Both labs now agree single-request safety checks aren't enough for frontier models — only one is making you give up zero data retention for it
TL;DR: On 19 August 2026, OpenAI previewed Private Safety Processing — safety monitoring that spots misuse across related interactions, not one request at a time, while staying compatible with Zero Data Retention. It aims squarely at Anthropic’s covered-models policy, in force since 9 June 2026: prompts and outputs from Mythos-class models are retained 30 days, “on every platform where these models are offered.” Per Anthropic’s own documentation, covered models are not available with ZDR and cannot be used under a HIPAA BAA — a hard exclusion for regulated workloads. The striking part is the agreement: both labs describe the same threat in nearly the same words — best-of-N jailbreaking, coordinated probing across accounts, agents drifting past their authority — attacks invisible in one request. They split on the price. Anthropic: hold the content 30 days, with human review only through a controlled path recorded in tamper-proof logs. OpenAI: keep content on customer infrastructure or encrypted under customer keys, and let only a “narrowly defined signal” out. The asymmetry that decides it today is maturity — Anthropic’s constraint is live and enforceable; OpenAI’s answer is a preview, with rollout and a technical white paper due in September.
What OpenAI announced
The framing OpenAI chose is telling. The post is titled around offering Zero Data Retention for frontier models — positioning ZDR as something a lab must work to preserve as models get more capable, rather than a default that survives on its own.
The baseline is unchanged: under ZDR, OpenAI does not retain prompts or model responses after a request is processed, customer content is not available to OpenAI personnel for review, and enterprise data is not used for training unless a customer explicitly opts in. What’s new is the acknowledgment that this baseline has a blind spot. Existing ZDR-compatible safety systems evaluate each interaction individually — and, in OpenAI’s words, some serious risks “may only become visible across multiple interactions.”
Private Safety Processing is the proposed fix. It extends automated monitoring across related interactions while, OpenAI says, keeping content out of its personnel’s hands. Two storage arrangements are described:
- Customer-controlled infrastructure — the standard ZDR deployment, where content stays where the customer put it.
- OpenAI-provided storage — content encrypted with keys the customer controls, which OpenAI states its personnel do not hold a copy of and therefore cannot use to access the content.
In both, automated systems can flag potential misuse and emit limited safety signals without exposing prompts or responses. When something trips, OpenAI receives a “narrowly defined signal indicating the type of activity involved” — and, explicitly, “OpenAI personnel do not receive access to the customer content even when it is flagged.” Enforcement decisions follow from the signal; customers can investigate using their own systems and may choose to share information to appeal or to support an abuse investigation.
Status matters here: it is being tested with early customers. Rollout and a technical white paper are promised for September 2026. Named collaborators include Glean, Databricks, Abridge and Microsoft.
What Anthropic actually requires
Anthropic’s policy is not a rumour or a report — it’s documented, dated, and specific, which makes the comparison fair.
Per Anthropic’s privacy documentation (article dated 10 July 2026, policy effective 9 June 2026), prompts submitted to and outputs generated by covered models are retained for 30 days to support safety work, “on every platform where these models are offered.” Covered models means Mythos-class models and future models with similar capabilities that Anthropic designates. Everything else is unaffected.
The scope is narrower than headlines suggest, and worth stating precisely. Consumer plans — Claude Free, Pro and Max across web, desktop and mobile, including Claude Code — are unaffected, because inputs and outputs are already retained there. The change bites only organizations that had ZDR: ZDR workspaces in Claude Console, Claude Code with ZDR in Claude Enterprise, or access through AWS Bedrock, Google Cloud Agent Platform or Microsoft Foundry with ZDR. Those organizations must turn retention on for the workspaces where they want covered models; other ZDR workspaces keep ZDR.
The protections around retained data are more substantial than “they keep your prompts” implies. By default no Anthropic personnel can read retained conversations. Human review happens only through a controlled access path — for instance when automated trust-and-safety systems flag content — performed by a small set of approved reviewers, with every access recorded in a tamper-proof log that reviewers cannot suppress or modify. Data is deleted automatically after 30 days, except where flagged or legally required. Eligible organizations can add customer-managed encryption keys and access-transparency audit logs.
And then the line that should drive procurement decisions: Anthropic’s BAA documentation states that covered models require 30-day retention, aren’t available with zero data retention, and can’t be used under the BAA. If you are a HIPAA-covered entity, the Mythos-class tier is not a configuration option — it is outside your agreement.
