AIBRIEF

OpenAI Rolls Out Zero Data Retention With Private Safety Processing as Anthropic Faces Pushback Over 30-Day Policy

E
EffectStory 編輯部Editorial Team
Published · Updated
OpenAI unveiled Private Safety Processing on August 19, screening for abuse across model interactions without storing customer content, and is positioning zero data retention against Anthropic's 30-day retention policy for its Mythos-tier models — a gap that drew criticism from White House adviser David Sacks, Microsoft CEO Satya Nadella, and Palantir CEO Alex Karp, and reportedly led Microsoft to pause internal use of Claude Fable 5.

How does OpenAI's Private Safety Processing detect abuse without retaining data?

OpenAI's Private Safety Processing analyzes patterns across a model's multiple interactions to flag safety risks without OpenAI staff accessing the underlying contentCITE:E1.

OpenAI is showing select customers a new technology that detects patterns and safety risks across multiple model interactions without OpenAI employees accessing the underlying contentCITE:E1. Customer data stays on infrastructure controlled by the customer; when customers use OpenAI's storage service, content is encrypted with customer-controlled keys, meaning OpenAI staff cannot see model prompts, responses, or other sensitive informationCITE:E2. When the system identifies risks such as cyberattacks or biological weapons threats, it alerts OpenAI, providing a signal that helps determine whether OpenAI needs to take actionCITE:E3. OpenAI published this system, named Private Safety Processing, on its official blog on August 19; its automated system, when it detects potential abuse, returns only narrowly scoped safety signals — the type of activity and its severity — without exposing the underlying prompts or responses to OpenAI personnelCITE:E15.

Why did Anthropic's 30-day retention policy draw pushback from the White House, Microsoft, and other tech leaders?

Anthropic's decision to retain customer data for 30 days for Claude Mythos 5 and Fable 5 drew criticism from White House AI adviser David Sacks, Microsoft CEO Satya Nadella, and Palantir CEO Alex KarpCITE:E7.

OpenAI's zero-data-retention commitment stands in contrast to Anthropic's policy, which retains customer data for 30 days to help ensure the safety of newer models such as Claude Mythos 5 and Fable 5CITE:E6. That approach drew criticism from tech leaders including White House AI adviser David Sacks, Microsoft CEO Satya Nadella, and Palantir CEO Alex Karp, who argue enterprise customers need confirmation that AI companies are not retaining data, particularly in heavily regulated industries such as healthcare and financeCITE:E7. Anthropic requires all traffic through Mythos-tier models to be retained for 30 days, across both first-party and third-party channelsCITE:E10. Anthropic's technical documentation states that once a conversation or session is flagged, Anthropic may retain the inputs and outputs for up to two years, a provision that is not limited to regulated modelsCITE:E12. Microsoft suspended employee use of Claude Fable 5, with its legal and compliance departments reviewing Anthropic's retention rules over concerns that customer data and internal company information could inadvertently leak, according to a media report that described the suspension as temporaryCITE:E14.

How is Anthropic responding to privacy concerns with its own-cloud deployment and enterprise partnerships?

Anthropic plans to let enterprise customers store the 30-day retained data on their own cloud infrastructure rather than on Anthropic's serversCITE:E8.

Anthropic is planning to adjust its enterprise data retention approach, keeping the 30-day retention period unchanged while allowing companies to store that data within their own cloud environment instead of on Anthropic's servers; people familiar with the matter say the accompanying security system is expected to launch later in 2026CITE:E8. Anthropic has been working with more than 100 enterprise customers on this approach for months, including SalesforceCITE:E9. Anthropic and Salesforce expanded their strategic partnership on October 14, 2025, under which all Claude traffic remains inside Salesforce's virtual private cloud, with Anthropic becoming the first large language model provider fully brought inside Salesforce's trust boundary, targeting regulated industries such as financial services and healthcareCITE:E19. In a June 9, 2026 announcement, Anthropic stated that the retained data would help defend against "sophisticated, novel attacks, including new jailbreak techniques and attacks that operate across multiple requests," with the data deleted after 30 daysCITE:E20.

Where are the boundaries of the retention policy — enterprise, consumer plans, and legal exceptions?

OpenAI's new zero-retention system currently applies only to qualifying enterprise and API customers, not ChatGPT users, while Anthropic's update leaves consumer plans untouchedCITE:E4CITE:E13.

OpenAI's new system is currently designed for qualifying enterprise and API customers, not for users of ChatGPTCITE:E4. Anthropic's technical documentation states that organizations or workspaces that have not enabled data-retention settings receive a 400 error when calling Fable 5 or Mythos 5; zero data retention must be requested from Anthropic's sales team and enabled organization by organization, and is not the defaultCITE:E11. Claude's Free, Pro, and Max consumer plans across web, desktop, and mobile apps, including Claude.ai and Claude Code, are not affected by this updateCITE:E13. OpenAI also notes that, under legal requirements, suspected child sexual exploitation imagery must still be retained for human review even under zero-data-retention deploymentsCITE:E17.

