OpenAI is addressing data retention, a primary objection for regulated-sector buyers adopting AI models.
On August 19, 2026, OpenAI reaffirmed Zero Data Retention (ZDR) for eligible API customers and previewing a system called Private Safety Processing. OpenAI states that under ZDR, it deletes customer prompts and outputs once processing completes, keeps that content out of reach of its own staff, and does not train on enterprise data unless the customer opts in.
Private Safety Processing detects risk patterns across multiple interactions rather than a single request, without giving OpenAI personnel access to the underlying content. When the system flags a risk, OpenAI receives only what it calls a “narrowly defined signal” about the category and severity. Customers investigate with their own tooling and may voluntarily share content to appeal or support an abuse case.
For CISOs in finance, healthcare, and federal programs, this targets the retention and access risk that stalls procurement sign-off. OpenAI describes two storage architectures. ZDR deployments keep content on customer-controlled infrastructure. A second option, storing content on OpenAI infrastructure under customer-held encryption keys, is in development with no general availability date. Private Safety Processing is currently in testing with a small group of early customers.
Before treating ZDR as an audit-ready control, verify two things. OpenAI claims no certifications like FedRAMP for this feature; ZDR remains a contractual and architectural commitment. Also confirm exactly what triggers an alert signal and what appeal recourse applies before relying on it for incident response.
Source: OpenAI



Leave a Reply