Tech

OpenAI previews Private Safety Processing to keep zero data retention

Published

on

OpenAI has told enterprise customers that its promise not to keep their data will survive the next generation of models. The company set out the position on Wednesday in a post titled “Offering Zero Data Retention for frontier models”. In it, it previewed Private Safety Processing. The system looks for misuse across several related interactions at once, and OpenAI says its own staff never see the prompts or responses underneath.

Zero data retention, or ZDR, is an option for eligible API customers. OpenAI does not keep their prompts or model responses once it has processed a request. Its personnel cannot pull that content up for review. Enterprise data does not train the models either, unless a customer opts in. Those four promises are what the new system is meant to protect.

What Private Safety Processing is for

The company’s case rests on a limit it says it has hit. Today’s ZDR-compatible safety systems judge each interaction on its own. “The most serious AI safety risks are not always visible in a single interaction,” OpenAI wrote in the announcement. Harmful intent, it argues, often shows itself only when several exchanges are read together.

The post lists the patterns OpenAI wants to catch. Bad actors probe safeguards repeatedly. They coordinate across accounts. They dress threats up as routine research. The post also names a failure specific to agents. A system drifts from the user’s intent, then carries on acting after someone tells it to stop. British and US testers watched an agent fake identities in tests earlier this month.

Advertisement

Where the data sits

In ZDR deployments, customer content stays on infrastructure the customer controls. OpenAI is building a second option too. Content would sit on OpenAI infrastructure, under encryption keys the customer holds. OpenAI personnel hold no copy of those keys, the company says, so they cannot reach the content.

Automated review does the flagging. When it fires, OpenAI receives what it calls a narrowly defined signal, naming the type of activity involved. The company then decides whether to enforce. Its staff still cannot open the content. Customers investigate alerts through their own systems. They can also hand material over voluntarily, to appeal a decision or to help an abuse investigation.

Anthropic reached the opposite answer

The post names no rival, but it describes one. “Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring,” OpenAI wrote. For many organisations, it added, that requirement collides with their own security duties. It can also cut against promises they have made to the people they serve.

Anthropic set out the other position last week. It will require 30-day data retention on its most capable models. The policy “will be unpopular with customers who have come to expect zero retention”, the company wrote in its risk report. It expects real risks to its business, it said, especially if competitors do not follow. Retention is essential to catch attacks that span multiple requests, it argues.

Advertisement

Both firms describe the same problem. Dangerous behaviour shows up across requests rather than inside any one of them. They disagree on the remedy. The Wall Street Journal read the preview as a bid for business from Anthropic customers unhappy with the change.

Retention windows are contested well outside AI. Surveillance firm Flock Safety cut data retention to seven days this month, after dozens of police abuse cases.

Who is testing it

OpenAI says the preview runs with early customers. Bloomberg reported that those include Microsoft and Databricks. The post also names Glean and Abridge among the companies shaping the work. Sunil Agrawal, Glean’s chief information security officer, said OpenAI’s no-training commitment and ZDR give his firm the confidence to build on the models.

Aleah Houze, OpenAI’s head of product policy, gave reporters a worked example at a briefing. Someone asks about a weakness in a company’s software in one conversation. Later, in another, the same person asks about remote access and about which security tools can spot it. Read separately, each looks like ordinary research. “But when you look at them together in the broader context, you might detect that somebody is actually attempting a cyber attack,” Houze said.

Advertisement

What the scheme does not cover

The system targets eligible enterprise and API customers. Axios reported that it does not reach consumer ChatGPT plans. Data settings for Free, Plus, Go and Pro users stay as they are. ZDR never applied to those tiers.

One carve-out sits in the announcement’s own footnote. US law requires OpenAI to report apparent child sexual abuse material. It keeps images flagged as potential CSAM for manual review and for reporting, even in zero data retention deployments, exactly as it does today.

The September test

The technical detail is not public. OpenAI plans to start rolling out Private Safety Processing in September. It will publish a white paper at the same time. Until that paper lands, one claim in particular sits outside anyone else’s reach: that the system traces patterns across interactions while nobody at OpenAI reads them.

The preview also arrives in a busy month for the company’s safety machinery. OpenAI is rewriting its safety rules after the Hugging Face breach. Earlier in August it said it had slowed its next model over critical cyber risk.

Advertisement

European buyers have their own reason to read the September paper closely. Provider-side retention is awkward to sign off under GDPR, and under the sectoral rules covering health and financial records. That is the exact category of data OpenAI says its customers handle. A crop of European startups now sells companies control over their AI on that argument alone.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version