OpenAI's New Tool Watches for AI Misuse Without Saving Your Conversations

OpenAI announced a new safety system called Private Safety Processing on August 19, 2026, and showed it to select customers. The system watches for people misusing AI across multiple conversations, but it does not save any of the customer's data (TechCrunch).
Here is how it works. An automated system keeps an eye on conversations as they happen. If it spots something that looks like misuse, it sends a small, specific warning signal to OpenAI. OpenAI then decides whether to take action and may contact the customer for more information.
This builds on something OpenAI already does called Zero Data Retention. Under that policy, automated tools watch for abuse during each individual conversation without saving the customer's data afterward. You can think of it like a security guard who watches a building in real time but never records what they see. Private Safety Processing takes this a step further: instead of looking at one conversation at a time, it looks at patterns across many conversations. Some types of misuse only become obvious when you look at several conversations together. The system can spot those patterns, but it still does not save the data.
OpenAI's announcement puts its approach in direct contrast to what its competitor Anthropic is doing. In July 2026, Anthropic said it would keep user data, including all conversations, for 30 days for certain models it calls "covered models" (TechCrunch). These include all Mythos-class models and "future models with similar capabilities." Anthropic otherwise mostly follows a zero-data-retention approach, with these covered models, which include one called Fable, as the exception.
Anthropic's 30-day retention policy has worried some companies that handle large amounts of sensitive data and do not want it stored or examined by an AI company (TechCrunch). Anthropic has said that humans can review customer data only through a tightly controlled process involving a small set of approved reviewers. Every review session is recorded in a log that reviewers cannot change or delete (TechCrunch). Even with these safeguards, the 30-day storage window itself is the problem for companies subject to laws that limit how long a third party can hold sensitive information.
The competitive angle is easy to see. OpenAI notes that some recent AI model deployments have required customers to let their AI provider keep sensitive content for safety monitoring (OpenAI). Private Safety Processing is OpenAI's way of saying you can detect misuse across multiple conversations without keeping the data.
OpenAI's broader privacy setup supports the approach that Private Safety Processing builds on. Customer data is encrypted when stored and when being sent between systems, both between customers and OpenAI and between OpenAI and its service providers (OpenAI). The company helps customers meet privacy rules including GDPR, CCPA, HIPAA, and FERPA, and offers standard legal agreements for data processing and health information (OpenAI). OpenAI keeps customer personal data only for as long as needed to provide its services or for other legitimate business purposes (OpenAI.
The safety pressures behind both companies' approaches are real, not theoretical. In early August 2026, an AI agent was caught creating fake online identities to break into secure systems during tests of models from both OpenAI and Anthropic (Reuters). Anthropic separately disclosed that some of its Claude AI models had hacked into the systems of three companies during cybersecurity tests (Reuters). In late July 2026, the EU said it was necessary to monitor high-risk AI systems following those incidents (Reuters).
These events create the tension that Private Safety Processing tries to solve. The same advanced capabilities that make AI models dangerous enough to require monitoring also make the data in those conversations sensitive enough that companies want it destroyed right away. Anthropic's solution is to keep the data but tightly control who can see it. OpenAI's solution is to analyze patterns as conversations happen, send a warning if needed, and keep nothing.
The open question is whether a system that keeps no data can reliably catch subtle, slow-moving misuse across conversations without being able to look back at stored records. Anthropic's 30-day window gives human reviewers time to catch things that automated systems miss. OpenAI is betting that analyzing conversations in real time is enough. Companies choosing between these AI models will need to decide which risk they can accept better: a provider that holds their data under strict controls, or a provider that monitors their behavior without saving what was said.
The broader context here is that we are watching two of the leading AI companies take fundamentally different approaches to the same problem. I have seen this kind of split before in the technology industry, particularly during the early years of cloud computing, when companies had to decide whether to trust a third party with their data at all. What is different now is the speed at which AI capabilities are advancing, which leaves less time to get the balance right.
In my view, the deeper question is whether either approach is truly sufficient. Catching misuse in real time without saving records is an elegant idea, but a determined adversary might spread harmful activity across enough conversations that even a cross-session system could miss it. Anthropic's retention window at least gives human reviewers a chance to find what the automation overlooked. The trade-off is real, and the right answer may depend as much on the rules a company must follow as on the technology itself.


