---
type: "post"
slug: "openai-zero-data-retention-for-frontier-models"
title: "OpenAI Zero Data Retention for frontier models"
description: "OpenAI previewed Private Safety Processing so abuse patterns can be detected across related interactions without staff reading customer content, keeping Zero Data Retention available."
retrieval_nugget: "OpenAI previewed Private Safety Processing so abuse patterns can be detected across related interactions without staff reading customer content, keeping Zero Data Retention available."
published_at: "2026-08-30"
updated_at: "2026-09-12"
record_date: "2026-08-19"
date_kind: "published_at"
topics: ["agent-retrieval","agents","ai","search"]
entities: ["OpenAI"]
source_url: "https://openai.com/index/offering-zero-data-retention-for-frontier-models/"
source_title: "Offering Zero Data Retention for frontier models"
source_domain: "openai.com"
source_terms: ["OpenAI","Zero","Retention","frontier","models"]
summary_word_count: 191
schema_version: "newruntime-agent-readable-v0.2"
stable_id: "post:openai-zero-data-retention-for-frontier-models"
status: "published"
source_urls: ["https://openai.com/index/offering-zero-data-retention-for-frontier-models/"]
visuals: []
editorial_provenance: {"schema_version":"newruntime-editorial-copy-v1","content_status":"source_grounded_final","final_copy_sha256":"sha256:e9d6c21fe7625025534aa3394670168a8b465ce69f70770fb3a0805b67df3878","reviewed_at":"2026-09-12T10:00:00Z","source_evidence_count":1,"verified_claim_count":2,"site_analysis_schema_version":"newruntime-site-analysis-v1","site_object_kind":"field_note","observed_fact_count":2,"implication_count":1,"watch_condition_count":1,"related_record_count":2}
analysis: {"schema_version":"newruntime-site-analysis-v1","object_kind":"field_note","thesis":"OpenAI previewed Private Safety Processing on 19 August, a safety layer designed to look across related interactions without giving OpenAI personnel access to the underlying content.","observed_facts":[{"text":"Zero Data Retention promises eligible API customers that prompts and responses are not retained after a request is processed.","source_urls":["https://openai.com/index/offering-zero-data-retention-for-frontier-models/"]},{"text":"Private Safety Processing is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.","source_urls":["https://openai.com/index/offering-zero-data-retention-for-frontier-models/"]}],"mechanism":"For ZDR deployments customer content stays on infrastructure the customer controls, with a further option being developed in which content sits on OpenAI infrastructure encrypted under customer-held keys; in both cases automated systems return limited safety signals rather than exposing prompts or responses.","why_now":"The reason this arrives now is that some recent frontier-model deployments required customers to permit retention for safety monitoring, which collides with their own security obligations.","implications":["That framing puts retention policy inside the [agent security](https://newruntime.com/topics/agent-security/) boundary rather than beside it, and it rhymes with the way [GPT-6 Astra turned the API call into a managed run](https://newruntime.com/posts/gpt-6-astra-managed-run-contract/)."],"evidence_boundary":"This is a preview, and the announcement describes design intent rather than an audited deployment.","watch_conditions":["The condition to watch is whether the customer-held-key option ships with a published key-handling and signal scope, because without that the phrase private safety processing stays a promise about internal access controls."],"related_records":[{"url":"https://newruntime.com/topics/agent-security","relation":"Topic hub for the access and authority boundary this policy sits inside."},{"url":"https://newruntime.com/posts/gpt-6-astra-managed-run-contract","relation":"Prior coverage of provider-managed runs reshaping the API contract."}]}
routes: {"html":"https://newruntime.com/posts/openai-zero-data-retention-for-frontier-models/","markdown":"https://newruntime.com/posts/openai-zero-data-retention-for-frontier-models.md","json":"https://newruntime.com/posts/openai-zero-data-retention-for-frontier-models.json"}
---

# OpenAI Zero Data Retention for frontier models

## Retrieval answer

OpenAI previewed Private Safety Processing so abuse patterns can be detected across related interactions without staff reading customer content, keeping Zero Data Retention available.

OpenAI previewed Private Safety Processing on 19 August, a safety layer designed to look across related interactions without giving OpenAI personnel access to the underlying content. Zero Data Retention already promises eligible API customers that prompts and responses are not retained after a request is processed, and that enterprise content is not used for training unless the customer opts in. The new piece addresses the gap that made that promise awkward for frontier deployments: existing ZDR-compatible safety systems evaluate each interaction individually.

The mechanism is deliberately narrow. For ZDR deployments customer content stays on infrastructure the customer controls, with a further option being developed in which content sits on OpenAI infrastructure encrypted under customer-held keys; in both cases automated systems return limited safety signals rather than exposing prompts or responses. The reason this arrives now is that some recent frontier-model deployments required customers to permit retention for safety monitoring, which collides with their own security obligations.

The stated risk model is about sequences, not single messages: repeated probing of safeguards, coordination across accounts, threats disguised as research, or an agentic task that keeps acting after being told to stop. That framing puts retention policy inside the [agent security](https://newruntime.com/topics/agent-security/) boundary rather than beside it, and it rhymes with the way [GPT-6 Astra turned the API call into a managed run](https://newruntime.com/posts/gpt-6-astra-managed-run-contract/).

This is a preview, and the announcement describes design intent rather than an audited deployment. The condition to watch is whether the customer-held-key option ships with a published key-handling and signal scope, because without that the phrase private safety processing stays a promise about internal access controls.
