OpenAI Private Intelligence: where ZDR records live
Zero Data Retention can still involve encrypted safety records in your cloud storage. Here's what Private Safety Processing changes, where Private Inference stands, and what the image leak establishes.
OpenAI Private Intelligence pairs Zero Data Retention with a system that can retain encrypted safety records for 30 days in customer-controlled storage. The system is called Private Safety Processing.
OpenAI's technical guide says it keeps no copies of those prompts and responses. An approved automated reviewer can still examine them in a protected runtime.
The change is where safety records live and who can read them. At DevDay on September 29, OpenAI also announced a Private Inference preview for this autumn. As of September 30, you need to assess those two pieces separately.
OpenAI Private Intelligence covers two different privacy questions
The DevDay recap groups Zero Data Retention with Private Safety Processing and the forthcoming Private Inference preview under the Private Intelligence name. PSP supports automated safety review without giving OpenAI personnel access to protected content. Private Inference is described as combining confidential computing with verifiable controls.
Separate those controls from the existing training policy when you compare them:
| Term | Question it addresses | Qualification |
|---|---|---|
| No training on API data by default | Will customer data train models? | Sharing can be enabled by opting in |
| Zero Data Retention | Will eligible request content be retained by OpenAI? | Endpoint and feature restrictions still apply |
| Private Safety Processing | How can automated safety review examine protected content? | Encrypted records can remain in customer-controlled storage |
| Private Inference | How is content protected while inference runs? | The announced preview is still forthcoming |
API data already isn't used for training unless you explicitly opt in, according to OpenAI's data-controls documentation. Private Intelligence builds on that baseline with a way to run safety processing under tighter content-access rules.
If you're buying for an enterprise, ask which control applies to your actual request path. The umbrella name won't answer that for every product.
Safety review reads encrypted records in a protected runtime
The PSP guide describes two flows. First, a safety classifier referral or an approved sampling policy can select an interaction. A referral alone doesn't mean the customer violated a policy.
The system encrypts the prompt and response, then writes the record to your regional cloud storage. OpenAI keeps an index with operational metadata and a storage reference instead of a content copy. The storage work happens asynchronously, without blocking inference.
Later, the safety pipeline retrieves that encrypted record. The reviewer uses an approved prompt and output schema in a hardware-attested computing environment designed to disable human access.
Only predefined safety signals and approved operational metadata can leave the review in plaintext. Detailed results are encrypted and stored with the original record's expiration. The guide gives these records a 30-day lifetime.
Automated examination still happens, and records still exist. PSP restricts content access and puts the retained content in storage you control.
Your encryption key can stop later decryption
The guide describes an OpenAI-managed inner encryption layer and a customer-managed Enterprise Key Management layer. Enable EKM and OpenAI's inner key alone isn't enough to decrypt the records; your key authorization is required too.
OpenAI recommends EKM for that added control. Revoking authorization prevents decryption of retained records. It won't delete them or undo processing already completed, so be clear about what revocation buys you.
This is OpenAI's documented design, rather than an independent security audit of the runtime or implementation.
ZDR still comes with storage and endpoint restrictions
OpenAI's data-controls page separates abuse-monitoring logs from application state. Under ordinary API retention, abuse-monitoring logs can contain content and stay for up to 30 days, subject to the documented exceptions. Approved ZDR changes that handling for eligible endpoints.
ZDR also forces store to false for Responses and Chat Completions requests. Features that need persistent application state can still be ineligible.
With PSP, you operate the storage holding encrypted safety records. OpenAI's guide requires them to remain available for at least 30 days. Owning the bucket doesn't remove that requirement.
PSP is enabled per project, so one project's setup doesn't establish the policy for every request in your organization. Its policy applies to that project's API traffic, including models that don't otherwise require PSP. The guide recommends a separate project for eligible requests that should use ZDR without PSP.
The docs also list exceptional retention and review paths, including image safety checks and advance-notified restrictions for severe-risk activity. Read the no-human-access claim within the protected PSP review's scope, alongside the relevant endpoint and policy conditions.
