AI agents · OpenClaw · self-hosting · automation

Quick Answer

OpenAI ZDR vs Anthropic Logging: Enterprise AI Data

Published:

The Short Answer

As of August 2026 the frontier vendors no longer agree on a basic question: does safety monitoring require keeping your prompts?

Position as of August 21, 2026
OpenAIZDR maintained for eligible API customers; Private Safety Processing previewed August 19, 2026 to detect cross-interaction misuse without staff access to content
AnthropicReported to require data logging for certain recent frontier deployments — retention as a condition of access
GoogleEnterprise terms with no-training defaults; regional endpoints carry roughly a 10% premium

This is now a procurement variable, not a footnote. For a regulated buyer it can outrank benchmark performance entirely.

The Underlying Tension

Both positions come from the same true observation: single-interaction safety checks miss the attacks that matter.

The dangerous patterns are sequential — an actor probing safeguards across dozens of individually harmless requests, a campaign split across accounts so no single one looks unusual, a threat framed as routine research, or a long-running agent that drifts out of alignment and keeps acting after being told to stop. Score each request in isolation and every one of those passes.

The disagreement is about the fix.

The retention answer: keep the content, let automated systems (and where necessary, humans) look across it. Straightforward, effective, and unacceptable to a large class of buyers.

The OpenAI answer: extend automated pattern detection across related interactions while the content stays either on infrastructure the customer controls or on OpenAI infrastructure encrypted with customer-held keys, returning only limited safety signals. No OpenAI personnel access to underlying prompts.

What OpenAI Is Actually Promising

Zero Data Retention, for eligible API customers, means three distinct things:

  1. Prompts and model responses are not retained after the request is processed.
  2. Customer content is not available to OpenAI personnel for review.
  3. Enterprise customer data is not used for training unless explicitly opted in.

Private Safety Processing, previewed August 19, 2026, is the mechanism that lets OpenAI keep offering (1) and (2) as models take on longer agentic tasks. Automated systems identify patterns across related interactions and surface only that a risk was detected — not the content that produced it.

The caveat that matters: this is a preview with select customers, not a GA contractual guarantee. Do not put it in an audit narrative yet.

What To Verify Before You Sign

Vendor marketing collapses distinctions that your auditor will not. Check all six:

  1. Eligibility scope. Which of your workloads qualify for zero-retention terms? “We use OpenAI” ≠ “we have ZDR.”
  2. Retention vs training. Nearly every vendor promises not to train on enterprise API data. Far fewer promise not to keep it. These are different guarantees with different failure modes.
  3. Physical location. Does content sit on your infrastructure, the vendor’s, or a cloud reseller’s? Bedrock and Google Cloud regional endpoints change the answer — and carry roughly a 10% premium on token rates.
  4. Key custody. If content is encrypted at the vendor, who holds the keys? OpenAI’s customer-controlled-key option is described as in development as of August 2026.
  5. Exception paths. Under what circumstances can a human at the vendor read content? Abuse investigation clauses frequently reopen a door the headline promise appeared to close.
  6. Contract status. Preview, beta, roadmap or executed DPA. Only the last one survives contact with a regulator.

How to Choose

If you are in healthcare, finance, defence or legal: data terms are your first filter and capability is your second. A vendor requiring retention is simply out of scope regardless of how it benchmarks. OpenAI’s ZDR path is currently the most explicit public commitment — verify eligibility for your specific workloads and treat Private Safety Processing as promising rather than banked.

If you are a normal SaaS company: you probably do not need ZDR, and demanding it will cost you pricing leverage and model access. Default no-training terms plus a sane retention window is a reasonable posture. Spend your negotiating capital on rate limits and committed-use discounts instead.

If you are building agents that touch production: weight the agentic drift problem heavily. The risk that a long-running agent keeps acting after a stop instruction is not hypothetical, and it is exactly the failure that per-prompt monitoring cannot see. Whichever vendor you pick, build your own kill switch and your own audit log rather than inheriting theirs.

The Read

The industry spent 2025 and early 2026 drifting toward you must let us watch to use the good models. That drift was quietly locking regulated buyers out of frontier capability.

OpenAI’s August 19 announcement is a bet that the trade-off was never fundamental — that cross-session abuse detection can run on content no vendor employee can read. If it reaches GA with contractual weight, it resets the default for enterprise AI procurement and forces competitors to match.

If it stays in preview, it was excellent timing. Both readings remain live as of August 21, 2026, and serious buyers should plan for either.

Sources