OpenAI Private Intelligence: a data decision for regulated teams

By Rogier Muller09.29.26
OpenAI Private Intelligence: a data decision for regulated teams

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.

OpenAI Private Intelligence gives regulated teams a documented way to use OpenAI API models with automated safety review and no OpenAI copy of the content. The current offer is Zero Data Retention with Private Safety Processing, described in OpenAI's PSP guide. It changes what OpenAI keeps, but your team still has to decide which agent traffic it covers and who runs the storage it depends on.

We wrote this for engineering leaders who need a yes or no from legal and security before developers point coding agents at sensitive repositories. It is a decision guide, not legal advice.

Who should look at Private Intelligence now?

Look at it if two things are true. Your developers want to send source code or customer data to OpenAI models through coding agents. And your current approval depends on how long the provider keeps that content and who can read it.

If your team only uses ChatGPT workspace sign-in, the relevant controls are your workspace retention and residency settings. PSP is an API project setting. It matters for API keys, agent pipelines, CI jobs and any tool that calls the OpenAI API with your organization's key.

Private Inference, the second half of the announcement, is a confidential computing preview due this fall. OpenAI has not published setup details for it yet. Do not plan a rollout around it until you can read the controls.

What the offer changes, and what stays with you

Concern What OpenAI documents for ZDR with PSP What your team still owns
Who can read retained content Decryption happens only in a hardware-attested runtime that disables human access Access rules on your own bucket and key service
Where retained content lives Encrypted records go to your S3, Azure Blob or Google Cloud Storage bucket Region choice, lifecycle rules, cloud audit logs
How long it is kept 30-day lifecycle on selected records Not deleting records earlier than 30 days
What leaves the review Only predefined safety signals and approved metadata in plaintext Deciding whether that metadata is acceptable to your DPO
Training use Stored content cannot be used to train models Confirming the same for every other tool in the chain
Scope The policy applies to all API traffic in the enabled project Keeping agent traffic in the right project

Two details deserve a direct conversation. First, not every request is retained: records are selected by a safety classifier referral or a sampling policy. Second, revoking your customer-managed key stops decryption but does not delete records or undo processing that already ran.

Questions to take to legal and security

Put these to your data protection, security and procurement leads before anyone enables the setting.

  1. Is our organization already approved for zero data retention on the OpenAI API? If not, who opens the conversation with OpenAI sales, since approval is not self-serve?
  2. Does a 30-day encrypted copy in our own bucket meet our retention rules, or does it create a new record we must classify?
  3. Which region must the bucket sit in to match the project's data residency?
  4. Will we enable Enterprise Key Management, and who holds authority to revoke the key?
  5. Is the plaintext safety signal and operational metadata acceptable under our data processing terms?
  6. Who responds when OpenAI sends a notice about a safety concern or a storage fault, and how fast?
  7. Which agent tools send our code through an API key, and which through a workspace sign-in?

The last question is where most rollouts slip. Coding agents often support more than one way to authenticate. For Codex, the authentication docs state that the sign-in method decides which admin controls and data policies apply. Check the matching setting in Claude Code, Cursor or any other tool you allow, and name the approved path for each in your policy.

Which agent traffic does the policy actually cover?

Draw the path for every tool your developers use. A laptop session, a CI job and a cloud agent can each authenticate differently. A PSP project protects only the requests made with keys from that project.

A clean pattern is one API project for coding agent traffic on regulated repositories, with ZDR and PSP enabled, and keys issued only from it. Experiments that do not need PSP go to a separate project, because the policy applies to everything in the enabled one. Revoke personal keys that point at other projects for those repositories.

Then check the stateful features your teams use. OpenAI lists endpoints that keep state until deleted, such as Assistants, Threads, Vector Stores and Conversations, as not eligible for ZDR. A workflow built on them needs a different design.

Rollout checklist

  • ZDR approval confirmed for the OpenAI organization
  • One named owner for the PSP bucket and one for the key service
  • Bucket created in the approved region, public access blocked
  • Lifecycle rule set to 30 days, with no earlier deletion rule
  • Storage registered and validated by an organization administrator
  • Project policy reads Zero Data Retention with Private Safety Processing
  • Every agent tool mapped to its sign-in path and project
  • Revalidation owner and schedule agreed, since a validated status is a one-time check
  • Incident contact agreed for OpenAI safety or storage notices
  • Repository rules updated so agents never receive secrets in prompts

What to measure in the first month

Measure whether the control holds, not whether people like the tool. Track the share of agent requests on regulated repositories that come from the PSP project. The target is all of them, and anything else is a finding.

Check cloud access logs on the bucket each week and separate validation probes from real PSP activity. Count storage or configuration notices and the time it took to fix each one. OpenAI notes that a missing object alone does not mean storage failed, because the sampling policy decides what is written.

Keep delivery metrics too. Our guide to measuring an AI workflow before scaling covers review effort and rework, so a privacy win does not hide a delivery cost. For the review side of the same rollout, the Delegate, Review, Own methodology gives reviewers one standard for agent changes.

Take the seven questions above to your data protection lead this week, and use our AI training for teams if you want to run the pilot on your own repositories.

Further reading