Refacto AI

Industry story

OpenAI launches Private Safety Processing to counter Anthropic data-retention policy

guardrails privacy security

OpenAI is previewing a new enterprise privacy feature called Private Safety Processing, which extends its existing Zero Data Retention (ZDR) approach — where customer conversation data is never stored — to cover multi-session safety monitoring. Unlike standard ZDR, which only scans a single session at a time using automated agents, this new system can analyze patterns across multiple conversations to detect spread-out malicious behavior (e.g., incremental malware engineering) without any human review of customer data. The move is a direct competitive response to Anthropic's July 2025 policy requiring 30-day data retention for its most capable 'covered models' (including Mythos-class and Fable models), a policy that has alarmed enterprise customers handling sensitive data. OpenAI's system only surfaces a 'narrowly defined signal' to OpenAI staff if triggered, and customers retain discretion over whether to share any data. The competitive context is significant: Anthropic's annualized revenue run rate is reportedly $65 billion and growing faster than OpenAI's Q2 growth, with both companies eyeing IPOs and fighting for enterprise market share.

Full analysis

OpenAI is previewing Private Safety Processing, a feature that extends Zero Data Retention (ZDR, where your conversation data is never stored) to watch for bad behavior spread across many sessions, not just one, without a human ever reading the content. The tell is the timing: it lands the same week Anthropic's July 2025 policy requiring 30-day retention on its top models drew enterprise heat. What's actually being decided for a technical buyer is whether "safety monitoring across sessions" is a reason to trust ZDR again, or a new thing watching that you now have to explain to your own compliance team.

Reversibility: Type 2 for most teams. You can route sensitive workloads between OpenAI and Anthropic per contract cycle. The forcing function is real though: Anthropic's retention policy is live now, and enterprise renewal conversations are happening this quarter.

The Skeptic. This is a preview with no published spec, announced the exact week Anthropic got bad press. Cross-session anomaly detection with no data retention is a hard problem. If OpenAI had cracked it cleanly, there would be a paper, not a blog post. The $65B Anthropic ARR figure in the framing is there to manufacture urgency, not to describe a shipped product. Right now this is a differentiated sales talking point that will get refined over two quarters of enterprise feedback. For the PM in the room: OpenAI announced it can do the hard thing, not that it has.

The Safety Lens. Here's the interesting inversion. Normally more monitoring means less privacy. OpenAI claims both at once by catching slow-moving attacks, incremental malware construction is their example, without anyone reading your content. That's the correct threat model. Single-session checks genuinely miss distributed adversaries. But "a narrowly defined signal surfaced to OpenAI staff" is still an undefined disclosure event, and the pressure on that definition only goes one way. Who audits the trigger? Nobody external. So enterprise customers are trusting OpenAI's internal incentives, which include keeping the contract, to hold the line on what counts as a trigger. For a non-specialist: they promise the tripwire is thin, but they alone decide where it sits.

The Researcher. The claim implies one of three things: differential privacy, secure multi-party computation, or an encrypted sketch that keeps the anomaly signal while destroying the content. OpenAI has disclosed none of them. That gap is the whole story. If this is genuinely cryptographic cross-session detection, it's a real advance worth studying. If it's delayed deletion with an audit window dressed in privacy language, it's marketing. The word "processing" in "Private Safety Processing" carries the ambiguity: processing is not the same as not-retaining, and until they say which primitive they used, nobody can grade the privacy claim.

The Enterprise Buyer. This is what a chief AI officer actually cares about, and it's why the feature exists. Anthropic's 30-day retention is a genuine procurement blocker for anyone in healthcare, finance, or legal. Data residency and "who can see this" questions kill deals. OpenAI just handed those buyers a line to put in the renewal deck. But I can't sign a preview. I need the DPA addendum, the trigger-definition audit rights, and a written answer on what "discretion over whether to share" means operationally. Give me that in contract language and this moves deals. Leave it as a blog post and it moves nothing.

Where they part ways

Two real disagreements. The Safety Lens thinks the correct threat model is the point; the Skeptic thinks the threat model is a story wrapped around an unfinished feature. Both can be true, and the resolution is a spec that doesn't exist yet.

The Researcher and the Enterprise Buyer want opposite things from the same silence. The Researcher wants the cryptographic primitive named so the claim can be checked. The Buyer wants contract language, and would happily sign without ever knowing whether it's differential privacy or a sketch, as long as the indemnification holds. The privacy claim can be technically thin and commercially sufficient at the same time.

What it hinges on

One belief: is cross-session detection without retention a cryptographic capability, or is it delayed deletion with better marketing? Everything else follows. If it's real, OpenAI has a durable enterprise moat and a paper worth reading. If it's audit-window deletion, Anthropic can match it in a quarter and this was a positioning move that bought share during a bad news cycle.

Before you move a sensitive workload on the strength of this, ask OpenAI for the DPA addendum and one plain sentence: which primitive preserves the signal while destroying the content? If they won't name it in writing, treat it as marketing and price it accordingly.

The call

The council leans skeptic on the substance and buyer on the effect. The mechanism is what I'd bet on: OpenAI shipped this to blunt a live enterprise objection during Anthropic's bad press, and marketing features that exist to win renewals get sold long before their technical spec is public. That is the normal pattern, not the exception.

Prediction: By 2027-02-23, OpenAI will make Private Safety Processing generally available to enterprise ZDR customers without publishing a technical specification that names the privacy-preserving primitive (differential privacy, secure multi-party computation, or an encrypted-sketch method) it uses to detect cross-session patterns.

Confidence: Medium. The commercial incentive to ship beats the incentive to disclose.

Why: OpenAI announced this as a preview the same week Anthropic's 30-day retention policy drew enterprise fire, which tells you the job of the feature is to answer a procurement objection, not to advance the privacy-monitoring literature. Labs that solve a genuinely hard cryptographic problem publish it, because the paper is itself a recruiting and credibility asset; the absence of one alongside the launch points to a mechanism they'd rather describe as a "narrowly defined signal" than specify. Enterprise buyers sign on DPA language and indemnification, not on primitives, so OpenAI can win the deals without ever naming the math, and naming it would only invite the peer scrutiny that could downgrade the claim. The opposite outcome, a full spec, would require OpenAI to trade a clean marketing position for the risk that researchers find the privacy guarantee is thinner than "Private" implies.

Revisit by 2027-02-23: We're right if Private Safety Processing reaches GA or broad enterprise rollout with the privacy mechanism still described only in marketing terms. We're wrong if OpenAI publishes a technical paper or spec naming the specific privacy-preserving primitive, or if the feature is quietly dropped before GA.

The tell to watch in the meantime is pricing. If cross-session monitoring never shows up as a line item, OpenAI is absorbing the inference cost to buy enterprise share against Anthropic, and the feature is a subsidy with a safety label slapped on it.

Comments