Man in a gray sweater looking to the side against a plain white background.

OpenAI unveils privacy-first safety scanning to counter Anthropic’s data retention push

OpenAI’s privacy-first safety system aims to detect misuse without storing customer data, challenging Anthropic’s 30-day retention policy.

In short

OpenAI has previewed a new privacy-first safety system that can detect abusive AI use across multiple sessions without retaining customer data. The move positions OpenAI against Anthropic, whose 30-day retention policy has drawn enterprise privacy concerns.

  • OpenAI previewed Private Safety Processing for selected customers.
  • The system is designed to detect misuse across multiple chats while keeping customer data out of retention.
  • The announcement directly contrasts with Anthropic’s 30-day data retention policy for covered models.
  • Enterprise buyers are increasingly choosing AI vendors based on privacy and safety controls, not just model performance.

OpenAI has introduced a new privacy-focused safety system, Private Safety Processing, that it says can spot abuse across multiple chats without retaining customer data. The move, announced on August 19, 2026, is aimed at enterprise users and appears designed to blunt criticism of Anthropic’s newer 30-day data retention policy.

The new approach matters because AI vendors are under growing pressure to prevent misuse without exposing sensitive business information. OpenAI is trying to show that companies can get stronger abuse detection while still keeping customer conversations out of long-term storage.

That balance has become one of the central tensions in enterprise AI. Businesses want tools that can detect malware planning, fraud attempts, and other harmful behavior. At the same time, many customers do not want their proprietary documents, legal discussions, or internal workflows retained by a model provider, even briefly, unless absolutely necessary.

What OpenAI announced

OpenAI said it is previewing Private Safety Processing for a limited group of customers. The company describes the system as an automated safety layer that scans for misuse while preserving the privacy guarantees associated with zero data retention, or ZDR.

Unlike a simple one-off session check, the new system is built to examine patterns across several conversations. That broader view is important because suspicious behavior often does not appear all at once. A user seeking to cause harm may break a request into smaller pieces to avoid triggering standard safeguards.

According to OpenAI, the system can generate a narrowly defined alert if it detects a concerning pattern. That signal can then prompt OpenAI to decide whether any enforcement action is needed. The company says it may contact the customer for more context if necessary.

OpenAI says the system is meant to catch abusive behavior across sessions while still avoiding the retention of customer data.

How Private Safety Processing works

OpenAI says Private Safety Processing extends its existing zero data retention model. ZDR already allows the company to use automated agents to monitor individual sessions for abuse without storing customer content in a durable way.

The new system goes further by analyzing multiple interactions over time. Instead of treating each conversation as isolated, it looks for signs that different prompts, outputs, or requests may be part of a coordinated attempt to misuse the model.

Why multi-session monitoring matters

Multi-session monitoring matters because malicious users often try to evade detection by spacing out their requests. For example, someone attempting to assemble malware or a cyberattack workflow may not ask for the full answer in one conversation. The process can be fragmented, with each step looking innocent on its own.

OpenAI’s new approach is designed to catch exactly that sort of slow-burn abuse. The company says the system can analyze multiple conversations without any human reviewer reading through a customer’s chats in real time.

What happens when the system flags activity?

When the system identifies a possible issue, it may send OpenAI a limited signal rather than the underlying content itself. OpenAI says that signal is deliberately narrow, meaning it is intended to indicate the type of behavior detected without exposing full conversation records.

If the company decides further action is needed, it can reach out to the customer. In some cases, the customer may voluntarily provide additional data to help resolve the situation or explain the context.

Why OpenAI is making this move now

OpenAI’s announcement comes as rivalry with Anthropic has intensified, especially in the enterprise market. Both companies are pitching their models to businesses that care deeply about security, confidentiality, and compliance.

That competition is not only about model quality. It is also about trust. Enterprise buyers increasingly want to know how AI vendors handle customer data, how abuse detection works, and whether the company can monitor safety without becoming a data custodian for sensitive information.

OpenAI appears to see a chance to differentiate itself by framing privacy as a feature of safety rather than a trade-off against it.

How does this compare with Anthropic?

OpenAI’s new system clearly contrasts with Anthropic’s latest retention policy, which has upset some enterprise customers. Anthropic said in July that it may retain data from sessions involving certain “covered models” for up to 30 days so it can review and analyze possible misuse.

The company says that policy applies to its Mythos-class models and other future systems with similar capabilities. Anthropic argues the retention period is part of a broader safety strategy.

But many enterprise customers see that approach differently. Businesses handling legal files, health records, financial data, or trade secrets often prefer strict limits on data storage. For those users, a 30-day retention window can feel too broad, even if it is meant to support safety reviews.

What Anthropic says about review access

Anthropic has said customer data can be reviewed by humans, but only through restricted access controlled by a small number of approved reviewers. The company also says those review sessions are logged in a tamper-resistant system that reviewers cannot alter or hide.

That model is meant to reassure customers that access is limited and accountable. Still, for organizations that want near-total minimization of data exposure, even tightly governed review access may be a step too far.

Company New policy or system Data retention Primary safety goal Customer concern
OpenAI Private Safety Processing No customer data retention under ZDR approach Detect misuse across multiple sessions Whether automated scanning can be effective without storing chats
Anthropic Covered-model retention policy Up to 30 days for covered models Enable safety analysis and review Potential exposure of sensitive enterprise data
Existing ZDR practice Session-level abuse monitoring No durable retention Spot abuse within a single session May miss coordinated abuse spread across sessions

What is zero data retention?

