OpenAI Adds Zero Data Retention and Private Safety Processing for Enterprise AI
OpenAI Adds Zero Data Retention and Private Safety Processing for Enterprise AI
OpenAI 为企业级 AI 增加“零数据留存”与“私有安全处理”功能
OpenAI has announced Zero Data Retention (ZDR) for frontier-model deployments and a new Private Safety Processing layer for enterprise customers. The combination is designed to address a difficult enterprise AI requirement: keeping sensitive prompts and responses under customer control while preserving safety monitoring that can identify harmful or policy-violating patterns. OpenAI 宣布为其前沿模型部署推出“零数据留存”(Zero Data Retention, ZDR)功能,并为企业客户引入了全新的“私有安全处理”(Private Safety Processing)层。这一组合旨在解决企业级 AI 应用中的一个难题:在保持敏感提示词(Prompts)和回复内容由客户掌控的同时,依然能够进行必要的安全监控,以识别有害或违反政策的行为模式。
According to OpenAI’s announcement on Zero Data Retention for frontier models, ZDR means OpenAI will not retain customer prompts or model responses after an individual request. Enterprise data also will not be used to train OpenAI models unless the customer explicitly opts in. The announcement is particularly relevant for regulated organizations that need clearer boundaries around data handling before deploying frontier models in sensitive workflows. 根据 OpenAI 关于前沿模型“零数据留存”的公告,ZDR 意味着 OpenAI 不会在单次请求完成后保留客户的提示词或模型回复。此外,除非客户明确选择加入,否则企业数据不会被用于训练 OpenAI 的模型。对于那些在敏感工作流中部署前沿模型前,需要明确数据处理边界的受监管机构而言,这一公告尤为重要。
What OpenAI announced: The most consequential change is the proposed data-control model for eligible frontier-model deployments. Under ZDR, OpenAI says customer content can remain on infrastructure controlled by the customer. Alternatively, content can be stored on OpenAI infrastructure using encryption keys controlled by the customer, so OpenAI personnel do not hold copies of those keys. OpenAI 公布的内容:最重大的变化是针对符合条件的前沿模型部署所提出的数据控制模型。在 ZDR 模式下,OpenAI 表示客户内容可以保留在由客户控制的基础设施上。或者,内容也可以存储在 OpenAI 的基础设施中,但使用由客户控制的加密密钥,这意味着 OpenAI 的员工无法持有这些密钥的副本。
That distinction matters because enterprise privacy is not limited to a promise not to train on data. Businesses also need to consider where content is stored, who can access it, how long it persists, and what evidence is available when an incident or compliance review occurs. OpenAI positions ZDR as a way to reduce retention while allowing customers to use its frontier models in environments with strict data-governance requirements. 这一区别至关重要,因为企业隐私不仅仅是“不使用数据进行训练”的承诺。企业还需要考虑内容存储在哪里、谁可以访问、数据保留多久,以及在发生事故或合规审查时有哪些证据可用。OpenAI 将 ZDR 定位为一种在减少数据留存的同时,允许客户在有严格数据治理要求的环境中部署其前沿模型的方法。
The announcement builds on OpenAI’s existing business privacy commitments, including no training on business data by default for business offerings, data-processing agreements, and data-residency options. ZDR adds a more specific retention and key-control model for the deployments covered by the new program. 该公告建立在 OpenAI 现有的商业隐私承诺基础之上,包括默认不对商业产品使用业务数据进行训练、签署数据处理协议以及提供数据驻留选项。ZDR 为新计划涵盖的部署提供了更具体的留存和密钥控制模型。
Zero Data Retention and customer-controlled storage
零数据留存与客户控制的存储
OpenAI’s description supports several concrete takeaways for enterprise architecture and governance teams: OpenAI 的描述为企业架构和治理团队提供了几个具体的要点:
- Prompts and model responses are not retained by OpenAI after a request in a ZDR deployment.
- 在 ZDR 部署中,OpenAI 不会在请求完成后保留提示词和模型回复。
- Model training requires explicit customer opt-in, rather than using enterprise data by default.
- 模型训练需要客户明确同意,而非默认使用企业数据。
- Customers can keep content on infrastructure they control.
- 客户可以将内容保留在自己控制的基础设施上。
- Customers can also use OpenAI infrastructure while maintaining control of the encryption keys that protect stored content.
