OpenAI Private Intelligence: Zero Data Retention for Frontier Models
OpenAI's Private Intelligence pairs Zero Data Retention with Private Safety Processing today and previews confidential Private Inference for fall 2026.
By Dillip Chowdary • Sep 30, 2026 • Source: OpenAI
OpenAI answered the enterprise question 'who can see our AI data?' at DevDay 2026 with Private Intelligence, an umbrella initiative in two parts. Available now: Zero Data Retention with Private Safety Processing, which runs automated safety reviews without giving OpenAI personnel access to the underlying content — encrypted safety records stay in customer-controlled storage and are reviewed inside a hardware-attested runtime. Previewed for this fall: Private Inference, which applies confidential computing with strict, verifiable controls to model inference itself.
This piece explains what each component does, why safety processing was the technical blocker for genuine zero retention on frontier models, and what security teams should ask before treating the architecture as sufficient for regulated data. It is written for security, compliance, and platform leads evaluating frontier-model deployments.
Private Intelligence: what OpenAI announced
The DevDay recap showed the shape of the product: project-specific policy controls listing Zero Data Retention with Private Safety Processing and validated external storage. Rather than a single global toggle, retention and processing guarantees attach to defined scopes of work — the granularity enterprises need when one project handles public data and another handles patient records.
The two-phase structure matters. ZDR with PSP is shipping; Private Inference is a preview with a fall timeline. What exists today changes who can access data around the model; what is coming aims to change what is technically possible to access during inference at all.
Why safety processing was the hard part

Zero data retention has always collided with a structural requirement: providers run safety systems over traffic — abuse detection, policy enforcement — and those systems historically created retained records that personnel could access when reviewing flags. That review path is precisely the exposure enterprise customers object to, and simply deleting it would gut safety enforcement.
Private Safety Processing is OpenAI's resolution: the safety review still happens, but automated, inside a hardware-attested runtime, with the resulting records encrypted and held in storage the customer controls rather than OpenAI's. Attestation means the customer can verify what code ran in the enclave; customer-controlled storage means access to safety artifacts is governed by the customer's keys and policies, not the provider's internal procedures.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Private Inference: the fall preview
The second phase extends the same philosophy to the inference path itself. Confidential computing — enclaves whose contents are shielded even from the infrastructure operator, with verifiable controls — would mean prompts and completions are protected during processing, not merely deleted afterward. OpenAI is promising the preview this fall without yet publishing the technical specifics: which hardware, what threat model, what performance cost.
The distinction between the phases is worth internalizing: ZDR with PSP is a policy-and-architecture guarantee about retention and access; Private Inference aspires to a cryptographic-grade guarantee about processing. Regulated industries have been explicit that the second is what unlocks their most sensitive workloads.
Who this is for, and the competitive stakes
The immediate audience is every enterprise whose security review stalled on the safety-records question — common in legal, healthcare, and financial deployments — and anyone contractually bound to demonstrate that vendor personnel cannot access content. Paired with the same day's Bedrock Managed Agents, which keeps agent runtimes inside customer AWS infrastructure, OpenAI addressed the two standing enterprise objections — where agents run and who sees data — in one keynote.
Competitively, verifiable privacy is becoming the enterprise battleground: data leakage and IP exposure concerns have hardened into procurement requirements, and a frontier lab offering attested safety processing today sets the reference point rivals will be measured against.
What security teams should verify
Attestation claims deserve their own diligence: ask which components run inside the attested runtime, how attestation evidence is exposed to customers, what the enclave's threat model excludes, and how key management for the encrypted safety records actually works — customer-controlled storage is only as strong as the controls on its keys. Ask too what happens operationally when automated safety review flags content and no human at OpenAI can read it.
For Private Inference, hold evaluation until the preview publishes hardware, threat model, and latency numbers this fall. The pragmatic path now: identify workloads blocked specifically on retention-and-access grounds, pilot them under ZDR with PSP, and keep genuinely confidential workloads queued for the inference preview.
Developer Action Items
- ☐ Verify the claim on the official OpenAI page (or OpenAI), not from this recap alone.
- ☐ Name the surface that moved — API, policy, model, hardware, or commercial terms — before you Slack the thread.
- ☐ Assign one owner a day to read the primary material and decide: this-sprint, this-quarter, or noise.
- ☐ Do not change production on day-one coverage. Watch the vendor changelog and one independent write-up first.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
OpenAI Agents API Adds Computer Use, Tool Search, Context Compaction
Read →
OpenAI Managed Agents Arrive on AWS Bedrock, Run Fully Inside AWS
Read →
ChatGPT Space Gives Teams a Shared Workspace With Dots and AI
Read →
ChatGPT Pages and Slides Bring Real-Time Human-AI Co-Editing
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement