OpenAI offers to keep nothing at all for frontier-model API customers
A companion system, Private Safety Processing, is meant to let automated abuse detection run across a customer's traffic without any employee seeing the prompts.
Original cover art, generated for this story. THE VISSION does not republish third-party press imagery.
- Approved API customers on OpenAI's frontier models can opt into Zero Data Retention, under which prompts and outputs are not stored after a request is processed.
- Customer content is not available for employee review and is not used for training unless the customer explicitly opts in.
- Private Safety Processing is previewing alongside it: automated systems look for misuse patterns across related interactions and return only a category-level risk signal, not the underlying content.
- The system is in testing with early customers and starts rolling out in September, with further technical detail promised then.
OpenAI said it will continue to offer Zero Data Retention for its frontier models to approved API customers, a configuration under which the company does not retain prompts or model outputs once a request has been served. Content under that arrangement is not available for employee review, and is not used to train OpenAI's models unless a customer explicitly opts in.
The harder problem the announcement addresses is that safety monitoring normally requires keeping the thing you are monitoring. As models take on longer and more autonomous work, the patterns worth catching stretch across many interactions rather than sitting inside a single prompt — and spotting those has historically meant retaining the traffic. OpenAI is previewing a system it calls Private Safety Processing to sever that dependency: automated systems examine related interactions for signs of misuse, and what reaches OpenAI is a limited signal naming the category of risky activity rather than the customer content that triggered it.
The company said the arrangement is being tested with early customers now and will begin rolling out in September, when it has promised more technical detail. Neither the eligibility criteria for approval nor the mechanism by which the safety signal is derived without exposing content has been published, which leaves the central claim — that pattern detection can run across retained-nothing traffic — resting on OpenAI's description of its own system rather than on anything an outside party can currently inspect.
Retention is the specific clause that stops regulated buyers — hospitals, banks, law firms — from putting real workloads on a frontier model, and it is a contractual objection rather than a capability one, so it is winnable without shipping a better model. The claim worth watching in September is the technical one: if safety classification genuinely runs without retention, it removes the standard argument that meaningful abuse monitoring and zero retention are mutually exclusive. If the detail shows the signal is derived from content held even briefly, buyers with a hard no-retention requirement are back where they started.