OpenAI tests zero-retention safety system for enterprise AI use

OpenAI is testing a safety system called Private Safety Processing that can detect patterns of AI misuse across multiple interactions without giving its employees access to customer prompts and responses. The system…

OpenAI is testing a safety system called Private Safety Processing that can detect patterns of AI misuse across multiple interactions without giving its employees access to customer prompts and responses. The system is currently being tested with early customers, with a broader rollout planned for September. It extends OpenAI's existing Zero Data Retention option, which already keeps prompts and responses out of retained data.

OpenAI tests zero-retention safety system for enterprise AI use

For Indian businesses, the feature remains a product and contracting choice rather than a compliance requirement under current law. India's Digital Personal Data Protection Act, 2023 places data-handling responsibility on the Data Fiduciary even when a processor is involved, but the relevant processing provisions will not take effect until May 2027. The Reserve Bank of India's draft data-governance guidance, which covers third-party arrangements, also remains non-binding.

OpenAI says images flagged as potential child sexual abuse material will still be retained for manual review, even in zero-retention deployments. Anthropic, by contrast, requires 30-day retention for its covered models including the Mythos-class, even for organisations that otherwise use zero data retention. MediaNama has asked OpenAI whether Indian customers will be able to use Private Safety Processing at rollout and whether India-specific terms apply.

Indian Opinion Analysis

The Private Safety Processing announcement arrives as Indian enterprises accelerate AI adoption under a data-protection framework that is still being built. The DPDP Act's processing provisions do not take effect until May 2027, creating a regulatory gap. Meanwhile, the RBI's draft data-governance guidance, which covers vendor arrangements, remains non-binding. This means Indian companies must currently rely on contractual clauses and internal risk assessments rather than a settled regulatory baseline. OpenAI's system only becomes commercially relevant if it survives the technical and policy scrutiny of India's banking and insurance regulators. The September rollout will be the first real test of whether enterprise customers in India accept a system that detects misuse without granting vendor employees access to their data.


Source: medianama.com

This story was synthesised by AI from the source linked above.

Ask their opinion on this story
They have read this article, our coverage, and the web.
AI simulations of historical figures. Responses are generated from the historical record, not authentic statements.

0 Votes: 0 Upvotes, 0 Downvotes (0 Points)

Share your opinion

Loading Next Post...
Search Trending
Ask their opinion
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...

All fields are required.