{"id":9214,"date":"2026-08-21T09:45:36","date_gmt":"2026-08-21T09:45:36","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9214"},"modified":"2026-08-21T09:45:36","modified_gmt":"2026-08-21T09:45:36","slug":"openai-adds-an-ai-safety-layer-to-detect-misuse-without-retaining-enterprise-data","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9214","title":{"rendered":"OpenAI adds an AI safety layer to detect misuse without retaining enterprise data"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOpenAI does not retain\u2026prompts or model responses after a request is processed,\u201d the company <a href=\"https:\/\/openai.com\/index\/offering-zero-data-retention-for-frontier-models\/\" target=\"_blank\" rel=\"noopener\">said<\/a> in a blog post, describing its ZDR approach. The new system, called Private Safety Processing, is \u201cdesigned to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The capability is being tested with eligible enterprise and API customers and is intended to address a limitation in existing safety controls that evaluate interactions individually, making it harder to detect risks that unfold over time.<\/p>\n<h2 class=\"wp-block-heading\">What does Private Safety Processing do<\/h2>\n<p class=\"wp-block-paragraph\">Private Safety Processing is designed to extend existing safety systems by correlating activity across related interactions rather than analyzing each prompt in isolation, according to OpenAI.<\/p>\n<p class=\"wp-block-paragraph\">Under the model, automated systems analyze interactions and generate \u201ca narrowly defined signal indicating the type of activity involved,\u201d instead of exposing the underlying prompts or responses, according to OpenAI.<\/p>\n<p class=\"wp-block-paragraph\">The system can operate whether customer data remains within enterprise-controlled infrastructure or is stored by OpenAI with encryption keys controlled by the customer, the company said.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel,\u201d the post added.<\/p>\n<h2 class=\"wp-block-heading\">Why existing safety controls fall short<\/h2>\n<p class=\"wp-block-paragraph\">OpenAI said the new capability is intended to address a gap in the detection of AI risks.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe most serious AI safety risks are not always visible in a single interaction,\u201d the company said, noting that harmful intent may only become clear when multiple interactions are viewed together.<\/p>\n<p class=\"wp-block-paragraph\">Such risks include repeated attempts to probe safeguards, coordinated activity across accounts, and misuse that emerges over a sequence of interactions, according to the company.<\/p>\n<p class=\"wp-block-paragraph\">As AI systems take on longer and more complex tasks, evaluating individual prompts in isolation can limit the ability to identify such patterns, OpenAI said in the post.<\/p>\n<h2 class=\"wp-block-heading\">Diverging approaches to AI safety<\/h2>\n<p class=\"wp-block-paragraph\">The introduction of Private Safety Processing highlights differing approaches to safety among AI providers.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said the system is designed to detect misuse patterns across interactions while preserving zero data retention.<\/p>\n<p class=\"wp-block-paragraph\">By contrast, some providers retain customer interaction data for a period of time to support safety monitoring, reflecting a different approach to identifying risks that span multiple requests.<\/p>\n<p class=\"wp-block-paragraph\">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the difference lies in how evidence is handled rather than whether signals are used.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is a disagreement about how much raw content you need besides a signal you are keeping regardless, rather than privacy against surveillance,\u201d Gogia said.<\/p>\n<p class=\"wp-block-paragraph\">He added that both approaches rely on derived indicators but differ in where investigation data resides. \u201cAnthropic wants enough content to investigate the case. OpenAI wants the customer to hold the case while the provider holds the alarm,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\">Signal-based detection and verification<\/h2>\n<p class=\"wp-block-paragraph\">The system\u2019s reliance on signals rather than direct data access shifts how enterprises verify and investigate incidents, analysts noted.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe architecture is entirely viable. Security has worked from derived indicators for a generation. The difficulty is verification, not feasibility,\u201d Gogia said.<\/p>\n<p class=\"wp-block-paragraph\">He added that detecting behavior across time requires retaining some form of representation. \u201cA system cannot detect behaviour across time unless it remembers something across time,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Private Safety Processing \u201cis privacy-preserving abuse detection. It is not an enterprise forensic record, and OpenAI does not claim it is,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\">Implications for regulated sectors<\/h2>\n<p class=\"wp-block-paragraph\">According to Apeksha Kaushik, senior principal analyst at Gartner, the approach could influence AI adoption in industries with strict data requirements.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPrivacy-preserving safety models, such as those employing Zero Data Retention (ZDR), represent an emerging approach that may lower barriers to AI adoption in regulated sectors like financial services and healthcare,\u201d she said.<\/p>\n<p class=\"wp-block-paragraph\">Such models \u201cmay help organizations address certain privacy requirements and may align with frameworks such as GDPR and HIPAA, contingent on specific implementation details and regulatory guidance,\u201d she noted.<\/p>\n<p class=\"wp-block-paragraph\">Kaushik added that organizations should evaluate such approaches against their compliance requirements. \u201cOrganizations are encouraged to consult with their compliance and legal teams to determine whether such approaches meet their specific regulatory and operational requirements,\u201d she said.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI said enterprises retain control over their data under this model and can investigate alerts using their own systems. Customers can also choose to share relevant data with the company to support investigations or appeals.<\/p>\n<p class=\"wp-block-paragraph\">Analysts say this shifts responsibility toward enterprises. \u201cZero Data Retention does not remove the forensic burden. It relocates it,\u201d Gogia said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments. \u201cOpenAI does not retain\u2026prompts or model responses after a request is processed,\u201d the company said in a blog post, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9215,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9214"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9214"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9214\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9215"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}