OpenAI has told enterprise customers that its promise not to keep their data will survive the next generation of models. The company set out the position on Wednesday in a post titled “Offering Zero Data Retention for frontier models”. In it, it previewed Private Safety Processing. The system looks for misuse across several related interactions at once, and OpenAI says its own staff never see the prompts or responses underneath.

Zero data retention, or ZDR, is an option for eligible API customers. OpenAI does not keep their prompts or model responses once it has processed a request. Its personnel cannot pull that content up for review. Enterprise data does not train the models either, unless a customer opts in. Those four promises are what the new system is meant to protect.

What Private Safety Processing is for

The company’s case rests on a limit it says it has hit. Today’s ZDR-compatible safety systems judge each interaction on its own. “The most serious AI safety risks are not always visible in a single interaction,” OpenAI wrote in the announcement. Harmful intent, it argues, often shows itself only when several exchanges are read together.

The post lists the patterns OpenAI wants to catch. Bad actors probe safeguards repeatedly. They coordinate across accounts. They dress threats up as routine research. The post also names a failure specific to agents. A system drifts from the user’s intent, then carries on acting after someone tells it to stop. British and US testers watched an agent fake identities in tests earlier this month.