- 客户也可以使用 OpenAI 的基础设施,同时保持对保护存储内容的加密密钥的控制权。
The approach is intended to keep customer data private while enabling continuing safety protections. The announcement does not provide a universal product-coverage matrix. It remains unclear whether ZDR will apply in the same way across the API, ChatGPT Business, ChatGPT Enterprise, or other OpenAI offerings. OpenAI also has not specified pricing in the published material. Enterprises should therefore treat ZDR as an important announced capability, but validate availability and contractual scope for their intended deployment. 这种方法旨在保持客户数据的私密性,同时实现持续的安全保护。该公告并未提供通用的产品覆盖矩阵。目前尚不清楚 ZDR 是否会以相同方式应用于 API、ChatGPT Business、ChatGPT Enterprise 或其他 OpenAI 产品。OpenAI 在发布的材料中也未明确定价。因此,企业应将 ZDR 视为一项重要的已发布功能,但需针对其预期的部署场景验证可用性和合同范围。
Private Safety Processing changes the safety trade-off
私有安全处理改变了安全权衡
Private Safety Processing is OpenAI’s answer to the tension between privacy and abuse prevention. Rather than assessing each interaction separately, the layer is intended to extend safety protections across related interactions. That broader view can support pattern-based risk detection, even when individual requests may not reveal the full context of a potential risk. “私有安全处理”是 OpenAI 对隐私保护与滥用预防之间矛盾的回应。该层旨在跨相关交互扩展安全保护,而不是单独评估每次交互。这种更广阔的视角可以支持基于模式的风险检测,即使单个请求可能无法揭示潜在风险的全部背景。
OpenAI says the underlying customer content is not exposed to its personnel through this process. When the system identifies a risk, it sends a narrowly defined signal to OpenAI for enforcement decisions. Customers retain the investigation and auditing data within their own systems. This approach is notable because it separates content from enforcement signals. For organizations evaluating AI systems, that separation could make it easier to preserve internal audit trails while limiting access to sensitive underlying material. However, OpenAI has not yet published the technical white paper that is expected in September 2026, so important implementation details remain to be clarified. OpenAI 表示,在此过程中,底层的客户内容不会暴露给其员工。当系统识别出风险时,它会向 OpenAI 发送一个定义狭窄的信号以供决策执行。客户将调查和审计数据保留在自己的系统中。这种方法值得注意,因为它将内容与执行信号分离开来。对于评估 AI 系统的组织而言,这种分离可以更容易地保留内部审计追踪,同时限制对敏感底层材料的访问。然而,OpenAI 尚未发布预计于 2026 年 9 月推出的技术白皮书,因此重要的实施细节仍有待明确。
| Capability | Zero Data Retention | Private Safety Processing |
|---|---|---|
| 功能 | 零数据留存 | 私有安全处理 |
| Primary purpose | Limits retention of prompts and model responses after a request. | Supports safety monitoring across related interactions. |
| 主要目的 | 限制请求后提示词和模型回复的留存。 | 支持跨相关交互的安全监控。 |
| Customer data handling | Content can remain on customer infrastructure or use customer-controlled encryption keys on OpenAI infrastructure. | Underlying content is not exposed to OpenAI personnel. |
| 客户数据处理 | 内容可保留在客户基础设施上,或在 OpenAI 基础设施上使用客户控制的加密密钥。 | 底层内容不会暴露给 OpenAI 员工。 |
| Information sent to OpenAI | OpenAI says prompts and responses are not retained after a request. | A narrowly defined risk signal is sent for enforcement decisions. |
| 发送给 OpenAI 的信息 | OpenAI 表示请求后不保留提示词和回复。 | 发送定义狭窄的风险信号以供执行决策。 |
| Current status | Announced for frontier-model deployments. | Being tested with early customers ahead of broader rollout plans. |
| 当前状态 | 已宣布用于前沿模型部署。 | 正在与早期客户进行测试,随后将进行更广泛的推广。 |
What the announcement means for enterprises
该公告对企业的意义
For businesses in finance, healthcare, legal services, public-sector work, and other data-sensitive fields, the announcement moves the conversation from general privacy commitments to more operational questions. Teams can now assess whether a deployment could meet their requirements for retention, encryption-key control, auditing, safety review, and internal access boundaries. 对于金融、医疗、法律服务、公共部门以及其他数据敏感领域的企业而言,这一公告将讨论重点从一般的隐私承诺转向了更具操作性的问题。团队现在可以评估部署方案是否满足其在数据留存、加密密钥控制、审计、安全审查和内部访问边界方面的要求。
The announcement also reinforces that privacy controls and safety controls do not have to be treated as mutually exclusive. A system that simply eliminates access to content may complicate risk monitoring. OpenAI’s proposed model instead seeks to retain monitoring through limited risk signals while leaving investigation data with the customer. Its effectiveness will depend on technical details that have not yet been published, including the scope of the signals, enforcement process, and supported deployment configurations. Organizations considering the new capabilities should focus their due diligence on: Which OpenAI products and frontier models are included in the rollout. Whether the organization’s data classification permits the selected… 该公告还强调,隐私控制和安全控制不必被视为相互排斥。仅仅消除对内容的访问可能会使风险监控变得复杂。相反,OpenAI 提出的模型试图通过有限的风险信号来保留监控能力,同时将调查数据留给客户。其有效性将取决于尚未发布的技术细节,包括信号范围、执行流程和支持的部署配置。考虑采用这些新功能的组织应重点关注:哪些 OpenAI 产品和前沿模型包含在推广范围内;以及组织的分类数据是否允许使用所选的……