Enterprise AI Privacy

OpenAI’s Private Safety Processing Takes Aim at Anthropic’s Data Retention

OpenAI previews Private Safety Processing, a zero-retention abuse-detection system designed to contrast with Anthropic's 30-day data retention policy for covered models.

LUMIEN5 min read
OpenAI’s Private Safety Processing Takes Aim at Anthropic’s Data Retention

OpenAI announced on August 19, 2026 that it is previewing a new enterprise feature called Private Safety Processing, which scans for AI misuse across multiple user sessions without storing any customer data or involving human reviewers. The announcement is a direct shot at Anthropic, whose July 2026 policy allows the company to retain all user session data for 30 days on "covered models" including its Mythos-class models and a model called Fable. Several enterprises that handle sensitive data have reportedly pushed back against that policy.

What happened

Detail Value
Feature name Private Safety Processing
Announced by OpenAI, August 19, 2026
Status Previewing with select customers
Anthropic retention period (covered models) 30 days
Anthropic covered models All Mythos-class models and Fable; future models with similar capabilities
Anthropic annualized revenue run rate $65 billion (reported)

OpenAI’s existing abuse-monitoring approach is called Zero Data Retention (ZDR). Under ZDR, agents inside the OpenAI API watch for bad activity session by session, then discard the data. No human reviews the conversations. Most AI companies, including Anthropic, follow ZDR as a baseline.

Private Safety Processing extends that baseline. Instead of looking at one session at a time, it analyses inputs and outputs across multiple conversations. This matters because a sophisticated bad actor, for example someone trying to piece together malware instructions for a cyberattack, might spread requests across many separate sessions to avoid triggering a single-session filter.

If the cross-session analysis is triggered, the system sends a “narrowly defined signal” to OpenAI flagging a specific type of activity. OpenAI then decides whether enforcement is needed. If so, it contacts the customer for context, and the customer can choose at their own discretion whether to share any data with OpenAI. No data is shared automatically.

How this compares to Anthropic’s approach

Dimension OpenAI Private Safety Processing Anthropic covered-model policy
Data retained None All sessions for 30 days
Human review No automatic human review Possible via controlled access path, small set of approved reviewers
Audit trail Not described Tamper-proof log reviewers cannot suppress
Monitoring scope Across multiple sessions Retained sessions reviewed if flagged
Customer data sharing Customer’s discretion after contact Retention is automatic for covered models

Anthropic’s policy does include controls. Human access to retained data runs through a controlled path limited to a small group of approved reviewers, and every review session is logged in a tamper-proof record. Still, the fact that data is stored at all has troubled enterprises in regulated industries, according to TechCrunch.

Why it matters

Enterprise AI adoption often stalls at the legal and compliance stage. A company handling health records, financial data, or legal documents needs assurance that its conversations with an AI model will not sit on a vendor’s servers. Anthropic’s 30-day retention window, even with access controls, is a hard stop for some procurement teams.

OpenAI is clearly reading that pain point. Private Safety Processing lets it tell a prospect: you get cross-session abuse detection and your data never leaves your control. That is a meaningful differentiator if it holds up in practice, particularly for sectors like finance, legal, and healthcare that are already cautious about AI integration.

The competitive backdrop also matters. A recent report cited by TechCrunch showed OpenAI’s Q2 revenue grew more slowly than Anthropic’s. Anthropic’s annualized run rate is reportedly $65 billion. Both companies are working toward IPOs, and Anthropic investors have floated a $2 trillion valuation. In that context, winning enterprise accounts on privacy grounds is a real revenue lever, not just a PR move. You can follow related developments in our OpenAI vs. Anthropic revenue coverage.

Our take

The feature sounds compelling on paper, but “previewing with select customers” means there is no independent verification yet. The critical question is what “narrowly defined signal” actually means in practice. If that signal contains enough session context to be useful for enforcement, it may carry more data than OpenAI is letting on. We would want to see a detailed technical spec, not just a spokesperson’s description, before recommending this as a compliance argument in a sales process.

That said, the direction is right. Cross-session monitoring without retention is exactly the kind of privacy-preserving architecture that enterprise buyers should be pushing all AI vendors toward. The fact that Anthropic’s policy triggered enough customer complaints to force a competitive response from OpenAI tells you that privacy is now a real procurement criterion, not a checkbox.

If you are evaluating AI vendors for an enterprise deployment and data residency is a concern, add “What is your data retention policy for safety monitoring?” to your security questionnaire now, before you sign anything. Our team can help you work through those questions as part of a broader AI integration assessment.

What to do about it

  1. Audit which AI tools your team currently uses and confirm whether any fall under a data-retention policy like Anthropic’s covered-model rule.
  2. Add specific data-retention and human-review questions to your AI vendor security questionnaire.
  3. If you are an OpenAI enterprise customer, ask your account manager about Private Safety Processing access and request the technical documentation.
  4. If you handle regulated data, loop in your legal or compliance team before expanding AI tool usage, regardless of which vendor you use.

Privacy architecture is becoming a real differentiator in enterprise AI. Ask vendors to show their work, not just describe it.

Source: TechCrunch · AI

Frequently asked questions

What is OpenAI Private Safety Processing?

Private Safety Processing is a new OpenAI feature, currently in preview with select enterprise customers, that monitors for AI misuse across multiple user sessions without retaining any customer data or involving human reviewers. If suspicious activity is detected, a narrow signal is sent to OpenAI, which then contacts the customer before any data is shared.

What is Anthropic's data retention policy for covered models?

Anthropic's policy, announced in July 2026, retains all user session data including full conversation history for 30 days on covered models. Covered models include all Mythos-class models, Fable, and future models with similar capabilities. Human review is possible through a controlled access path with a small set of approved reviewers.

What is Zero Data Retention in AI APIs?

Zero Data Retention (ZDR) is a standard policy where an AI provider's API monitors sessions for abuse using automated agents but does not store the customer's conversation data after the session ends. Most major AI companies, including OpenAI and Anthropic, follow ZDR as a baseline, though Anthropic carves out an exception for its covered models.

How does Anthropic's revenue compare to OpenAI's in 2026?

According to TechCrunch, Anthropic's annualized revenue run rate is reportedly $65 billion, and its Q3 growth rate outpaced OpenAI's Q2 growth rate. Both companies are working toward IPOs, with Anthropic investors reportedly discussing a $2 trillion valuation.

More from AI