Policy

OpenAI adds Private Safety Processing to detect misuse

OpenAI has introduced Private Safety Processing, a feature that detects multi-step system abuse while maintaining strict zero data retention policies for enterprise customers.

Computerworld AI3 days agoPolicy
Image: Computerworld AI

OpenAI is testing a new safety feature called Private Safety Processing with eligible enterprise and API customers. The system is designed to identify patterns of misuse that unfold over multiple interactions, addressing a key limitation in traditional safety controls that only evaluate prompts individually. This capability allows organizations to monitor for complex risks—such as coordinated account activity or repeated attempts to probe safeguards—while upholding OpenAI's Zero Data Retention commitments.

Instead of keeping or exposing the underlying prompts and responses to OpenAI personnel, the automated system analyzes interactions to generate a restricted signal indicating the type of activity detected. This process functions whether the customer's data remains within their own infrastructure or is stored by OpenAI using customer-controlled encryption keys. According to Greyhound Research chief analyst Sanchit Vir Gogia, this architecture shifts the forensic burden to the client, meaning "the customer to hold the case while the provider holds the alarm."

This approach contrasts with competitors like Anthropic, which retain customer interaction data for a period to conduct safety investigations. For enterprise practitioners, OpenAI's signal-based architecture means security teams must use their own systems to investigate alerts, though they can choose to share data with OpenAI for appeals. While this places the responsibility of verification on the enterprise, it significantly reduces data privacy risks.

Gartner senior principal analyst Apeksha Kaushik noted that privacy-preserving safety models like this could lower adoption barriers in highly regulated industries, including healthcare and financial services. By aligning with compliance frameworks such as GDPR and HIPAA, Private Safety Processing may help risk-averse organizations deploy generative AI tools more confidently, provided their legal teams verify that the implementation meets specific regulatory requirements.

This is our own summary of reporting by Computerworld AI

More in Policy