Private Inference is still an autumn preview
The launch recap gives Private Inference an autumn preview window, with no exact date, model list, or price.
OpenAI names confidential computing as the approach. The recap leaves implementation details and production commitments for your workload unsettled. Ask what you can verify, how approved software is identified, and which service components sit outside the protected execution boundary.
Those are questions to evaluate, not answers OpenAI has already supplied. PSP having a setup guide doesn't make the separate Private Inference preview available to every API customer today. You need an applicable preview agreement and technical specification before treating it as protection for your inference workload.
Glean's confidence is about training policy and ZDR
The Next Web reported this statement from Glean chief information security officer Sunil Agrawal: “OpenAI's no-training commitment and ZDR give Glean confidence to build with OpenAI.” The exact coverage places it alongside the Private Intelligence announcement.
Sunil Agrawal is expressing confidence in specific controls. His statement supplies no measured failure rate, independent audit, or evidence that every Glean workflow uses the forthcoming Private Inference system.
The reason he gives is useful: training policy and retention matter to a customer building with the API. Ask for the same clarity about your own features and configurations.
The 53-image disclosure was public on September 25
Days before the privacy announcement, Reuters reported on September 25 that OpenAI's agents had leaked 53 images from ChatGPT users. OpenAI declined to say when the images had been posted or whether they depicted identifiable people.
The count is 53 images; it doesn't establish 53 distinct affected users. Later coverage referred to Monday, September 28, but the Reuters report establishes an earlier public disclosure. We still don't know when the incident occurred.
Reuters says the agents could access images through anonymized user data used in training. Enterprise data wasn't eligible for training, while consumer users needed to opt out. The report doesn't identify ZDR enterprise requests as the source of the leaked images.
A ChatGPT subreddit post emphasized the training opt-out question. It captures the consumer concern raised by the disclosure, rather than documenting the enterprise PSP product.
The incident makes the trust questions more pressing: where can content go, what workload can read it, and what evidence shows the boundary holds? It doesn't establish that the new architecture caused the leak or would have prevented it.
Your storage setup remains your responsibility
If your organization is already approved for ZDR, the guide says you can set up PSP through the API console. Connect customer-controlled AWS S3, Azure Blob Storage, or Google Cloud Storage to an OpenAI project, then register and validate the connection.
Validation doesn't provide continuous storage-health monitoring. You're responsible for storage configuration, permissions, key authorization, retention, and responding to safety notices. Disconnect the last PSP storage connection and, the guide says, the project returns to your organization's default retention policy.
Check feature compatibility before assuming the privacy offer covers your agent application. OpenAI's Agents API overview says that service isn't currently ZDR-eligible, even with a self-hosted sandbox.
Follow one real workflow from request to tool output to retained records. That's how you establish where Private Intelligence's controls apply in the system you intend to use.
FAQ
What is OpenAI Private Intelligence?
It's the umbrella name for ZDR with Private Safety Processing and the announced Private Inference preview.
Can OpenAI staff read Private Safety Processing records?
The documented protected review disables human access to the content. Endpoint limitations and separate exceptional-retention policies still apply.
Does Zero Data Retention mean nothing is stored?
No. PSP stores encrypted safety records in customer-controlled storage. Some features also retain application state or aren't ZDR-eligible.
When is OpenAI Private Inference available?
The DevDay recap says this autumn, without an exact launch date.
Did agents leak images from 53 users?
Reuters reports 53 images from ChatGPT users. The report doesn't establish 53 distinct people or when the images were posted.
Sources
- OpenAI: DevDay 2026 recap
- OpenAI: ZDR with Private Safety Processing
- OpenAI: API data controls and retention limits
- OpenAI: Agents API retention limitations
- The Next Web: DevDay coverage and Glean's statement
- Reuters via MarketScreener: September 25 image disclosure
- Reddit: Consumer reaction to the image disclosure