• Latest
  • Trending
  • All
Official OpenAI announcement artwork: a blue and green gradient grid on a dark field, carrying the headline Offering Zero Data Retention for frontier models.

OpenAI’s Private Safety Processing keeps ZDR alive

20 August 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Monday, September 21, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

OpenAI’s Private Safety Processing keeps ZDR alive

by stephane
20 August 2026
in Dev
0
Official OpenAI announcement artwork: a blue and green gradient grid on a dark field, carrying the headline Offering Zero Data Retention for frontier models.
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Your security team signed off on the API integration on one condition: nothing you send leaves your control. Then the good models started arriving with a retention clause attached, and that sign-off quietly expired. On August 19 OpenAI pushed back. It's previewing Private Safety Processing, a way to keep Zero Data Retention on frontier models while still watching for abuse across a whole agent run rather than one call at a time. Content stays on infrastructure you control, or on OpenAI storage encrypted with keys OpenAI doesn't hold. When something trips, OpenAI receives a narrow signal about the type of activity, not your prompts. Anthropic went the other way in June and requires 30 days of retention on its covered models. So the trade is a live procurement question now, and one side of it is still a promise with a September date on it.

The short answer

OpenAI says Zero Data Retention keeps working on its frontier models. The new piece is Private Safety Processing: automated systems correlate abuse patterns across related calls, then hand OpenAI a narrow signal instead of your prompts. Content stays on your infrastructure, or on OpenAI storage encrypted with keys you hold. Anthropic took the opposite route in June and does not offer ZDR on covered models. OpenAI’s version is a preview. Anthropic’s is already policy.

Aug 19OpenAI previews Private Safety Processing
30 dayswhat Anthropic requires on covered models
Septemberrollout and white paper, both promised
Answer card: OpenAI announced Private Safety Processing on 19 August 2026 so Zero Data Retention keeps working on frontier models, with content on infrastructure the customer controls or on OpenAI storage encrypted with customer-held keys, automated systems returning a narrow safety signal rather than prompts, currently in preview with a rollout and technical white paper promised for September 2026.
The one-card version. Note which parts are terms you already have and which parts arrive next month.

What OpenAI actually announced

Zero Data Retention is an old promise and OpenAI restated it plainly: for eligible API customers, prompts and model responses aren’t retained once a request has been processed, that content isn’t available to OpenAI staff for review, and enterprise data isn’t used for training without an explicit opt-in.

The problem OpenAI describes is real, and it isn’t unique to OpenAI. A single request rarely looks dangerous. The pattern does. Someone probing a safeguard the same way forty times, or coordinating across accounts, or an agent that keeps acting after it’s been told to stop. ZDR-compatible safety systems today score each interaction on its own, which is exactly the wrong shape for that.

Private Safety Processing is the attempt to widen the window without widening who can read your data. Automated systems look across related interactions. If something trips, OpenAI receives a narrowly defined signal describing the type of activity, and uses that to decide whether enforcement is warranted. Staff don’t get the content even then. You investigate the alert with your own logs, and if you want to appeal or support an investigation, you choose what to hand over.

OpenAI announcement artwork, a blue and green gradient grid on a dark field with the headline Offering Zero Data Retention for frontier models.
Image: OpenAI

Glean, Databricks, Abridge and Microsoft are named on the announcement as customers shaping it. Glean’s CISO, Sunil Agrawal, is the only one quoted. Preview, early customers, no numbers.

The other lab picked the other side

This landed as competitive positioning and it reads that way, so let’s be exact about what it’s positioned against.

Anthropic’s own privacy documentation says prompts and outputs from covered models are retained for 30 days to support safety work, effective 9 June 2026. Covered models are the Mythos-class models plus future ones Anthropic designates, and Claude Fable 5 shares that underlying model. ZDR isn’t available for them. An organisation already running a zero-retention workspace has to switch retention on to get access, and that holds across the Claude API, AWS Bedrock, Google Cloud Agent Platform, Azure Foundry and Claude Enterprise. After 30 days the data is deleted automatically, minus anything flagged by trust and safety or held for legal reasons. Eligible organisations can add customer-managed encryption keys and access transparency logs.

Side-by-side comparison of OpenAI keeping Zero Data Retention available with Private Safety Processing returning narrow safety signals and a September 2026 rollout still pending, against Anthropic retaining prompts and outputs for 30 days on covered models since 9 June 2026 with no Zero Data Retention on those models.
Same diagnosis, opposite prescription. One of these you can cite in a risk register today.

Honestly, both readings of the problem are defensible. Anthropic’s is that if you need cross-interaction context, you need the interactions, so say so and put a clock on it. OpenAI’s is that you can get the signal without the content, which is a harder engineering claim and a much easier sell.

