Skip to content
Rush Commerce
AI & Automation3 min read

OpenAI's zero-retention safety monitoring: read the terms

OpenAI is previewing Private Safety Processing — misuse detection across sessions with no customer data retained. What vendor retention policy means for you.

Every AI vendor has a retention policy, and almost nobody reads it until a customer's lawyer asks. On August 19, OpenAI started previewing Private Safety Processing — a system that watches for misuse across multiple conversations without keeping the underlying prompts or responses. It's a real engineering answer to a real tension. It's also a competitive shot, landing weeks after Anthropic told enterprise customers it would hold data for 30 days on covered models. If you push customer data through a model API, this is your contract, not their press release.

What actually happened

The tension is structural. Safety monitoring historically required someone — or something — to look at the content. Look at enough of it and you can spot a user who splits a malicious task across twenty innocuous-looking sessions. But looking means retaining, and retaining means your customers' data sits on a vendor's disk.

OpenAI's stated fix: run the analysis with automated agents that assess inputs and outputs across related conversations, then emit only a narrowly defined signal when something trips — a flag that says "this pattern occurred," not the text that produced it, per TechCrunch's reporting. Customer data can stay on customer-controlled infrastructure, or sit with OpenAI under customer-held encryption keys, Axios reports. If a signal fires and OpenAI wants to investigate, the customer chooses whether to hand over the content.

It's a preview to select customers, not general availability. OpenAI has said a broader rollout and a technical white paper are coming in September. Until that paper lands, the mechanism is a vendor claim, not a verified design.

Why AI data retention matters for your business

Here's the part that shows up in your business, not theirs.

If you run support tickets, invoices, patient intake, or contracts through a model API, your vendor's retention window is your breach window. Not hypothetically — a 30-day retention policy means a vendor-side incident 29 days from now exposes data you sent today. You did not choose that window. You inherited it when you picked a model.

That inheritance is now a competitive variable, which is the actual news. Two frontier labs are publicly differentiating on retention. That means it's negotiable, and it means it will keep changing. A policy you diligenced in March is not the policy running in August.

Three moves. Write the retention terms into your own customer-facing agreements — if you promise a client their data isn't retained and your model vendor quietly retains it for 30 days, that's your liability, not theirs. Keep the model layer swappable so a retention policy change is a config edit, not a legal crisis. And minimize at the source: strip names, card numbers, and account IDs before the payload leaves your infrastructure. The safest data for a vendor to retain is the data you never sent.

Key takeaways

  • OpenAI previewed Private Safety Processing on August 19 — cross-session misuse detection that emits a signal, not the content
  • Customer data can remain on customer infrastructure or under customer-controlled encryption keys
  • It contrasts with Anthropic's 30-day retention for covered models, which drew enterprise pushback
  • Preview only; broader rollout and a technical white paper are slated for September — treat the mechanism as unverified until then
  • Your vendor's retention window is your breach window; redact before the payload leaves your stack

Retention policy shouldn't be something you find out about after signing. We build AI systems with a redaction layer in front of the model and the vendor swappable behind it — so a policy change is a config edit, not a rebuild. See how we build, or tell us what data you're sending and where.

Sources: TechCrunch, Axios.

  • #ai-automation
  • #data-retention
  • #openai
  • #vendor-risk
  • #compliance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.