OpenAI is rolling out a new safety framework called Private Safety Processing for its enterprise and paying customers. The feature is designed to detect multi-step cyber threats while maintaining the company's zero data detention policy.

Artificial intelligence developer OpenAI has announced plans to enhance safety processes for paying users who utilize its advanced AI models. The update comes as enterprise customers increasingly entrust AI systems with more complex tasks and sensitive information.

Currently, OpenAI offers a zero data detention policy to certain customers using its application programming interface (API). Under this policy, the company does not retain prompts or model responses after a request is processed, and it lacks direct access to customer content.

On Wednesday, the company announced it has begun testing Private Safety Processing with early customers, including Microsoft Corp. and Databricks Inc. OpenAI plans to formally roll out the feature in September, accompanied by a technical white paper detailing its operations.

Aleah Houze, OpenAI's head of product policy, explained the rationale behind the new framework during a press briefing. According to Houze, risks associated with advanced frontier models often become apparent only when observing multiple interactions over time, rather than examining single prompt and response pairs in isolation.

The development coincides with the broader industry trend of AI companies offering agentic tools. These tools are capable of executing complicated, multi-step tasks without requiring explicit, step-by-step instructions from users.

To illustrate the need for broader contextual oversight, Houze provided an example involving potential cybersecurity threats. An individual might inquire about software weaknesses in one conversation and later ask about remote access or security detection tools in a separate session. While each isolated prompt may resemble legitimate cybersecurity research, analyzing them together within a broader context can reveal a potential cyber attack.

OpenAI has emphasized that under the new Private Safety Processing mechanism, customer content will remain restricted from the company in order to preserve user privacy.

"As businesses increasingly adopt advanced AI tools for complex, multi-step tasks, security frameworks must evolve beyond isolated data checks. OpenAI's move to introduce Private Safety Processing addresses the growing need for contextual risk detection while maintaining enterprise data privacy. For startups and technology companies building or deploying enterprise AI, balancing robust multi-interaction security with strict data confidentiality will be critical to earning customer trust in an increasingly agentic AI landscape." — Dr. Shishir Gupta, Founder & CEO, StartupLanes