As AI models grow more powerful, so does the potential for mischief - and the chorus of voices demanding guardrails. AI companies now face the delicate task of respecting enterprise customers' privacy while keeping an eye out for abuse. Sensing a chance to one-up rival Anthropic, OpenAI has announced a privacy-centric approach to monitoring for misuse: Private Safety Processing. This automated system watches for potential abuse while retaining none of the customer's data, because apparently, you can have your cake and eat it too - if the cake is made of algorithms.

This move directly counters Anthropic's recently announced data-retention policy, which has irked some customers. That policy, which took effect in July, allows the AI lab to keep user data - all sessions and conversations - for 30 days when it comes to 'covered models,' including all Mythos-class models and 'future models with similar capabilities.' The policy was designed for safety, letting the lab sift through potential impropriety. But it has deeply concerned enterprises handling sensitive data who don't want their information harbored or inspected by the AI lab.

OpenAI, like most AI companies, already offers a level of privacy via Zero Data Retention (ZDR). ZDR uses agents within the OpenAI API to monitor for abuse on a per-session basis, so customer data isn't retained, but bad activity can still be flagged without human intervention. Notably, Anthropic also abides by ZDR - except for 'covered models' like Fable.

OpenAI says Private Safety Processing widens ZDR's scope. It's a form of long-horizon safety monitoring that assesses inputs and outputs across multiple conversations, not just one. The monitoring is done by an agent that, if triggered, catches interactions and analyzes them across sessions for signs of misuse. This helps detect malicious use that spans multiple sessions - like a bad actor trying to engineer malware by spreading out requests to avoid detection. Private Safety Processing can analyze those conversations for abuse without human review.

If triggered, the system may send a 'narrowly defined signal' to OpenAI warning of specific activity. Based on that, OpenAI can decide if 'enforcement is necessary.' If so, they'll reach out to the customer for context or to work on the issue, and the customer may choose to share data at their discretion. Meanwhile, Anthropic notes that human review of customer data can occur, but only through a 'controlled access path' involving 'a small set of approved reviewers,' with every review session recorded in a tamper-proof log that reviewers can't suppress or modify.

The corporate rivalry between OpenAI and Anthropic is heating up, with both seeking any advantage. A recent report showed OpenAI's Q2 growth slower than Anthropic's, whose annualized revenue run rate is reportedly $65 billion. Anthropic investors have floated an IPO at $2 trillion, while OpenAI is also working on its IPO. In the race to win enterprise trust, OpenAI just threw down the privacy gauntlet - and it's wrapped in zeroes and ones.