
OpenAI is testing a safety system called Private Safety Processing that can detect patterns of AI misuse across multiple interactions without giving its employees access to customer prompts and responses. The system…
OpenAI is testing a safety system called Private Safety Processing that can detect patterns of AI misuse across multiple interactions without giving its employees access to customer prompts and responses. The system is currently being tested with early customers, with a broader rollout planned for September. It extends OpenAI's existing Zero Data Retention option, which already keeps prompts and responses out of retained data.

For Indian businesses, the feature remains a product and contracting choice rather than a compliance requirement under current law. India's Digital Personal Data Protection Act, 2023 places data-handling responsibility on the Data Fiduciary even when a processor is involved, but the relevant processing provisions will not take effect until May 2027. The Reserve Bank of India's draft data-governance guidance, which covers third-party arrangements, also remains non-binding.
OpenAI says images flagged as potential child sexual abuse material will still be retained for manual review, even in zero-retention deployments. Anthropic, by contrast, requires 30-day retention for its covered models including the Mythos-class, even for organisations that otherwise use zero data retention. MediaNama has asked OpenAI whether Indian customers will be able to use Private Safety Processing at rollout and whether India-specific terms apply.
The Private Safety Processing announcement arrives as Indian enterprises accelerate AI adoption under a data-protection framework that is still being built. The DPDP Act's processing provisions do not take effect until May 2027, creating a regulatory gap. Meanwhile, the RBI's draft data-governance guidance, which covers vendor arrangements, remains non-binding. This means Indian companies must currently rely on contractual clauses and internal risk assessments rather than a settled regulatory baseline. OpenAI's system only becomes commercially relevant if it survives the technical and policy scrutiny of India's banking and insurance regulators. The September rollout will be the first real test of whether enterprise customers in India accept a system that detects misuse without granting vendor employees access to their data.
Source: medianama.com
This story was synthesised by AI from the source linked above.