OpenAI is testing a new safety system that aims to detect possible cyber threats across multiple AI conversations while keeping customer data private. The new system is called Private Safety Processing, and is being tested with some early customers, including Microsoft and Databricks. OpenAI plans to make it available and publish a technical paper about it in September. The move comes as businesses increasingly use advanced AI models for complex tasks and handle sensitive information. OpenAI says the new system can identify risks that may not be visible when conversations are checked one at a time. It is designed to provide stronger safety checks without giving OpenAI access to customer content.
Private Safety Processing is designed to look for possible security threats across multiple interactions with an AI model. OpenAI says this is important because some risks may only become clear when several conversations are viewed together.
Aleah Houze, OpenAI’s head of product policy, said increasingly powerful AI models need a different approach to safety. “We’re seeing with more capable frontier models that often, risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions,” Houze said during a press briefing, as quoted by Bloomberg.
For example, a person may ask about a weakness in a company’s software in one conversation. Later, they may ask about remote access or security tools. Looking at these questions separately may not reveal a threat. Together, they could point to a possible cyberattack.
Also read: Samsung Galaxy event date announced: Here is when Galaxy S26 FE will launch
we support business privacy!https://t.co/SJ6w5DeYTY
— Sam Altman (@sama) August 19, 2026
Private Safety Processing builds on the safety systems already used for customers with zero data retention, or ZDR. These systems normally check each interaction separately. The new system can check related interactions to identify patterns. OpenAI says its automated systems can do this without giving its employees access to customer content.
Customer data can remain in infrastructure controlled by the customer or in storage provided by OpenAI. When OpenAI provides the storage, the data is encrypted with keys controlled by the customer. OpenAI employees do not have copies of these keys.
If the system detects a possible risk, OpenAI receives only a limited signal. The company says its employees still cannot see the customer content, even if an interaction is flagged.
Customers can review alerts and enforcement decisions through their own systems. They can also choose to share relevant information with OpenAI if they want to appeal a decision or help investigate confirmed abuse.