On August 19, OpenAI announced Private Safety Processing—a system that monitors for AI misuse across multiple conversations without retaining customer data . The pitch is direct: Anthropic requires a 30-day data hold for its most powerful models to keep them safe. OpenAI says it can do the same thing without holding your data. One company is asking for trust. The other is offering a guarantee.
The announcement comes as enterprise customers are increasingly caught between two competing demands: the need to detect sophisticated AI misuse, and the requirement to keep sensitive data under their own control.
OpenAI's answer is Private Safety Processing, a new automated safety system currently in preview with select customers and expected to roll out broadly in September.
OpenAI Doesn't Store. Anthropic Stores. That's the Divide.
The technical distinction is sharp. OpenAI's existing Zero Data Retention (ZDR) policy already promises that customer prompts and responses are not retained after processing. The limitation: safety monitoring only looked at individual sessions.
Private Safety Processing extends that monitoring across multiple related conversations. An actor probing a company's security vulnerabilities in one session and then asking about remote access in another might appear legitimate in isolation. Across sessions, the pattern becomes clear. OpenAI's automated systems can now detect that without storing the underlying data.
The privacy architecture is designed to be airtight. Customer content remains on customer-controlled infrastructure, or if stored by OpenAI, encrypted with keys only the customer holds. When the system detects suspicious activity, OpenAI receives only a "narrowly defined safety signal" indicating the type of activity—not the underlying conversation. OpenAI personnel cannot view customer content, even when flagged. If enforcement is needed, the customer can choose whether to share data with OpenAI.

Anthropic's Bet: "The Trade-Off Is Not Optional"
Anthropic's position is that data retention is not optional for safety. For its most capable "covered models"—Mythos and Fable series—Anthropic requires 30-day data retention. The company's reasoning: sophisticated misuse patterns only become visible across multiple requests, and detecting threats like state-sponsored espionage requires analyzing conversations together over time.
Anthropic is explicit about the trade-off. In a recent risk report, the company acknowledged that the retention requirement "will be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow)." But Anthropic still deems it necessary.
Human review can occur, though only through controlled access paths by approved reviewers, with tamper-proof logs. The 30-day clock starts from the interaction, after which data is automatically deleted.
Enterprise Customers Are Caught in the Middle
Private Safety Processing emerges from a moment when enterprise AI adoption is hitting a friction point. Organizations handling financial records, health data, or confidential business plans cannot simply allow an AI lab to retain their prompts. At the same time, AI models are becoming capable enough to pose real security risks if misused.
OpenAI is betting that enterprises will prefer automated monitoring over data retention. Anthropic is betting that safety requires the latter.
The market will decide. Microsoft and Databricks are already testing Private Safety Processing. But Anthropic's enterprise revenue growth suggests many customers are accepting the trade-off. The question is whether OpenAI's approach can match Anthropic's safety track record without the data.
The timing is not accidental. This is the same week OpenAI paused training on its most advanced models after a safety incident. The company is signaling that safety and privacy are not a trade-off—at least not in its view.
P.S. OpenAI plans to publish a technical white paper in September. The most revealing detail may not be the architecture, but how OpenAI measures the false positive rate. If the system flags legitimate activity too often, enterprises will lose trust. If it misses too much, the safety case collapses. Technical white papers are easy. Operational trust is not.
Frequently Asked Questions
Q: What is OpenAI's Private Safety Processing?
A: Private Safety Processing is a new safety system announced by OpenAI on August 19, 2026. It uses automated systems to detect potential AI misuse across multiple related conversations without retaining customer data. It extends OpenAI's existing Zero Data Retention (ZDR) policy, which already ensures that customer prompts and responses are not stored after processing.
Q: How is Private Safety Processing different from existing ZDR protections?
A: Under the existing ZDR policy, safety monitoring only evaluated each interaction individually, making it difficult to spot threats that unfold across multiple conversations. Private Safety Processing extends automated monitoring across related interactions, allowing the system to detect patterns that only become visible when multiple conversations are analyzed together.
Q: How does OpenAIs system protect customer privacy?
A: Customer content either remains on infrastructure controlled by the customer, or if stored by OpenAI, is encrypted with keys only the customer holds. OpenAI personnel do not have access to those keys and cannot view the underlying content. When the system detects a risk, OpenAI receives only a "narrowly defined safety signal" indicating the type of activity, not the actual conversation.
Q: What happens if the system flags suspicious activity?
A: Customers receive alerts and can investigate using information in their own systems. If OpenAI determines that further action is needed, it will reach out to the customer for more context. Customers have full discretion over whether to share relevant data with OpenAI.
Q: How does this compare to Anthropic's data retention policy?
A: Anthropic requires 30-day data retention for its most capable "covered models"—Mythos-class models and Fable 5. Anthropic argues that detecting sophisticated threats like state-sponsored espionage requires analyzing conversations together over time. OpenAI's Private Safety Processing is positioned as a competitive alternative that provides similar safety monitoring without requiring data retention.
Q: Does Anthropic allow human review of customer data?
A: Yes, but only through restricted channels. Human reviews are conducted by a small set of approved reviewers through controlled access paths. Each review session is recorded in tamper-proof logs that reviewers cannot suppress or modify.
Q: Can customers access Private Safety Processing now?
A: Private Safety Processing is currently in preview with select early customers, including Microsoft and Databricks. OpenAI plans a broader rollout in September 2026, when it will also publish a technical white paper on the system.
Q: Is Private Safety Processing available to consumer ChatGPT users?
A: No. The new safety system is designed for eligible enterprise and API customers, not for Free, Plus, Go, or Pro consumer ChatGPT users. OpenAI's ZDR controls do not apply to consumer plans.
Q: What is the "zero data retention" (ZDR) promise?
A: Under ZDR, OpenAI does not retain customer prompts or model responses after processing. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train OpenAI's models unless customers explicitly opt in.
