OpenAI published a post at 19:00 UTC on 19 August restating its commitment to Zero Data Retention on frontier models and previewing a scheme called Private Safety Processing. The headlines have read as a launch. Neither half of the post describes something that shipped.

What the common telling gets wrong

The first error is treating Zero Data Retention as news. ZDR has been available to qualifying API customers since 2023: on qualifying calls, prompts and completions are not stored and are not used for training. Nothing about that arrangement changed on 19 August. The second error is reporting Private Safety Processing as a live privacy feature. It is in preview, being tested with early customers including Microsoft and Databricks, with general rollout and a technical white paper both stated for September 2026.

The problem the mechanism is meant to solve

Safety systems that inspect one prompt-and-response pair at a time miss risks that only appear as a pattern. Aleah Houze, OpenAI's head of product policy, put it this way: risks emerge "not just by looking at one single prompt and response pair, but when you look over time at multiple interactions." Private Safety Processing is meant to let the safety systems observe across related interactions while emitting only narrow signals, so that no OpenAI staff member sees the underlying customer content.

The word doing the most work is "eligible"

The announcement refers throughout to eligible API customers and does not say who is eligible. Whether zero retention reaches all paid tiers, only enterprise agreements, or requires a specific contractual arrangement is not stated. For a procurement team, that is the entire question — a data-residency guarantee that may or may not apply to your contract is not yet a guarantee.

Why the tension is real

Frontier-model safety monitoring and enterprise data-residency promises pull against each other: monitoring wants to see more, residency wants the vendor to see less. Most vendors resolve it by picking a side. OpenAI is staking out the position that both are achievable at once — on paper, with the proof deferred to a white paper that does not exist yet.