OguzhanTekin
OpenAI Says It Can Watch Without Remembering
Technology & SocietyAugust 20, 2026

OpenAI Says It Can Watch Without Remembering

By Oguzhan TekinBack to Blog

OpenAI has made a simple promise: it can watch for serious misuse without keeping business conversations. It calls the system Private Safety Processing.

If it works, OpenAI may have found a better answer to a hard AI problem. But customers are being asked to trust the answer before they can inspect the work.

Zero Data Retention creates a real blind spot. Some API customers can use OpenAI models without OpenAI saving their prompts and replies after the request ends. Staff cannot read the content later. OpenAI also says it does not train on that data unless the customer agrees.

That protects privacy. It also makes slow attacks harder to see.

A harmful plan can be split across several harmless-looking requests. One asks about a software flaw. Another asks about remote access. A third asks how to hide activity. Each request may look safe alone. The risk appears only when they are joined.

OpenAI says its new system can join the pattern without showing OpenAI the conversation. The content can stay on systems run by the customer. Another planned option would store it on OpenAI systems with keys held by the customer.

Software then checks related activity. If it sees a possible threat, OpenAI receives a small signal such as the risk type and level — not the prompts.

This sounds clean. The trust line is not.

Encryption can protect saved data. But code still needs a way to read or process it somewhere. OpenAI has not yet explained where that happens, how customers can check the code, how sessions are linked, or how long the safety signals are kept.

A small signal is still data. Risk type, timing, account links, and repeat alerts can reveal behaviour even when the words stay hidden. OpenAI has not said who can search those signals or whether they could become a second record of customer activity.

Mistakes also matter. A missed signal may allow an attack. A wrong signal may block a valid customer. OpenAI may then need more details to settle the case. The customer could face an odd choice: reveal private data or accept a safety decision it cannot test.

Anthropic chose a less tidy answer. It keeps conversations for 30 days when business customers use certain "covered models." Anthropic says it needs that window to find abuse spread across many requests.

That choice is more invasive, but easier to understand. The data is kept. Access is controlled. Reviews are logged. Buyers can judge the cost.

OpenAI is selling the better result — safety without readable storage. It is also giving worried Anthropic customers a reason to switch. That does not make OpenAI's design false. It does make the timing useful.

OpenAI says a technical paper will arrive in September. It should answer basic questions. What can the signal reveal? How are wrong decisions challenged? Can customers check the code? Will an outside party test the system?

Until then, Private Safety Processing is a good idea and a strong sales message. It is not yet proof that OpenAI can watch without remembering.

References