--- 格式版本: 2 标题: "Offering Zero Data Retention for frontier models" 原文链接: "https://openai.com/index/offering-zero-data-retention-for-frontier-models" 发布日期: "2026-09-06" 发布时间校准状态: "found" 发布时间需复核: "否" 发布时间来源: "llm:scrape:provider_published_at" 发布时间证据: "provider publishedAt: 2026-09-06" 发布时间校准原因: "候选日期来自发布者元数据,与当前YAML发布日期一致,可视为文章发布时间。" 发布时间校准置信度: "1" 发布时间候选数量: 1 发布时间严格候选数量: 0 发布时间原页读取状态: "source template page reused from URL open" 发布时间未找到原因: "" 发布时间校准时间: "2026-09-07T22:54:45+08:00" 发布时间仲裁状态: "confirmed" 发布时间仲裁尝试次数: 1 发布时间仲裁耗时毫秒: 2814 发现时间: "2026-09-07T22:06:43+08:00" 入库时间: "2026-09-07T14:54:56.780Z" 来源平台: "固定入口" 搜索渠道: "fixed_url" 搜索词: "https://openai.com/news/security/" 匹配关键词: - "AI" 相关厂家: - "OpenAI" 相关专家: [] 内容类型: "网页" 抓取工具: "Free Fetch + Defuddle" 清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取" 原始附件: [] AI优质: "否" AI打分: 44 AI分档: "非优质" AI质检状态: "不通过" AI打分理由: "正文主线为OpenAI预览Private Safety Processing隐私安全处理功能,属于模型API数据保留与安全监控机制,并非超节点、AI Rack、机柜级系统或关键部件直接讨论。来源为OpenAI官方一手发布,权威性高;发布时间2026-08-19,功能预览有一定新颖性,但本质是安全功能而非机架级基础设施产品。技术细节停留在加密、密钥控制、自动化安全信号等概念层面,无具体架构、规格或机架级工程数据。商业信号仅有早期客户测试和Glean高管引语,无具名量产、部署、订单或明确规模。知识库未命中同主题新增记录。最终命中应用与模型效率相关否决项,且不满足任何高价值准入通道。" AI质检模型: "zj-deepseek-v4-flash" AI质检时间: "2026-09-07T22:55:02+08:00" AI主题相关性: 2 AI来源权威性: 15 AI新颖性: 10 AI技术细节: 5 AI商业部署信号: 2 AI完整性: 10 AI评分提示词版本: "v17-精简生产版" AI评分提示词SHA256: "48fb9777f386026761b4873eaff30807694fb11e9b352d7c69bf2dfde750cc7d" AI评分知识库版本: "knowledge_base_v1-20260819+runtime.100" AI评分知识库SHA256: "7fe4568b9de9fc322c105ece08d18efab5b9b86f27dea6eb043b9a4d273bde60" AI评分知识库检索词: "[\"OpenAI\",\"https://openai.com/news/security/\",\"RAS\",\"Intel\",\"ZDR\",\"API\",\"citation-bottom-1\",\"ZDR-compatible\"]" AI评分知识库命中: "[{\"id\":\"runtime-51cfe3db04ed0bd3efb5e0e3\",\"title\":\"The full stack behind abundant intelligence\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-25\",\"matchedTerms\":[\"OpenAI\",\"RAS\",\"Intel\",\"API\"],\"rank\":-10.128090231500291},{\"id\":\"historical-may-024\",\"title\":\"OpenAI、Microsoft等围绕MRC协议构建更大规模AI以太网训练网络\",\"sourceType\":\"curated_item\",\"time\":\"2026-05\",\"matchedTerms\":[\"OpenAI\",\"Intel\"],\"rank\":-9.434960145126517},{\"id\":\"runtime-b9406ae170bd91336ab3bb25\",\"title\":\"Jalapeño’s first results show industry-leading speed and efficiency in AI inference\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-25\",\"matchedTerms\":[\"OpenAI\",\"RAS\",\"Intel\",\"API\"],\"rank\":-9.257113550414697},{\"id\":\"runtime-bf4039a0342d37545e9459a2\",\"title\":\"Most Neoclouds Suck At Security\",\"sourceType\":\"ai_excellent_article\",\"time\":\"2026-08-30\",\"matchedTerms\":[\"OpenAI\",\"RAS\",\"Intel\",\"API\"],\"rank\":-7.672247531474112},{\"id\":\"july-correct-0065\",\"title\":\"AMD Pensando™ Vulcano 800 AI NIC: Built to Scale-Out and Across\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"OpenAI\",\"RAS\",\"API\"],\"rank\":-6.378387176991242}]" 采集批次: "2026年9月7日22点05分18秒" 采集批次ID: "20260907-220517-361" 去重键: "https://openai.com/index/offering-zero-data-retention-for-frontier-models" --- Previewing Private Safety Processing, which strengthens safeguards across interactions while remaining compatible with ZDR. Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review 1, and enterprise customer data is not used to train our models unless customers explicitly opt-in. As models take on longer, more complex tasks, some serious risks may only become visible across multiple interactions. Existing ZDR-compatible safety systems evaluate each interaction individually. Today, we’re previewing Private Safety Processing, which is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content. For ZDR deployments, customer content remains on infrastructure the customer controls. We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel. ## Why safety systems need to evolve The most serious AI safety risks are not always visible in a single interaction. Often, potentially harmful intentions become clear only when multiple interactions are viewed together. Similar risks can arise when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Risks can also develop over the course of an agentic task—for example, if a system becomes misaligned with the user’s intent by continuing to act after being told to stop. As AI systems take on longer and more complex tasks, this broader context becomes increasingly important for distinguishing legitimate activity from misuse and ensuring that AI agents remain within the bounds of their intended authority. Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve. Private Safety Processing is designed so we can continue to offer ZDR. ## How Private Safety Processing works Private Safety Processing builds on the automated protections already used in ZDR and other deployments. Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content. Private Safety Processing utilizes customer content regardless of where it is stored—whether in infrastructure customers control (ZDR deployments) or in storage provided by OpenAI. With OpenAI-provided storage, customer content is encrypted using keys controlled by the customer. OpenAI personnel do not have a copy of those keys, so they cannot access the underlying content. When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved, similar to our existing safety systems today. That signal can be used to determine whether enforcement is necessary. OpenAI personnel do not receive access to the customer content even when it is flagged. Customers can investigate alerts and enforcement decisions using information available in their own systems. If they want to appeal, clarify legitimate activity, or support an investigation into verified abuse, they can choose to share relevant information with OpenAI. Private Safety Processing is currently being tested with early customers. We are sharing this preview now because we’ve heard our customers loud and clear that they need predictability about how their content will be protected as AI systems become more capable. Our mission is to ensure that artificial general intelligence benefits all of humanity. Collaboration with customers and partners is essential to how we build effective safeguards. As [our principles](https://openai.com/index/our-principles/) make clear, no AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes. The organizations we work with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans, and proprietary research. Protecting that information is essential to meeting regulatory obligations, maintaining customer trust, and preserving their competitive advantage. Their feedback is helping us build stronger safeguards while keeping their information under their control. “Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.” —Sunil Agrawal, Chief Information Security Officer, Glean We will continue working with customers on the technical and operational details of our approach. We plan to start rolling out Private Safety Processing, and share a technical white paper, in September. We’ll keep customers informed every step of the way, sharing updates early, explaining what they mean for existing commitments, and providing the time and support customers need to plan ahead.