What it changes for you this week

Not much, and that’s the honest answer. If your ZDR terms are already in place with OpenAI, nothing in this announcement removes them. That’s the actual news: a reaffirmation, at a moment when the direction of travel looked like the opposite.

Where it does change something is the shortlist. Teams handling health records, legal files or client data under contractual no-retention clauses have been quietly ruling out certain models for weeks. If you’re one of them, the shortlist just got longer on the OpenAI side and stays shorter on the other. Whether that’s the right way to pick a model is a separate argument, and it’s not one your compliance officer is going to lose.

One thing worth doing now: go and read what your current agreement actually says, rather than what you remember it saying. Model tiers move. We watched GPT-5.6 ship in three variants with different availability rules, and retention eligibility is exactly the kind of clause that gets attached per model rather than per account.

The part that isn’t published yet

Checklist separating what OpenAI confirmed about Private Safety Processing from what is still unpublished, including no technical white paper, no general availability date, no pricing, no eligibility criteria and no list of the safety signals returned.
The load-bearing claim is the one with no documentation behind it yet.

Everything rests on one assertion: automated systems can correlate behaviour across your calls, flag it, and no human at OpenAI ever sees what triggered it. That’s plausible. It’s also the exact thing a technical white paper exists to demonstrate, and the white paper comes in September along with the rollout.

Until then there’s no threat model, no general availability date, no pricing, no eligibility criteria, and no published list of the signals that leave your tenancy when something fires. I might be wrong about how much that matters to a CISO who mostly wants a direction of travel. But a preview announced against a competitor’s live policy is a different artefact from a shipped control, and it’s worth keeping the two apart in your notes.

September is the test. If the paper lands with a real description of how the correlation works and what the signals contain, this becomes a genuine option. If it slips, the announcement was positioning.

Sources

OpenAI, “Offering Zero Data Retention for frontier models” (official announcement, 19 August 2026, including the September rollout and white paper commitment and the CSAM footnote). Anthropic Privacy Center, “Data retention practices for Covered Models” (the 30-day retention policy, effective 9 June 2026, and the surfaces it applies to). TechCrunch on the announcement and its competitive framing. The Next Web on what the preview leaves unproven.

Frequently asked questions

What is Private Safety Processing?

It is a safety system OpenAI previewed on 19 August 2026 that looks for abuse patterns across related interactions rather than scoring each call on its own, without OpenAI personnel getting access to the underlying content. Customer content either stays on infrastructure the customer controls, which is the Zero Data Retention case, or sits on OpenAI storage encrypted with keys the customer holds. When a risk is identified, OpenAI receives what it calls a narrowly defined signal indicating the type of activity, and can act on that. It is in preview with early customers, with a rollout and a technical white paper promised for September.

Does Zero Data Retention still exist on OpenAI frontier models?

Yes. OpenAI restated the ZDR promise for eligible API customers: prompts and model responses are not retained after a request is processed, that content is not available to OpenAI personnel for review, and enterprise customer data is not used for training unless the customer opts in. One carve-out survives. Images flagged as potential child sexual abuse material are still retained for manual review and reporting, as they are today, because US law requires the report.

What does Anthropic require on covered models?

Anthropic retains prompts and outputs from covered models for 30 days to support safety work, a policy that took effect on 9 June 2026. Covered models are the Mythos-class models and future models with similar capabilities that Anthropic designates. ZDR is not available on those models, so an organisation with an existing zero-retention agreement has to enable retention to use them. That applies on the Claude API, AWS Bedrock, Google Cloud Agent Platform, Microsoft Azure Foundry and Claude Enterprise. Consumer plans are unaffected, and the data is deleted automatically after 30 days unless it was flagged or is legally held.

Can I put Private Safety Processing in a compliance document today?

We would not. It is a preview, not a general availability announcement, and OpenAI has published no white paper, no threat model, no eligibility criteria and no pricing. The claim that automated systems can correlate behaviour across calls while no human sees the content is the whole product, and none of the technical detail behind it is public until September. The existing ZDR terms in your contract are the thing you can point an auditor at right now.

Who is the customer-managed key option for?

Teams that want the cross-interaction safety coverage but cannot run the storage themselves. OpenAI says it is developing an option where content sits on OpenAI infrastructure encrypted with keys the customer controls, and that OpenAI personnel do not hold a copy of those keys. Practically that is the same shape as customer-managed encryption keys elsewhere in cloud, and the same questions apply: who can trigger a decrypt, under what process, and what gets logged when they do.

Tags: aianthropicapicompliancenewsopenaiprivacy
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.