OpenAI Takes Aim at Anthropic With a New Privacy-Focused Safety System
OpenAI has introduced Private Safety Processing, a new privacy-centric system designed to monitor AI misuse across multiple sessions without retaining customer data. This approach contrasts sharply with rival Anthropic's data-retention policy for "covered models," where user data is kept for 30 days. The move highlights the intensifying corporate competition and the delicate balance between AI safety and user privacy.
As AI companies push their models into more sensitive business operations, the fight over how customer data is monitored is becoming almost as important as the models themselves.
OpenAI is now testing a new system called Private Safety Processing, designed to detect misuse across multiple conversations without retaining the customer’s underlying data. The move gives OpenAI a new way to pitch privacy-conscious businesses while drawing a sharp contrast with a recent policy change from rival Anthropic.
The system is being previewed with a limited group of customers and is intended to address a problem that traditional safety monitoring can struggle with: detecting harmful activity that unfolds gradually across several sessions.
OpenAI wants to monitor misuse without keeping the data
OpenAI already offers Zero Data Retention (ZDR) for eligible API customers. Under ZDR, customer data is not retained by OpenAI, while automated systems can still scan individual sessions for signs of abuse.
Private Safety Processing takes that approach further.
Instead of examining conversations one session at a time, the system can look for patterns across multiple interactions. That matters because someone attempting to misuse an AI model could deliberately spread requests across separate conversations to avoid triggering conventional safeguards.
For example, a person developing malware could divide the work into seemingly harmless requests rather than asking an AI model for the complete malicious code in one session.
Private Safety Processing is designed to identify that broader pattern.
If the system detects suspicious activity, it sends OpenAI a “narrowly defined signal” describing the type of activity detected rather than handing over the customer's conversations. OpenAI can then determine if further action is necessary.
If it decides intervention is required, the company can contact the customer for additional information. The customer can then decide what data, if any, to provide to OpenAI.
That distinction is central to the company's pitch: OpenAI wants to know that something potentially dangerous is happening without necessarily seeing the customer's underlying conversations.
Anthropic's approach has raised privacy concerns
The announcement comes as Anthropic has taken a different approach for some of its more capable models.
In July, Anthropic introduced a data-retention policy allowing it to retain certain customer sessions for 30 days for safety monitoring. The policy applies to models classified under its covered-model framework, including Mythos-class models and future models with comparable capabilities.
Anthropic says the retention allows it to investigate potential misuse and, in limited circumstances, conduct human reviews through a controlled access system.
For companies handling sensitive financial, legal, medical or corporate information, however, the prospect of an AI provider retaining conversations can be uncomfortable.
That gives OpenAI an obvious opening.
Rather than simply promising that customer data will not be retained, OpenAI is attempting to show that privacy and long-term safety monitoring do not have to be mutually exclusive.
The distinction is particularly important for large enterprises that want powerful AI systems but cannot easily allow their employees' conversations or proprietary information to sit inside an AI company's systems.
The privacy fight is also a business fight
There is a commercial calculation behind the technical differences.
OpenAI and Anthropic are competing aggressively for enterprise customers, where trust, security and data handling can determine which AI provider a company chooses.
Anthropic has built a strong reputation around safety, while OpenAI is now positioning its own privacy-preserving monitoring technology as a competitive advantage.
The timing is significant. Anthropic has been growing rapidly, with its annualized revenue reportedly reaching $65 billion, while investors have floated valuations as high as $2 trillion for a potential future IPO. OpenAI is also reportedly preparing for a public offering.
That makes enterprise customers increasingly valuable.
For businesses, the argument is becoming less about simply asking which AI model is smarter and more about what happens to their data when they use it.
OpenAI's Private Safety Processing is an attempt to answer that concern with a different proposition: the company can monitor for dangerous behavior without necessarily keeping the conversations that reveal it.
Whether that approach proves effective at scale remains to be seen. But as AI systems become capable of carrying out increasingly complex tasks over long periods, the ability to detect misuse without turning customer privacy into collateral damage could become a major battleground between the industry's biggest players.
