Key takeaways
- OpenAI's Private Safety Processing detects misuse across conversations without storing data, directly addressing enterprise concerns about third-party data retention.
- Anthropic's policy keeps user data for 30 days on covered models and applies human review through a controlled access path, a tradeoff OpenAI avoids entirely.
- The competition reflects broader market dynamics: Anthropic's annualized revenue run rate is $65 billion with a potential IPO valuation of $2 trillion, while OpenAI's Q2 growth has slowed by comparison.
- Enterprises must choose between data minimization (OpenAI's approach) and human oversight with audit trails (Anthropic's approach) based on their risk tolerance and regulatory environment.
The escalating competition between OpenAI and Anthropic over enterprise customers now centers on how they monitor for misuse and handle customer data in the process. OpenAI has announced Private Safety Processing, a new service available to select customers that detects abuse across multiple conversations without retaining any customer data—a direct response to Anthropic’s data retention policies that have drawn criticism from enterprises handling sensitive information.
OpenAI’s Private Safety Processing
OpenAI’s Private Safety Processing operates as an automated agent that watches for potential abuse across customer interactions while storing nothing about those conversations. The system represents an expansion of the company’s existing Zero Data Retention policy, which already monitors individual sessions for malicious activity. Private Safety Processing extends this capability to detect patterns that unfold over multiple conversations—the kind of threat that a malicious actor might deliberately spread across sessions to evade detection.
The system is designed to identify sophisticated attacks that might otherwise escape notice. Consider a scenario in which someone attempts to engineer malware for a cyberattack: fragmenting requests across separate conversations could evade single-session detection. By analyzing the same customer’s inputs and outputs across multiple conversations over time, Private Safety Processing identifies whether individual requests, harmless when viewed alone, form a coherent threat pattern when combined.
When the system detects suspicious activity, it generates what OpenAI calls a “narrowly defined signal” that alerts the company to a specific type of concern. This signal acts as the trigger for OpenAI’s response options: the company can decide whether enforcement is necessary and, if needed, reach out to the customer to discuss the issue. At that point, the customer can choose to share additional data with OpenAI at their discretion, but sharing remains optional rather than automatic.
Anthropic’s Data Retention Alternative
Anthropic announced its data retention policy in July, enabling the company to keep user sessions and conversations for 30 days when customers use what it calls “covered models”—a category including all Mythos-class models and future models with similar capabilities. The policy was framed as a safety measure that allows the company to identify and prevent misuse. However, enterprises that handle sensitive data, including financial records, trade secrets, or personal health information, have objected to having such information stored and reviewed by a third party, even with safeguards.
Anthropic also operates under Zero Data Retention in most cases—the difference is that retention applies as an exception for covered models. This distinction between default and exception has created friction with customers who either fall into the covered model category or worry about future policy changes affecting their use cases.
Human Review and Audit Trails
When human review of customer data occurs at Anthropic, it follows what the company describes as a “controlled access path” restricted to a small set of approved reviewers. Every review session is recorded in a tamper-proof log that reviewers cannot suppress or modify. This layer of oversight attempts to address privacy concerns through transparency and accountability rather than data minimization.
Anthropic’s framework assumes that enterprises will accept data retention if access to that data is sufficiently restricted and auditable. The controlled access model represents a middle ground between unlimited data access and no retention at all, though enterprises concerned about sensitive information may not view it as sufficient.
The Case for Data Retention
Anthropic’s position assumes that some data retention is necessary for effective safety monitoring and pattern analysis. The company argues that access to historical conversations enables better identification of edge cases and sophisticated misuse patterns that a real-time agent might miss. The 30-day window provides enough temporal scope to detect attacks that unfold gradually or span multiple days of activity, without creating indefinite records.

Agent-Based vs. Human-Centered Approaches
Monitoring Without Storage
OpenAI’s Zero Data Retention uses automated agents to scan each session individually for abuse signals. These agents operate within the OpenAI API and require no human review to function. Private Safety Processing preserves this agent-based structure while expanding the observation window: instead of analyzing one session at a time, agents now track patterns across multiple conversations over time.
The distinction is critical for detecting sophisticated threats. Single-session analysis can catch obvious misuse, but fragmented attacks require visibility across multiple interactions. Private Safety Processing provides that visibility without requiring the company to keep records of those interactions after the agent has completed its analysis.
The Enforcement and Escalation Path
OpenAI has structured its escalation path to preserve customer choice and minimize data exposure. When agents identify a pattern, OpenAI decides whether to take action based on the signal they provide. Unless a customer volunteers additional data, OpenAI’s enforcement decision rests on what the agent can detect without any data retention. This positions agent-generated insights as sufficient for most decisions and treats data sharing as an option rather than a requirement.
The company says that if enforcement is necessary, it will work with the customer on the issue, but the customer retains control over whether to share more context. This approach inverts Anthropic’s model: it assumes that agent analysis is adequate for most purposes and human review is the exception rather than the rule.
Why This Matters for Enterprises
Enterprises that handle large volumes of sensitive data face competing pressures when selecting an AI provider. Data governance frameworks often minimize third-party access to sensitive information, which conflicts with Anthropic’s 30-day retention policy. OpenAI’s approach eliminates that conflict by removing the retention window altogether.
However, the tradeoff is real. By not storing data, OpenAI sacrifices the ability to conduct retrospective analysis or involve human experts in review of complex edge cases. Enterprises must decide whether data minimization outweighs the potential benefits of human oversight. The answer varies depending on industry, regulatory environment, and the sensitivity of the data at stake.
The Competitive Calculus
OpenAI’s timing reflects broader competitive pressure in the enterprise AI market. A recent report indicated that OpenAI’s Q2 revenue grew more slowly than Anthropic’s. Anthropic’s annualized revenue run rate now stands at $65 billion, and investors have valued the company as a potential IPO candidate at $2 trillion. OpenAI is also pursuing its own public listing.
In this environment, policy differences become competitive advantages. OpenAI’s Private Safety Processing announcement positions the company as the privacy-respecting alternative for enterprises that rejected Anthropic’s terms, while Anthropic continues to argue that its controlled access model offers better safety assurance than data minimization alone. The resolution of this standoff will likely depend on which tradeoff enterprises prioritize: data minimization or human oversight backed by audit trails.
Frequently Asked Questions
What is Private Safety Processing?
OpenAI's Private Safety Processing is an automated system that monitors customer interactions across multiple conversations to detect potential abuse, while retaining no customer data. It sends a "narrowly defined signal" to OpenAI if suspicious activity is detected.
How does Anthropic's approach differ?
Anthropic retains user sessions and conversations for 30 days on covered models like Mythos-class, allowing human reviewers to analyze data through a controlled access path recorded in a tamper-proof log. OpenAI's system stores nothing by design.
What are the revenue and business stakes between the two companies?
Anthropic's annualized revenue run rate stands at $65 billion, with investors valuing the company for a potential IPO at $2 trillion. OpenAI's Q2 revenue grew more slowly than Anthropic's, and OpenAI is also pursuing a public listing. OpenAI positioned its Private Safety Processing announcement as targeting enterprises that rejected Anthropic's data retention terms.