OpenAI’s Privacy Play Takes Aim at Anthropic

OpenAI just drew a line in the sand on customer privacy, and it’s pointed straight at Anthropic. According to TechCrunch AI, the company is previewing a new service for select customers called Private Safety Processing, an automated system that watches for misuse while keeping none of the customer’s data. It’s a direct shot at Anthropic’s recent data-retention policy, and the timing is not an accident.

Here’s what happened and why it matters.

What OpenAI announced

Private Safety Processing is OpenAI’s answer to a hard problem: how do you catch bad actors without spying on your customers? As AI models get more capable, the pressure to police misuse grows. But enterprises handling sensitive data don’t want their conversations stored or inspected.

OpenAI’s pitch is that it can do both. TechCrunch AI reports the system uses an automated agent to monitor inputs and outputs across multiple conversations, not just one. If it spots something suspicious, it sends what OpenAI calls a “narrowly defined signal” flagging a specific type of activity. No human reads your chats. From there, OpenAI decides whether enforcement is needed and may reach out to the customer for context. The customer can choose to share data at their discretion.

The clever part is the multi-session view. A bad actor trying to build malware might spread requests across many chats to dodge detection. Private Safety Processing is built to connect those dots without a person ever reviewing the conversations.

The two approaches, side by side

This is really a story about two philosophies. Here’s how they stack up, per TechCrunch AI:

OpenAI (Private Safety Processing)

  • Retains none of the customer’s data
  • Monitors across multiple sessions with an automated agent
  • Sends only a narrow signal when something triggers
  • Customer shares data voluntarily, if at all
  • Extends the existing Zero Data Retention model

Anthropic (data-retention policy, announced July)

  • Keeps user sessions and conversations for 30 days on “covered models”
  • Covered models include all Mythos-class models and future ones with similar capabilities
  • Allows human review, but only through a “controlled access path” with a small set of approved reviewers
  • Every review session is logged in a tamper-proof record reviewers can’t alter

Both companies largely follow Zero Data Retention, or ZDR, which scans for abuse on a per-session basis without storing data. The split shows up on those high-capability “covered models,” where Anthropic reserves the right to retain and, in limited cases, have humans inspect data. OpenAI is betting that enterprises hate that idea enough to switch.

Why this matters

What stands out here is the positioning. Anthropic’s 30-day retention was designed for safety, letting the lab analyze potential abuse. But it rattled some enterprise customers, especially those in regulated industries or sitting on piles of sensitive data. OpenAI saw the opening and moved.

For practitioners, the practical difference is real. If you’re building on these APIs and your data can’t leave your control, the retention policy is a procurement question, not a footnote. OpenAI is now offering a story you can take to your security team: monitoring happens, but your conversations don’t get parked on someone else’s servers for a month.

Anthropic’s counterargument is transparency. Its human reviews are rare, gated, and logged in a way reviewers can’t suppress. That’s a defensible design. But “we retain less” is an easier sell than “we retain some, carefully.”

The bigger picture

This lands during a tense stretch between the two labs. TechCrunch AI notes OpenAI’s Q2 grew more slowly than Anthropic’s, and Anthropic’s annualized revenue run rate is now reportedly around $65 billion. Investors have floated a $2 trillion IPO for Anthropic, while OpenAI is working on its own public offering. Privacy has become another front in that fight.

Expect this to escalate. Once one lab makes “we keep nothing” a selling point, the others feel the pull to match it. If you run AI workloads at an enterprise, watch for Private Safety Processing to move from preview to general availability, and read the retention terms closely before you sign anything.

For the full breakdown, the original report at TechCrunch AI has the details.

Scroll to Top