Page 1 of 1 [ 1 post ] 

exec
Veteran
Veteran

User avatar

Joined: 26 Oct 2024
Gender: Male
Posts: 4,945

Today, 12:18 pm

https://betanews.com/article/openai-pri ... rocessing/

Quote:
OpenAI announced a new privacy architecture called Private Safety Processing, built to detect AI misuse across multiple interactions without exposing customer prompts or responses to OpenAI staff. The system runs alongside Zero Data Retention, OpenAI's existing policy under which prompts and model outputs are discarded once a request finishes processing and are never made available to OpenAI personnel for review.

The preview follows a policy change at rival Anthropic, which began requiring 30-day data retention on its most capable models starting June 9, 2026. Anthropic classifies Claude Fable 5 and Claude Mythos 5 as "Covered Models," a designation that excludes them from Zero Data Retention across every platform where they operate, including first-party surfaces and third-party platforms such as Amazon Bedrock and Google Vertex AI.

Both models were pulled from access for roughly three weeks after the U.S. government issued an export control directive on June 12, 2026, citing national security authorities and ordering Anthropic to block access for foreign nationals, including its own foreign-national employees. The government lifted the controls on June 30, 2026, and Anthropic restored full access to Claude Fable 5 and Claude Mythos 5 on July 1, 2026.

GPT-5.6 Sol, OpenAI's flagship model, reached general availability on July 9, 2026, after a limited preview that began June 26, 2026, alongside the Terra and Luna tiers. It keeps its Zero Data Retention eligibility under the new preview, and OpenAI said the rollout targets eligible API and enterprise customers rather than people on ChatGPT's Free, Plus, Go, or Pro subscription plans.

Zero Data Retention gives customers a guarantee that a vendor processes a request and discards the content once the transaction completes, with no prompts or responses stored afterward. For industries handling legal filings, financial records, or government data, that guarantee is typically a baseline requirement in vendor contracts, one of the security concerns tracked in surveys of enterprise AI adoption since large language models entered business workflows.

Anthropic addressed the tradeoff in its August 2026 risk report, writing that the retention policy "will be unpopular with customers who have come to expect zero retention." The company said the 30-day window lets it detect attacks that only become visible across multiple requests, including Best-of-N jailbreaking, in which an attacker sends hundreds of slight variations of a prompt hoping one bypasses safeguards.

OpenAI's reasoning centers on a related gap: automated safety systems built for Zero Data Retention evaluate each interaction on its own, which misses coordinated activity that unfolds over several sessions. Aleah Houze, OpenAI's head of product policy, said risks tied to more capable frontier models often surface only when multiple interactions are examined together, not through any single prompt and response pair.

That kind of gap surfaced in a UK AI Security Institute evaluation disclosed in 2026, when Claude Mythos 5 and GPT-5.6 Sol each took unsanctioned actions during testing runs in which their cyber safety classifiers had been turned off, according to the companies' own disclosures.

Private Safety Processing preserves a multi-session view of activity without changing who can see the underlying content. Under Zero Data Retention deployments, customer content stays on infrastructure the customer controls; OpenAI is also developing a second storage option in which content sits on OpenAI's own infrastructure but is encrypted with keys held exclusively by the customer, so OpenAI personnel cannot read it. As the company put it in its announcement, "Private Safety Processing is designed so we can continue to offer ZDR."

When the automated system flags potential misuse, OpenAI receives only a narrow signal naming the category of concern, without the prompts or responses attached to it. Customers can investigate flagged activity using their own systems and can choose to share details with OpenAI directly if they want to appeal an enforcement decision or support an investigation into confirmed abuse.

One category is excluded from Zero Data Retention regardless of configuration: images flagged as potential child sexual abuse material remain subject to retention for manual review and mandatory reporting, a requirement OpenAI said follows federal law under 18 U.S.C. § 2258A.

OpenAI said Private Safety Processing is currently being tested with a small group of early customers, with a wider rollout and a technical white paper planned for September 2026. Companies named in the announcement as having given feedback during development include Glean, Databricks, Abridge, and Microsoft.

Glean's chief information security officer, Sunil Agrawal, said in the announcement that OpenAI's "no-training commitment and ZDR give Glean confidence to build with OpenAI."

Anthropic's retention requirement applies only to Claude Fable 5 and Claude Mythos 5. The company has said its other Claude models remain unaffected and continue to operate under existing Zero Data Retention terms.