OpenAI Offers Zero Data Retention for Frontier Models, Introduces Private Safety Processing

·

A major player in the development of artificial intelligence (AI) has announced a significant update to its data retention policies. OpenAI is now offering zero data retention for eligible API customers, ensuring that their prompts and model responses are not retained after processing. This move aims to provide an added layer of security and control for organizations using AI tools for business, particularly those handling sensitive information such as financial records or confidential research.

In a statement, the company emphasized its commitment to protecting customer content and adhering to regulatory obligations. OpenAI personnel will not have access to retained customer content, even in cases where it is flagged for potential misuse. This approach aligns with the company’s principles of prioritizing transparency and collaboration with customers and partners.

The introduction of zero data retention comes as AI systems take on increasingly complex tasks. As models become more capable, they may engage in longer interactions that can reveal patterns of potentially harmful behavior. Existing safety systems evaluate each interaction individually, but Private Safety Processing extends these protections across related interactions without exposing the underlying content to OpenAI personnel.

Private Safety Processing builds upon automated protections already used in zero data retention and other deployments. This new system allows for the identification of patterns across multiple interactions, enabling automated systems to flag potential misuse without accessing customer content. The approach is designed to streamline safety monitoring while maintaining control over sensitive information.

The organizations working with OpenAI handle some of the most sensitive information in their sectors. Protecting this data is essential for meeting regulatory obligations and preserving competitive advantage. By offering zero data retention, OpenAI aims to provide predictability about how customer content will be protected as AI systems become more capable.

A key aspect of Private Safety Processing is its ability to operate regardless of where the customer’s content is stored – whether on infrastructure controlled by the customer or in storage provided by OpenAI. In cases where OpenAI-provided storage is used, customer content remains encrypted with keys controlled by the customer, ensuring that OpenAI personnel do not have access to it.

When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved. This information can be used to determine whether enforcement is necessary without exposing the underlying content. Customers can investigate alerts and enforcement decisions using information available in their own systems, with the option to share relevant data with OpenAI if needed.

Private Safety Processing is currently being tested with early customers. The company plans to start rolling out this new system in September, along with a technical white paper providing more details on its implementation. Throughout this process, OpenAI will maintain open communication channels with customers, sharing updates and explanations of how these changes affect existing commitments.

The development of Private Safety Processing reflects the collaborative approach that OpenAI takes towards addressing emerging risks in AI. By working closely with customers across industries, regions, and company sizes, the company aims to build stronger safeguards while maintaining control over sensitive information. This commitment is essential for ensuring that artificial general intelligence benefits all of humanity.