OpenAI Introduces Private Intelligence to Limit Staff Access to Customer AI Data
The initiative separates automated safety checks from employee access. But its zero-retention option still requires encrypted records in customer-controlled storage, and the forthcoming inference service lacks pricing and support details.
OpenAI’s Private Intelligence combines customer-controlled storage for selected safety-review records with a separate service intended to process requests privately. In the available safety offering, automated reviews can decrypt records only inside a hardware-attested runtime; OpenAI says employees cannot inspect their contents. The design gives customers control over storage and key authorization, but not a guarantee that no records persist: protected content has a 30-day retention period, and customers must keep the storage accessible for reviews.
01
Zero Data Retention with Private Safety Processing is available now; OpenAI previewed the system in August and began a phased API-customer rollout on September 22, 2026.
02
OpenAI says protected content cannot be used for model training or shared with other OpenAI groups or partners.
03
Potential child sexual abuse material remains subject to retention for manual review and reporting, including in zero-data-retention deployments.
Businesses can now have AI interactions reviewed for safety while keeping selected content encrypted in storage they control, OpenAI says. At DevDay on September 29, 2026, the company introduced Private Intelligence, pairing that safety system with a forthcoming private-processing service. The distinction is consequential: limiting OpenAI’s access does not mean eliminating every stored record.
The initiative brings together two components with different schedules. Zero Data Retention with Private Safety Processing is available now, according to OpenAI’s DevDay presentation. Private Inference remains in preview and is expected this fall. The safety system is not entirely new: OpenAI previewed it in August and began a phased API-customer rollout on September 22.
Safety checks need a longer view
OpenAI’s rationale starts with a limitation of its existing zero-data-retention checks: they evaluate interactions individually. Misuse can become apparent only across related exchanges. In its August explanation, the company cited repeated attempts to probe safeguards, coordination across accounts, and agents continuing to act after being told to stop. Private Safety Processing is designed to recognize those longer patterns.
For the customer-controlled version, content selected by a safety classifier or an approved sampling policy is encrypted and written to the customer’s storage. OpenAI keeps an index with operational metadata and a reference to the record, rather than its own readable copy. Supported storage includes AWS S3, Azure Blob and Google Cloud Storage.
An automated review can retrieve those records into a protected computing environment that OpenAI calls a hardware-attested safety runtime. The company says this is the only workload capable of decrypting them, and its personnel cannot inspect the underlying material. The system can also use customer-managed Enterprise Key Management authorization.
The output is constrained too. Only predefined safety signals and approved operational metadata may leave that environment in readable form, OpenAI says. More detailed results are encrypted before leaving. That separates the automated system’s access to content from the information available to employees.
Customers must maintain the storage, permissions and key authorization during that period so automated reviews can run. The arrangement gives them control over the storage environment, but also leaves them responsible for keeping it available. Security teams assessing retention rules must account for those customer-side records, not just what OpenAI itself keeps.
With Private Intelligence, OpenAI is starting to answer that demand with “you don’t have to let us see it.”Source: venturebeat.com.
OpenAI also says content processed through Private Safety Processing cannot be used for model training or provided to other OpenAI groups or partners. That restriction addresses reuse of the protected material, separately from the question of where it is stored and who can decrypt it.
There is an important exception to the broader zero-retention promise. OpenAI’s primary explanation says images flagged as potential child sexual abuse material continue to be retained for manual review and reporting, including in zero-data-retention deployments. The company describes that as an existing practice tied to its legal reporting obligations.
Private Inference is the unfinished component
Private Inference concerns the processing of AI requests themselves, rather than the subsequent safety review. OpenAI describes it as confidential computing with verifiable controls. The fall timetable is a plan, not current availability, and several details needed to evaluate the service remain unannounced:
Coverage: which models and API endpoints it will support, and whether ChatGPT Enterprise workloads will be included.
Verification: what customers will be able to independently check, and which trusted computing hardware OpenAI will use.
Cost: OpenAI has not yet specified pricing.
Privacy protection does not remove OpenAI’s enforcement role. A narrowly defined safety signal can inform a decision about whether enforcement is necessary. Customers can investigate alerts using their own systems and choose to share relevant information when appealing a decision or assisting an abuse investigation. That makes customer participation a separate step from the automated review.
Sources
openai.comOffering Zero Data Retention for frontier models
venturebeat.comOpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Reader comments
Newest comments first. Replies stay oldest first.