastructure the customer controls. We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel.

Why safety systems need to evolve

The most serious AI safety risks are not always visible in a single interaction. Often, potentially harmful intentions become clear only when multiple interactions are viewed together. Similar risks can arise when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Risks can also develop over the course of an agentic task—for example, if a system becomes misaligned with the user’s intent by continuing to act after being told to stop.

As AI systems take on longer and more complex tasks, this broader context becomes increasingly important for distinguishing legitimate activity from misuse and ensuring that AI agents remain within the bounds of their intended authority.

Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve.

Private Safety Processing is designed so we can continue to offer ZDR.

How Private Safety Processing works

Private Safety Processing builds on the automated protections already used in ZDR and other deployments. Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content.

Private Safety Processing utilizes customer content regardless of where it is stored—whether in infrastructure customers control (ZDR deployments) or in storage provided by OpenAI. With OpenAI-provided storage, customer content is encrypted using keys controlled by the customer. OpenAI personnel do not have a copy of those keys, so they cannot access the underlying content.

When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved, similar to our existing safety systems today. That signal can be used to determine whether enforcement is necessary. OpenAI personnel do not receive access to the customer content even when it is flagged.

Customers can investigate alerts and enforcement decisions using information available in their own systems. If they want to appeal, clarify legitimate activity, or support an investigation into verified abuse, they can choose to share relevant information with OpenAI.

Private Safety Processing is currently being tested with early customers. We are sharing this preview now because we’ve heard our customers loud and clear that they need predictability about how their content will be protected as AI systems become more capable.

Dijagram kontrola pristupa sadržaju prikazuje API zahtjev koji ulazi u Privatnu sigurnosnu obradu, uz šifriranu pohranu pod kontrolom korisnika i automatizirani sigurnosni pregled. Korisnici primaju potpuna upozorenja i mogu podijeliti sadržaj s OpenAI-jem; OpenAI inače vidi samo kategoriju i ozbiljnost upozorenja, bez sadržaja korisnika.

Privacy and safety built with and for our customers

Our mission is to ensure that artificial general intelligence benefits all of humanity. Collaboration with customers and partners is essential to how we build effective safeguards. As our principles make clear, no AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes.

The organizations we work with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans, and proprietary research. Protecting that information is essential to meeting regulatory obligations, maintaining customer trust, and preserving their competitive advantage.

Njihove povratne informacije pomažu nam da izgradimo snažnije zaštitne mjere, dok njihove informacije ostaju pod njihovom kontrolom.

„Prihvatanje AI-ja u kompanijama u potpunosti zavisi od kontrole korisnika nad podacima, bez njihove direktne ili izvedene upotrebe izvan odabrane usluge. Obaveza OpenAI-ja da neće koristiti podatke za obuku i ZDR daju Gleanu povjerenje da razvija rješenja uz OpenAI. Kako modeli postaju sposobniji, OpenAI pokazuje da sigurnost može napredovati bez ugrožavanja privatnosti i kontrole na kojima počiva povjerenje kompanija.“

—Sunil Agrawal, glavni službenik za informacijsku sigurnost, Glean

Nastavit ćemo sarađivati s korisnicima na tehničkim i operativnim pojedinostima našeg pristupa. U septembru planiramo započeti uvođenje Privatne sigurnosne obrade i objaviti tehničku bijelu knjigu. Korisnike ćemo obavještavati u svakoj fazi: pravovremeno ćemo dijeliti novosti, objašnjavati šta one znače za postojeće obaveze te pružati vrijeme i podršku potrebne za planiranje.

Autor

OpenAI
  1. 1

    Kao i drugi pružatelji graničnih modela, OpenAI je zakonski obavezan(otvara se u novom prozoru) prijaviti sadržaj koji očigledno prikazuje seksualno zlostavljanje djece (CSAM). Slike označene kao mogući CSAM i dalje će se zadržavati radi ručnog pregleda i prijavljivanja, čak i u primjenama bez zadržavanja podataka, kao što je slučaj i danas.