The agreement nobody is highlighting
Read the two labs’ threat descriptions side by side and the competitive framing starts to look thin.
Anthropic justifies retention this way: some attacks only become visible across multiple requests. Best-of-N jailbreaking sends hundreds of slight prompt variations hoping one lands. Larger patterns — state-sponsored espionage, data-extortion campaigns — only surface when classifiers can zoom out across many requests. Detecting them “requires temporarily retaining prompts and outputs so they can be analyzed together, rather than one at a time.”
OpenAI justifies Private Safety Processing this way: harmful intent often becomes clear only when multiple interactions are viewed together; bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research; and risks develop over long agentic tasks — for example, a system continuing to act after being told to stop.
That is the same threat model, written twice. Both labs have concluded that per-request safety evaluation is structurally insufficient for frontier-capability models — which is a genuinely important industry consensus, and consistent with what we saw in OpenAI’s own cyber-capability posture and Anthropic’s Project Glasswing work.
The disagreement is purely about what customers must surrender to get it. Anthropic concluded the content has to sit together somewhere for 30 days. OpenAI is betting it can do cross-interaction analysis without that. OpenAI even names the competitive point without naming the competitor: “Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations.”
Why this matters
A model tier can now be excluded by your compliance posture, not your budget. This is the concrete shift. Historically, model choice was about capability and price; the Claude vs ChatGPT decision turned on quality and cost. Now a healthcare provider under a BAA cannot use Anthropic’s top tier at all, and an organization with a contractual no-retention commitment to its customers faces the same wall. Check which models your teams actually call before assuming your existing agreement covers them.
“Zero retention” has a carve-out — know it before you write it into policy. OpenAI notes it is legally required to report apparent CSAM, and that images flagged as potential CSAM are retained for manual review even in ZDR deployments. Anthropic likewise exempts flagged or legally required material from automatic deletion. This is correct and universal, but if you have told a customer “nothing is ever retained,” that statement is imprecise at both vendors.
Preview is not product. OpenAI has announced a design, four named collaborators, and a September date for rollout and a white paper. Anthropic has a policy in force with documented, auditable controls. Both facts are creditable; they are not the same kind of fact. The right response to Private Safety Processing today is a pilot and a diary note for September — not a standardization decision.
Expect this to become a procurement checkbox across the market. Once one lab claims cross-session safety monitoring without retention, “do you require retention for your frontier tier?” joins the RFP alongside SOC 2 and data residency — and it will be asked of Gemini and every other enterprise provider too. Note also what this is not: like Claude Code’s self-hosted environments, which relocate execution rather than inference, none of this changes where the model itself runs. It governs what is kept and who may read it, and those are different questions from data residency. Nor is it free: in the same week OpenAI put the cost of its new monitoring at roughly 20% of the inference compute being watched, which is the first public number anyone has attached to this class of safety infrastructure.
The verdict
OpenAI has made a real argument, not merely a competitive jab: if per-request monitoring is inadequate for frontier models — and both labs now say it is — then the industry needed someone to try solving it without charging customers their retention guarantees. Attempting that is worth credit.
But the shipped-versus-promised gap decides today’s action. Anthropic’s constraint is live, documented to the workspace level, with review controls specific enough to audit. OpenAI’s alternative is a preview whose technical substance arrives in September.
Recommendation: If you hold a hard no-retention requirement — a BAA, regulated data, a commitment you cannot renegotiate — Anthropic’s covered models are already out, and you should confirm which models your teams are calling today rather than discovering it in an audit. If your requirement is strong but flexible, Anthropic’s 30-day window with tamper-proof review logging is a defensible trade for the capability, and the enable-per-workspace design lets you keep ZDR everywhere else. Either way, pilot Private Safety Processing if you’re offered it, and read the September white paper before you standardize on it — particularly the detail on how much a “narrowly defined signal” can reveal in aggregate, which is the part a one-page announcement cannot settle.
