Productspublished

OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats

The select-customer preview tries to catch misuse spread across separate API sessions while keeping the provider from retaining the underlying conversations. Its practical test is whether automated signals can supply enough context for safety decisions.

By 2 min read
OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats

Listen to this story

The audio brief

About 1:29
0:001:29
Read transcript
OpenAI is previewing Private Safety Processing, a system designed to spot misuse that unfolds across multiple API conversations without retaining the conversations themselves. The trial is limited to select customers, but it tackles a real weakness in session-by-session monitoring: a request that looks harmless on its own may become suspicious when connected to other requests over time. OpenAI’s example is someone distributing malware-related development requests across separate sessions to evade isolated checks. The system extends OpenAI’s existing Zero Data Retention approach, which monitors activity without keeping customer data. Routine monitoring is automated, and OpenAI says conversations are not sent to human reviewers as part of that process. If the system detects a concerning pattern, it produces a narrowly defined signal and starts a review process—not an automatic penalty. OpenAI may ask the customer for context, and if deeper investigation is needed, the customer can choose whether to share relevant data. That makes the contrast with Anthropic’s policy important. For defined covered models, Anthropic allows sessions and conversations to be retained for 30 days for safety analysis, with human review through controlled access and tamper-proof logs. OpenAI is testing a different privacy-safety tradeoff: automated detection across a longer history, without holding the underlying chats. The key constraint is that Private Safety Processing is still an early, select-customer preview, so its practical effectiveness has not yet been established.

Story brief

3 key points

OpenAI is testing Private Safety Processing with select customers as a way to identify misuse patterns spanning multiple conversations while maintaining a no-retention boundary. The system is automated in routine operation and produces a limited signal rather than imposing immediate enforcement; customers may be asked for context and can choose whether to share data for deeper investigation. The preview positions...

  1. 01

    The preview extends Zero Data Retention monitoring from individual sessions to patterns across multiple conversations.

  2. 02

    OpenAI’s example involves distributing malware-related requests across sessions to evade isolated checks.

  3. 03

    A trigger is not an automatic penalty; OpenAI may seek customer context before deciding on action.

OpenAI is previewing Private Safety Processing, a system for select customers that is meant to detect potential misuse across several conversations without retaining customer data. OpenAI says the monitoring is automated and does not send conversations to human reviewers as part of the routine process.

From one session to a longer pattern

The change is in the scope of the safety check. OpenAI’s existing Zero Data Retention approach monitors API activity for abuse on a session-by-session basis without retaining customer data. Private Safety Processing extends that approach by assessing inputs and outputs from multiple conversations over time.

That wider view addresses a specific evasion problem: activity that appears ordinary in isolation may form a concerning pattern when connected across sessions. OpenAI gave the example of a person spreading requests related to malware development across separate conversations to avoid detection.

A trigger starts a review process, not an automatic penalty

When the system triggers, OpenAI says it may receive a narrowly defined signal about a particular type of activity. The signal does not automatically result in enforcement: OpenAI may contact the customer for context before deciding whether action is necessary. If more investigation is needed, the customer may choose whether to share relevant data with OpenAI.

Anthropic’s policy applies to a defined model category

The comparison is narrower than a blanket divide over enterprise privacy. Anthropic largely follows Zero Data Retention outside covered models, according to the policy description. For covered models, however, its policy permits the company to keep sessions and their conversations for 30 days so it can analyze potential safety problems.

Anthropic says human review can occur through a controlled access path involving a small group of approved reviewers. It also says each review session is recorded in a tamper-proof log that reviewers cannot suppress or alter. That approach keeps material available for inspection under stated access controls; OpenAI’s preview instead puts its safety case on automated detection before any customer decides to provide more data.

The product claim is a new privacy-safety tradeoff

Private Safety Processing is still a preview limited to select customers. But its distinct promise is clear: OpenAI says it can look for misuse that unfolds across a longer sequence of interactions while preserving a no-retention boundary. The result is a different answer to the central enterprise question—how a provider can seek signs of misuse without holding the underlying conversations for later analysis.

Sources

  1. techcrunch.comOpenAI seeks to one-up Anthropic with new customer privacy protections | TechCrunch