OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats
The select-customer preview tries to catch misuse spread across separate API sessions while keeping the provider from retaining the underlying conversations. Its practical test is whether automated signals can supply enough context for safety decisions.
Listen to this story
The audio brief
Story brief
3 key pointsOpenAI is testing Private Safety Processing with select customers as a way to identify misuse patterns spanning multiple conversations while maintaining a no-retention boundary. The system is automated in routine operation and produces a limited signal rather than imposing immediate enforcement; customers may be asked for context and can choose whether to share data for deeper investigation. The preview positions...
- 01
The preview extends Zero Data Retention monitoring from individual sessions to patterns across multiple conversations.
- 02
OpenAI’s example involves distributing malware-related requests across sessions to evade isolated checks.
- 03
A trigger is not an automatic penalty; OpenAI may seek customer context before deciding on action.
OpenAI is previewing Private Safety Processing, a system for select customers that is meant to detect potential misuse across several conversations without retaining customer data. OpenAI says the monitoring is automated and does not send conversations to human reviewers as part of the routine process.
From one session to a longer pattern
The change is in the scope of the safety check. OpenAI’s existing Zero Data Retention approach monitors API activity for abuse on a session-by-session basis without retaining customer data. Private Safety Processing extends that approach by assessing inputs and outputs from multiple conversations over time.
That wider view addresses a specific evasion problem: activity that appears ordinary in isolation may form a concerning pattern when connected across sessions. OpenAI gave the example of a person spreading requests related to malware development across separate conversations to avoid detection.
A trigger starts a review process, not an automatic penalty
When the system triggers, OpenAI says it may receive a narrowly defined signal about a particular type of activity. The signal does not automatically result in enforcement: OpenAI may contact the customer for context before deciding whether action is necessary. If more investigation is needed, the customer may choose whether to share relevant data with OpenAI.
Anthropic’s policy applies to a defined model category
The comparison is narrower than a blanket divide over enterprise privacy. Anthropic largely follows Zero Data Retention outside covered models, according to the policy description. For covered models, however, its policy permits the company to keep sessions and their conversations for 30 days so it can analyze potential safety problems.
Anthropic says human review can occur through a controlled access path involving a small group of approved reviewers. It also says each review session is recorded in a tamper-proof log that reviewers cannot suppress or alter. That approach keeps material available for inspection under stated access controls; OpenAI’s preview instead puts its safety case on automated detection before any customer decides to provide more data.
The product claim is a new privacy-safety tradeoff
Private Safety Processing is still a preview limited to select customers. But its distinct promise is clear: OpenAI says it can look for misuse that unfolds across a longer sequence of interactions while preserving a no-retention boundary. The result is a different answer to the central enterprise question—how a provider can seek signs of misuse without holding the underlying conversations for later analysis.
Sources
- techcrunch.comOpenAI seeks to one-up Anthropic with new customer privacy protections | TechCrunch