OpenAI launches zero-retention privacy as Anthropic opts for 30-day data logs
OpenAI launched a zero data retention safety system for enterprises amid competition with Anthropic.
Why it matters: Privacy compliance is paramount for legal tech buyers using AI, making enterprise-grade data protections a key market edge.
- OpenAI introduced 'Private Safety Processing' to monitor AI misuse without retaining customer data.
- Anthropic enforces a 30-day data retention policy for its Fable 5 and Mythos 5 model users.
- OpenAI's system is tested with early enterprise and API customers, not yet for individual ChatGPT users.
- OpenAI holds ISO 27001:2022, ISO 27701:2019 certifications, and SOC 2 Type 2 compliance, supporting GDPR, CCPA, HIPAA, and FERPA.
OpenAI has unveiled its 'Private Safety Processing' system targeting enterprise customers. This system enables the company to detect misuse patterns in its AI models without retaining the underlying customer data, a notable advancement in privacy protection. The feature is presently in testing with early enterprise and API clients but has not been rolled out to individual ChatGPT subscribers yet. For details, visit Axios.
In contrast, Anthropic — a leading competitor in the AI legal tech market — has implemented a 30-day data retention policy for users of its Fable 5 and Mythos 5 models. This approach prioritizes security needs by retaining user data logs for a limited window. Anthropic characterizes this policy change as a pragmatic response to the absence of national or international regulatory frameworks, rather than succumbing to commercial pressures. More on this from Time.
OpenAI’s broader security infrastructure undergoes rigorous third-party reviews. Its API, ChatGPT Enterprise, ChatGPT Edu, and healthcare offerings have been audited to conform with industry standards for confidentiality and security. The company maintains key certifications including ISO/IEC 27001:2022 and ISO/IEC 27701:2019 for information security and privacy management, along with a SOC 2 Type 2 examination covering Security, Availability, Confidentiality, and Privacy controls.
OpenAI also supports compliance with major privacy laws, including GDPR, CCPA, HIPAA, and FERPA. They offer tailored contractual terms such as Data Processing Addenda and Business Associate Agreements to meet enterprise privacy requirements.
The competition between OpenAI's zero-retention safeguards and Anthropic's 30-day retention highlights diverging strategies among AI providers seeking to serve the highly regulated legal tech market. This rivalry unfolds against a backdrop of unclear AI governance and evolving safety commitments.
By the numbers:
- 30 days — Anthropic’s user data retention period for Fable 5 and Mythos 5 models
- ISO/IEC 27001:2022 and ISO/IEC 27701:2019 — OpenAI’s current information security and privacy certifications
- SOC 2 Type 2 — Independent audit status covering OpenAI’s API and ChatGPT business services
Yes, but: While OpenAI’s zero-retention system promises stronger data privacy, it is still under testing and not broadly available, unlike Anthropic's established 30-day data retention policy.
What's next: OpenAI plans to expand 'Private Safety Processing' availability to more enterprise customers soon; potential regulatory guidance on AI data privacy may emerge.