Update (23 August 2026). The covered-model constraint described here just met a product that routes around it. On 21 August Anthropic made Mythos 5 the engine behind Claude Security, its codebase vulnerability scanner — in public beta for Claude Enterprise, with no direct model access at all. You receive patches, alerts and CWE-tagged findings rather than a prompt box, which is precisely the mechanism that let Anthropic widen distribution without loosening its restrictions. It also sharpens the question this article documents: the covered-models policy retains Mythos prompts and outputs for 30 days “on every platform where these models are offered,” and Claude Security is now such a platform — but Anthropic’s privacy documentation does not yet name it among the affected surfaces, and the announcement did not mention retention. For a scanner pointed at an entire source tree, that is a question to close in writing before enabling scheduled scans.
Frequently asked questions
What is OpenAI's Private Safety Processing?
It is automated safety monitoring that looks for misuse patterns across multiple related interactions instead of evaluating each request in isolation, without giving OpenAI staff access to the underlying content. Announced as a preview on 19 August 2026, it works either with content held on infrastructure the customer controls (standard Zero Data Retention deployments) or, in an option OpenAI says it is still developing, on OpenAI infrastructure encrypted with customer-controlled keys that OpenAI does not hold. When something is flagged, OpenAI receives what it calls a 'narrowly defined signal' indicating the type of activity — not the prompts or responses. It is being tested with early customers, with broader rollout and a technical white paper planned for September 2026.
Does Anthropic really require 30-day retention for its top models?
Yes, for models it designates as 'covered models.' Per Anthropic's privacy documentation, prompts submitted to and outputs generated by covered models are retained for 30 days 'on every platform where these models are offered.' This applies to Mythos-class models and future models Anthropic designates similarly; the policy took effect 9 June 2026. It only changes things for organizations that previously had zero data retention — ZDR workspaces in Claude Console, Claude Code with ZDR in Claude Enterprise, or access via AWS Bedrock, Google Cloud Agent Platform or Microsoft Foundry with ZDR. Consumer plans and all non-covered models are unaffected, and those organizations must explicitly enable retention on the workspaces where they want covered models.
Can I use Anthropic's covered models for healthcare data under a BAA?
No. Anthropic's own documentation on Business Associate Agreements states plainly that covered models require 30-day data retention and are not available with zero data retention, and that services cannot use covered models under the BAA. For HIPAA-regulated workloads this is a hard exclusion, not a configuration choice — you can use Anthropic's non-covered models under a BAA, but not the Mythos-class tier. Any organization that assumed the whole model lineup was available under its existing agreement should check which models its teams are actually calling.
Is OpenAI's approach actually more private, or is it marketing?
The architectural claim is meaningful and the maturity gap is equally meaningful. OpenAI's design keeps content out of its own staff's reach in both storage modes and reduces what crosses the boundary to a categorical signal, which is a genuinely different posture from retaining full prompts and outputs for 30 days. But Anthropic's controls are live and specific — controlled-access human review by a small approved set, tamper-proof logs reviewers cannot suppress or modify, automatic deletion after 30 days, optional customer-managed keys and access-transparency logs — while OpenAI's is a preview with early customers and a white paper due in September. Judge the shipped thing against the shipped thing, and revisit when the paper lands.
Does Zero Data Retention mean nothing is ever kept?
Not quite, and the exception is the same across the industry. OpenAI notes that, like other frontier providers, it is legally required to report apparent child sexual abuse material, and images flagged as potential CSAM continue to be retained for manual review and reporting even in ZDR deployments. Anthropic similarly excludes from automatic 30-day deletion anything flagged by its trust and safety systems or that it is legally required to keep. 'Zero retention' is therefore a strong default with a narrow, legally mandated carve-out — worth knowing precisely if you are writing it into a policy document.
Which provider should an enterprise pick on this basis?
It depends on whether your constraint is contractual or architectural. If you have a hard, auditable no-retention requirement today — regulated data, a BAA, a customer commitment you cannot renegotiate — Anthropic's covered models are simply off the table, and that is decided by their documentation rather than by negotiation. If your requirement is strong-but-flexible, Anthropic's 30-day window with tamper-proof review logging may well be acceptable, and it buys you a model tier you may want. Do not make a long-term standardization decision on OpenAI's preview alone; it is the right thing to pilot and the wrong thing to sign for.
Sources
- OpenAI — Offering Zero Data Retention for frontier models (19 Aug 2026)
- Anthropic Privacy Center — Data retention practices for Covered Models (10 Jul 2026)
- Anthropic Privacy Center — Business Associate Agreements (BAA) for Commercial Customers
- TechCrunch — OpenAI seeks to one-up Anthropic with new customer privacy protections
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.