What are the technical limits behind privacy protection, and what's the industry timeline ahead?

OpenAI's Private Safety Processing remains in early customer testing, with wider rollout and a technical white paper planned for September, while a security researcher flags a limit to the approachCITE:E16CITE:E18.

OpenAI plans a broader rollout next month along with publication of a technical white paperCITE:E5. The feature is currently in early customer testing, with the broader launch and white paper scheduled for SeptemberCITE:E16. Johns Hopkins University computer science professor Matthew Green cautions that when an AI agent can simultaneously access private data and send messages externally, private inference alone provides little technical protectionCITE:E18.

Key figures at a glance

MetricValueSource
Anthropic retention period for Mythos-tier models30 daysCITE:E6
Maximum retention for flagged sessions2 yearsCITE:E12
Error code without a retention opt-in400CITE:E11
Enterprise customers piloting own-cloud storage100+CITE:E9
Salesforce partnership expansion dateOct 14, 2025CITE:E19
Anthropic retention policy announcementJun 9, 2026CITE:E20
OpenAI Private Safety Processing announcementAug 19, 2026CITE:E15
OpenAI wider rollout / white paperSeptemberCITE:E16

What this means

OpenAI frames zero retention as a default now extended to qualifying enterprise and API customersCITE:E4, while Anthropic maintains a 30-day retention requirement across first-party and third-party channels for its Mythos-tier modelsCITE:E10, a gap that drew criticism from David Sacks, Satya Nadella, and Alex KarpCITE:E7 and reportedly led Microsoft to pause internal use of Claude Fable 5 pending legal reviewCITE:E14. Anthropic's countermeasure — letting enterprise customers hold the retained data on their own cloud infrastructureCITE:E8 — extends the same trust-boundary model it already built with Salesforce's virtual private cloudCITE:E19. Matthew Green's caution that private inference offers limited protection once an agent can both access and transmit dataCITE:E18 is a limit that applies regardless of which company's retention policy a customer is weighing.

📊 Evidence

FAQ

How does OpenAI's Private Safety Processing detect abuse without retaining data?

OpenAI's Private Safety Processing analyzes patterns across a model's multiple interactions to flag safety risks without OpenAI staff accessing the underlying c…

Why did Anthropic's 30-day retention policy draw pushback from the White House, Microsoft, and other tech leaders?

Anthropic's decision to retain customer data for 30 days for Claude Mythos 5 and Fable 5 drew criticism from White House AI adviser David Sacks, Microsoft CEO S…

How is Anthropic responding to privacy concerns with its own-cloud deployment and enterprise partnerships?

Anthropic plans to let enterprise customers store the 30-day retained data on their own cloud infrastructure rather than on Anthropic's serversCITE:E8.

Where are the boundaries of the retention policy — enterprise, consumer plans, and legal exceptions?

OpenAI's new zero-retention system currently applies only to qualifying enterprise and API customers, not ChatGPT users, while Anthropic's update leaves consume…

📎 Sources

  1. infosecu.technews.tw
  2. inside.com.tw

Related data

Author's TakeEffectStory 編輯部

The two companies are effectively solving different problems: OpenAI's Private Safety Processing screens for abuse signals without ever storing content, while Anthropic's 30-day window exists specifically to catch attacks that unfold across multiple requests over time — a pattern-detection job a stateless, zero-retention pass cannot easily do. Anthropic's own-cloud fix doesn't reverse that retention requirement; it relocates where the retained data sits, extending the same trust-boundary architecture it already runs with Salesforce's virtual private cloud to the broader set of 100-plus enterprise customers now piloting the approach. The harder question is the one Matthew Green raised: once an AI agent can both read private data and send messages externally, neither company's current safeguard is described as covering that case. The concrete thing to watch is whether OpenAI's promised September white paper addresses Private Safety Processing's behavior in agentic, tool-calling contexts — that's precisely the gap Green flagged, and it's unresolved in every fact reported so far.

E
EffectStory 編輯部Editorial Team

Related

BRIEF

Android's Motion Assist Adds Moving Dots to Fight Car Sickness

Google is rolling out Motion Assist, a Play Services feature for Android 17 that places moving dots along the screen edges to track a vehicle's motion using the phone's accelerometer and gyroscope, aiming to reduce or eliminate motion sickness — two years after Apple shipped a similar Motion Cues feature in iOS 18.

EffectStory 編輯部 ·
BRIEF

OpenAI Restores 5-Hour Usage Limit for ChatGPT Plus's Codex and Work, Effective August 25

OpenAI reinstated the 5-hour rolling usage limit for Codex and ChatGPT Work on Plus accounts starting August 25, 2026, restoring a dual-limit system that pairs the 5-hour cap with the existing weekly quota. OpenAI's Codex and ChatGPT lead Thibault Sottiaux confirmed the change on X, linking it to a usage surge after the GPT-5.6 Sol launch. Pro, Enterprise, and Edu plans remain unaffected for now.

EffectStory 編輯部 ·