OpenAI says Zero Data Retention survives its new safety monitoring. It guarantees that no human looks, not that nothing reads
Private Safety Processing spots abuse across related interactions without personnel access, and OpenAI concedes that recent frontier deployments have required customers to allow retention for monitoring. Retention, access and processing are three promises, and only two are made.
By Parminder Kumar Sharma · · 6 min read

What was announced
On 19 August 2026 OpenAI published a post reaffirming Zero Data Retention for eligible API customers and previewing a system called Private Safety Processing. The promise it restates is precise:
Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed.
The new part addresses a problem the company states plainly, and this is the sentence that makes the post worth reading rather than skimming:
Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve.
That is an admission, and it arrives one day after the Astra safety update in which monitoring was described as consuming roughly 20% of the inference compute being monitored. Read in sequence, the two posts say: we have greatly expanded what we watch, and here is why you can still buy it.
Three promises, and only one of them is on the tin
Private Safety Processing extends automated checks across related interactions rather than evaluating each one alone, because, as the post says, harmful intent often becomes visible only when several are read together. OpenAI's own diagram labels the parts: customer-controlled data storage "encrypted under customer control", an automated safety review that identifies abuse "without human review or customer content retention on OpenAI servers", and an alert of which "OpenAI can only see the category and severity", carrying no customer content.
Take that at face value, because there is no reason not to. It is real privacy engineering and it is better than the alternative the post describes. It also answers one question while leaving two others standing.
What crosses the line, and what the promise is silent about
Three things are true at once
Preview · 19 Aug 2026
Customer side
Customer-controlled storage
Encrypted under keys OpenAI does not hold
The part the promise is silent about
Automated safety review
Reads the content across related interactions. No personnel access, and no human review
Reaches OpenAI
Category and severity
The only thing that crosses on its own
The return path, drawn as a neutral arrow in the original
The content, volunteered
To contest an enforcement decision, the customer chooses to share what ZDR was protecting
Zero Data Retention is a promise about retention and about who may look. It was never a promise that nothing reads the content, and a system designed to spot a pattern across interactions cannot be one. Both statements can be true, and only one of them is on the tin.
Retention, personnel access and processing are separate guarantees
| The guarantee | What is stated | What it does not settle |
|---|---|---|
| Retention | Prompts and responses are not retained after a request is processed | How long processing lasts, and what derived signals persist afterwards |
| Personnel access | OpenAI personnel do not have access, and hold no copy of customer keys | Nothing. This one is clear, and it is the strongest claim on the page |
| Processing | Automated systems identify patterns across related interactions | That the content is read by machine is implied rather than stated, and it is the whole mechanism |
| The outbound signal | OpenAI sees only category and severity, with no customer content | What a long series of categorised alerts on one account reveals in aggregate |
Zero Data Retention is a promise about retention and about who may look. It was never a promise that nothing reads the content, and a system built to spot a pattern across interactions cannot be one. Both things are true at once. Only one of them is what a procurement officer hears in the phrase.
The appeal path is where the burden moves
The part of the diagram worth the most attention is the smallest. When the automated review fires, the customer receives an alert, and:
Customers can investigate alerts and choose to share content with OpenAI.
The post adds that a customer may share information "if they want to appeal, clarify legitimate activity, or support an investigation into verified abuse".
Follow that through. Enforcement can proceed on a category and a severity. Contesting it means handing over the content that Zero Data Retention existed to keep back. It is described as a choice, and it is one, in the way that any choice with a single tolerable outcome is a choice.
This is not a trick, and no other design is obviously available: OpenAI cannot adjudicate an appeal about content it cannot see. It is worth naming because it is the one route by which customer content reaches OpenAI under this architecture, and because it will not be the paragraph anybody quotes.
It is a preview, not a product
The post says Private Safety Processing "is currently being tested with early customers", and describes the OpenAI-hosted, customer-keyed storage variant as something the company is "also developing".
Coverage will report this as available. A buyer being told this week that ZDR now coexists with full safety monitoring should ask which of the two storage models they would actually be getting, and whether the answer is one that exists today.
Take this with you
Questions for the contract, not the blog post
- Ask which storage model applies to you. Content in infrastructure you control is a materially different arrangement from content on OpenAI infrastructure under your keys, and only the first is described as available now.
- Ask what the safety signal contains, field by field, and get it in writing. Category and severity is a good answer. It is also a channel, and a long run of categorised alerts on one account carries more than any single alert does.
- Ask what derived artefacts survive processing. Zero retention of prompts and responses is not the same as zero retention of scores, embeddings, hashes or flags computed from them.
- Ask what happens on enforcement before you appeal. If suspension can follow from a category and a severity, your continuity plan needs a path that does not depend on disclosing the content you bought ZDR to protect.
- Ask your own regulator-facing question: whether machine processing of content by a provider, with no human access, is a disclosure under the obligations you are actually subject to. It is a legal question and the answer differs by regime.
The position
This is a serious piece of work and the criticism it deserves is narrow.
OpenAI has been open about the pressure it is under, has not pretended that safety monitoring is free, and has built something that keeps human eyes off customer content while still catching cross-interaction abuse. The engineering is better than the industry norm and the post is more candid than it needed to be.
What it cannot do is make the phrase mean what buyers think it means. Zero Data Retention describes retention and personnel access. It has never described processing, and the system announced this week is one whose entire purpose is to process. A customer reading the two words and concluding that nothing at OpenAI reads their prompts will be wrong, and will have been misled by the industry's vocabulary rather than by this announcement.
This is the third piece here in a week where the published artefact is accurate and answers a narrower question than the reader is asking, after a framework that never named who produces its evidence and a breach notice that left the data types as a merge field. The pattern is not dishonesty. It is that precise documents are read imprecisely, and the gap is where the risk lives.
Sources
- PrimaryOffering Zero Data Retention for frontier models, 19 August 2026OpenAIaccessed 2026-08-20
- PrimaryPacing model development in an era of cyber-critical capabilities, 18 August 2026OpenAIaccessed 2026-08-20