Zero data retention is a privacy model in which a provider does not keep customer content beyond what is needed to process the request. In the AI context, it usually means the company can run automated abuse checks without saving the underlying prompts and responses for future use.

OpenAI says Private Safety Processing is built on top of that model. The company’s argument is that privacy and abuse detection do not have to be opposing goals if the monitoring is sufficiently automated and limited in scope.

For enterprise buyers, ZDR is appealing because it reduces the risk of long-term exposure. For providers, it also creates a challenge: the less data they keep, the harder it can be to identify coordinated abuse or emerging threat patterns.

Why enterprise customers care so much

Enterprise clients are not just concerned about hackers. They are also worried about where confidential information travels once it enters an AI system. A procurement team may not want vendor pricing details stored. A law firm may not want legal strategy retained. A hospital may not want patient-related text logged longer than necessary.

That is why data retention policies can become a competitive issue, not just a compliance issue. In the enterprise market, a company that promises stronger privacy may win deals even if its rival offers comparable model performance.

OpenAI’s timing suggests it believes there is room to gain ground by narrowing that trust gap. By emphasizing automated monitoring without storage, OpenAI is signaling that safety features need not come at the cost of data exposure.

How customers may respond

Customers are likely to judge the feature on a few practical questions:

  • Does the system meaningfully improve detection of abuse that spans multiple chats?
  • Will the company ever need to review customer content manually?
  • How clearly are alerts defined, and what triggers enforcement?
  • Can the customer opt in without sacrificing confidentiality commitments?

Those questions matter because privacy language alone may not be enough. Enterprise decision-makers usually want technical explanations, contractual assurances, and clear operational boundaries.

How the rivalry with Anthropic is shaping product strategy

OpenAI and Anthropic are now competing not just on benchmarks, but on how responsibly they handle business customers’ data. That shift is notable because it shows the AI market maturing. The next phase of competition is not simply about model power; it is about deployment trust.

Recent reports have suggested that Anthropic’s revenue growth in the second quarter outpaced OpenAI’s. Anthropic’s annualized revenue run rate has been reported at $65 billion, and investors have floated the possibility of a future public listing that could value the company at $2 trillion. OpenAI, meanwhile, is also believed to be working toward an eventual IPO.

In that environment, product decisions can double as market signaling. Each company is trying to persuade enterprises, investors, and regulators that it is the safer, more reliable platform for large-scale adoption.

OpenAI’s message is that privacy-focused safety can be automated, scalable, and compatible with strict data minimization.

What this means for AI safety policy

The broader significance of OpenAI’s move is that it pushes the industry toward a new model for safety governance. Instead of choosing between privacy and abuse detection, providers are now trying to build systems that do both at once.

That may become increasingly important as AI tools get more capable. As models improve, so does the risk that they can be used to draft phishing campaigns, develop malicious code, automate fraud, or assist other harmful activity. Providers need monitoring tools that can keep up with those risks without alarming customers.

Private Safety Processing suggests one possible path forward: use automated agents to inspect behavior patterns, retain as little content as possible, and escalate only when a narrowly defined signal indicates a real concern.

Potential limits of the approach

Even so, the approach is not without trade-offs. If a system is too restrictive, it may miss subtle abuse. If it is too aggressive, customers could worry that benign activity is being over-monitored or that false positives could affect service relationships.

There is also the question of transparency. Companies may want to know how much information is inferred from the signal, how often the system triggers, and whether the review process can be audited. Those details will likely shape adoption as much as the privacy promise itself.

Timeline of the privacy and safety dispute

The dispute between privacy and safety in enterprise AI has unfolded quickly over the past several months. The following timeline highlights the key milestones behind the latest OpenAI announcement.

Date Event Why it matters
July 2026 Anthropic announces a 30-day retention policy for covered models Raises concerns among privacy-conscious enterprise customers
August 2026 OpenAI previews Private Safety Processing Offers a privacy-first alternative to retained-data safety review
August 2026 OpenAI frames the system as an extension of ZDR Signals a broader push to combine privacy with multi-session abuse detection

What happens next?

OpenAI has only said the feature is being previewed to select customers, so widespread availability may still be ahead. The next stage will likely involve testing, feedback from enterprise users, and scrutiny from customers who want to understand exactly how the system behaves in practice.

What matters most now is whether OpenAI can prove that privacy-preserving monitoring is not only possible, but reliable enough for business adoption. If it succeeds, the company may gain a meaningful edge in a market where trust is becoming just as valuable as raw model capability.

If it falls short, the debate over how much AI companies should see, store, and review will continue to define the enterprise market — and the rivalry between OpenAI and Anthropic will only intensify.

Frequently asked questions

What is OpenAI’s Private Safety Processing?

OpenAI’s Private Safety Processing is a new automated safety system that looks for signs of misuse across multiple conversations while avoiding customer data retention. The company says it is designed to improve abuse detection without requiring human review of routine chats.

How is OpenAI’s approach different from Anthropic’s?

OpenAI says its system keeps data out of retention under a zero data retention model, while Anthropic’s covered-model policy can keep sessions for up to 30 days. The difference matters because many enterprise customers prefer not to have sensitive conversations stored at all.

Why do AI companies monitor customer chats for misuse?

AI companies monitor customer chats to detect harmful activity such as malware planning, fraud, or attempts to evade safeguards. The challenge is doing that while still protecting customer privacy and minimizing how much content the provider stores or reviews.

Will OpenAI’s new system read customer conversations?

OpenAI says the system is automated and does not rely on human review of chats in normal operation. If it detects a concerning pattern, it may generate a narrow signal that prompts further action, and any follow-up data sharing would be up to the customer.

Share this 🚀