Article 77TW6 OpenAI chases Anthropic's biz customers with zero data retention pledge

OpenAI chases Anthropic's biz customers with zero data retention pledge

by
from www.theregister.com - Articles on (#77TW6)
Story ImageOpenAI appears to have found a way to balance AI model safety with commitments to retain no customer data, a feat rival Anthropic hasn't yet managed. For orgs concerned about who has access to their data, this could be a game-changer. The free-spending AI biz on Wednesday announced Private Safety Processing, a mechanism for automatically scanning customer model interactions for safety risks without violating Zero Data Retention (ZDR) commitments. Anthropic meanwhile has noted that its implementation of ZDR includes a non-zero amount of data retention for covered models - currently Mythos 5 and Fable 5. For commercial customers using ZDR as of June 9, 2026, "we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered." OpenAI, Anthropic, and various other AI model makers agree some oversight of rapidly advancing model capabilities is a good idea. The devil is in the details, which in the case of Private Safety Processing have not yet been published. Generally speaking, both companies have similar policies for commercial customers using lower tier models. "For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation," Anthropic says, with exceptions for certain services, ZDR agreements, and legal/policy enforcement. For OpenAI ChatGPT Business customers, "Your workspace admins can control how long your data is retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm." That 30-day policy also applies to OpenAI's API in most cases. When Anthropic detects usage violations, it may retain model inputs and outputs for up to two years and trust and safety classification scores for up to seven years. The major distinction now is ZDR and how the two frontier AI companies define that concept. Anthropic has a ZDR exception for those using its top models. For OpenAI ZDR deployments, customers may control the infrastructure or they may choose to store data on OpenAI infrastructure, where OpenAI says it will soon provide customer-controlled encryption keys. "In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel," the company explains in its post. Anthropic allows more room for human review when content is flagged by its automated systems. "By default, no Anthropic personnel can read your retained conversations," the company says in its documentation. "Human review can occur only through a controlled access path-for example, when content is flagged by our automated trust and safety systems for potential harm." OpenAI's human intervention scenario is narrow - in the event child exploitation material is detected. With the addition of Private Safety Processing - to be explained in more detail next month, OpenAI insists - whatever data gets stored is unavailable to company personnel. "Private Safety Processing builds on the automated protections already used in ZDR and other deployments," the AI biz explains. "Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content." What's noteworthy about this beyond the privacy commitment is the company's expanded interest in "related interactions." That suggests OpenAI's safety assessment is looking not just at prompt input and output but tool use and network data signals. Keeping AI interactions and data flows private has become a major concern. Apple has its Private Cloud Compute. Google has its Private AI Compute. Nvidia offers Confidential Computing. Even Meta, not exactly known for its commitment to privacy, talks up its Private Processing for AI. And much of the interest in running local AI models reflects a desire to keep sensitive data safe from potentially prying service providers and adversaries. OpenAI may have read the room well with its celebration of private model policing, but as Matthew Green, associate professor of computer science at Johns Hopkins University, observed recently, "private inference isn't private enough." Green notes that AI agents - models connected to tools - often rely on sensitive data when they act on our behalf, and while private inference may protect some part of the data flowing to and from AI agents, there are many other gaps in the system. "At the risk of saying more obvious things, the difference between a helpful private agent, a corporate advertising bot, and a government spy comes down mainly to a matter of prompting, and maybe a bit of model fine-tuning," he wrote. "Once you combine private data access and the ability to send messages, there is essentially no technical protection that private inference alone can offer." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments