OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats

The select-customer preview tries to catch misuse spread across separate API sessions while keeping the provider from retaining the underlying conversations. Its practical test is whether automated signals can supply enough context for safety decisions.

By 2 min read
OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats
OpenAI Previews Cross-Session Safety Checks Without Keeping Customer Chats

Listen to this story

The audio brief

About 1:42
0:001:42
Read transcript
OpenAI is previewing Private Safety Processing, a system designed to spot misuse that unfolds across multiple API conversations without retaining the customer’s underlying chats. It is available only to select customers, and OpenAI says routine monitoring is automated rather than sent to human reviewers. The key change is moving from a single-session check to a broader pattern. Under Zero Data Retention, OpenAI already monitors API activity for abuse without keeping the data from each session. This preview adds signals from inputs and outputs across separate conversations, so activity that looks harmless on its own can be assessed as part of a larger sequence. OpenAI’s example is someone distributing malware-related requests across sessions to evade isolated checks. A trigger is not an automatic penalty. OpenAI says it may first ask the customer for context. If deeper investigation is needed, the customer can decide whether to share relevant data. That puts the system’s safety case on automated signals, while preserving the stated no-retention boundary. The contrast is Anthropic. For defined covered models, its policy allows sessions and conversations to be retained for 30 days for safety analysis, with human review through a controlled process and tamper-proof logs. Outside those models, Anthropic largely follows Zero Data Retention, according to the policy description. The practical question is whether OpenAI’s automated signals provide enough context without the conversations themselves. Since the preview is limited to select customers, its effectiveness in real-world use is still unestablished.

Story brief

3 key points

OpenAI is testing Private Safety Processing with select customers as a way to identify misuse patterns spanning multiple conversations while maintaining a no-retention boundary. The system is automated in routine operation and produces a limited signal rather than imposing immediate enforcement; customers may be asked for context and can choose whether to share data for deeper investigation. The preview positions...

  1. 01

    The preview extends Zero Data Retention monitoring from individual sessions to patterns across multiple conversations.

  2. 02

    OpenAI’s example involves distributing malware-related requests across sessions to evade isolated checks.

  3. 03

    A trigger is not an automatic penalty; OpenAI may seek customer context before deciding on action.

OpenAI is previewing Private Safety Processing, a system for select customers that is meant to detect potential misuse across several conversations without retaining customer data. OpenAI says the monitoring is automated and does not send conversations to human reviewers as part of the routine process.

From one session to a longer pattern

The change is in the scope of the safety check. OpenAI’s existing Zero Data Retention approach monitors API activity for abuse on a session-by-session basis without retaining customer data. Private Safety Processing extends that approach by assessing inputs and outputs from multiple conversations over time.

That wider view addresses a specific evasion problem: activity that appears ordinary in isolation may form a concerning pattern when connected across sessions. OpenAI gave the example of a person spreading requests related to malware development across separate conversations to avoid detection.

A trigger starts a review process, not an automatic penalty

When the system triggers, OpenAI says it may receive a narrowly defined signal about a particular type of activity. The signal does not automatically result in enforcement: OpenAI may contact the customer for context before deciding whether action is necessary. If more investigation is needed, the customer may choose whether to share relevant data with OpenAI.

Anthropic’s policy applies to a defined model category

The comparison is narrower than a blanket divide over enterprise privacy. Anthropic largely follows Zero Data Retention outside covered models, according to the policy description. For covered models, however, its policy permits the company to keep sessions and their conversations for 30 days so it can analyze potential safety problems.

Anthropic says human review can occur through a controlled access path involving a small group of approved reviewers. It also says each review session is recorded in a tamper-proof log that reviewers cannot suppress or alter. That approach keeps material available for inspection under stated access controls; OpenAI’s preview instead puts its safety case on automated detection before any customer decides to provide more data.

The product claim is a new privacy-safety tradeoff

Private Safety Processing is still a preview limited to select customers. But its distinct promise is clear: OpenAI says it can look for misuse that unfolds across a longer sequence of interactions while preserving a no-retention boundary. The result is a different answer to the central enterprise question—how a provider can seek signs of misuse without holding the underlying conversations for later analysis.

Sources

  1. techcrunch.comOpenAI seeks to one-up Anthropic with new customer privacy protections | TechCrunch

Loading discussion...