← All tool briefs

Tool brief · August 24, 2026

OpenAI's Zero Data Retention for Frontier Models: what it actually changes for legal teams

LegalFor Legal

The tool

OpenAI Zero Data Retention for Frontier Models

Visit OpenAI Zero Data Retention for Frontier Models

What it is

Zero Data Retention (ZDR) is a deployment mode on OpenAI's API — not a separate product — where OpenAI does not retain the customer's prompts or model responses after a request is processed. In OpenAI's own framing, customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train its models unless customers explicitly opt-in. Alongside it, OpenAI previewed Private Safety Processing, a safety architecture designed to detect multi-session misuse without exposing the underlying prompts or responses to OpenAI personnel.

The next-work-session test

Concrete scenario: a corporate M&A team asks you to run frontier-model redline comparisons on a draft SPA that includes named counterparties, deal values, and reps and warranties still under negotiation. Today, most legal teams either (a) redact the doc first, which kills the model's ability to reason about indemnity carve-outs, or (b) route it through a vetted vendor with a signed DPA and pray about retention windows.

Under ZDR, the answer to "does this create a second copy of privileged material inside a third-party vendor's systems?" becomes closer to no — the inference payload isn't stored server-side after the response. That is the specific fact you need to defend when general counsel asks whether the tool touched work-product-protected drafts. It does not change whether privilege attaches; it changes the retention exposure you have to disclose.

Pricing

No separate price was announced. One analyst site was blunt: the announcement concerns data and safety policy, not pricing, and no price change was mentioned in the official post. Eligibility criteria are also not public yet — OpenAI didn't say what constitutes eligibility for the zero data retention program, only that it would start in September, when the company would share details in a technical white paper. Pricing: effectively unverified as a line item. Assume it is bundled into enterprise API contracts and negotiated per-account, and get the eligibility criteria in writing before you rely on it.

What we'd actually use it for

Narrower than the vendor pitch. Realistic uses in a legal shop:

  • Redlining and clause-comparison on drafts that contain client-identifying facts.
  • Summarizing deposition transcripts and privileged internal memos without creating a durable third-party copy.
  • Running due diligence Q&A over a data-room export where the retention window on the vendor side is a live issue with the client.

Not what we'd use it for: anything where you need audit logs of the model's inputs and outputs for later defensibility — because by design, there aren't any on OpenAI's side.

Limits

  • Eligibility is undefined publicly. Until the September white paper lands, "eligible API customers" is a phrase, not a checklist.
  • Reseller channels break the promise. If you consume OpenAI via Microsoft, AWS, or an app vendor, you are likely not the direct customer. As one analyst put it in CSO Online's coverage of the announcement, if you use a tool that uses OpenAI via API to build an app, Amazon or the vendor is the customer and you are their customer; if you want zero data retention protection you must provide your own API key. For law firms using an off-the-shelf legal AI product built on OpenAI, this is the single most important sentence in the announcement.
  • CSAM exception is carved out. Images flagged for potential CSAM will continue to be retained for manual review and reporting purposes, even in Zero Data Retention deployments. Not usually relevant to legal work, but note that "zero" has a defined exception.
  • ZDR ≠ no processing in memory. While ZDR addresses durable provider-side storage of the inference payload, that still allows transient in-memory processing, automated abuse screening, customer-configured persistence, or legally compelled retention. Read the promise as contractual and technical, not metaphysical.
  • Private Safety Processing is a preview, not a shipped guarantee. Treat it as a roadmap item when advising your client, not a control you can rely on today.
  • It doesn't answer the privilege question. Whether sending a privileged communication to a third-party API waives privilege is a jurisdiction-specific legal question. ZDR reduces one risk (durable storage) but does not resolve waiver analysis.

Try it if

  • You're in-house or at a firm negotiating an enterprise OpenAI contract directly, and you can get ZDR written into the order form with defined eligibility.
  • Your compliance team's blocker on frontier models has been the retention window, not the training-data question.
  • You want to reduce the volume of redaction work upstream of AI-assisted review.

Skip it if

  • You access OpenAI through a legal-tech vendor or hyperscaler reseller and can't route via your own API key — the ZDR promise doesn't automatically flow to you.
  • Your matter requires the vendor to preserve inputs and outputs for later audit or litigation hold — ZDR is the opposite of what you want.
  • You need a decision this week. The eligibility rules and the Private Safety Processing details are, per OpenAI's own statement, coming in a September technical white paper. Wait for the paper, then paper the contract.

---

This content is for informational purposes only and is not legal advice. Confirm confidentiality, privilege, and jurisdictional rules before using any AI tool with client matters.

Source: openai.com

More for Legal professionals →

Get the next one in your inbox

One daily brief. Every story gets a hype verdict.

No spam. Unsubscribe anytime.

No sponsored verdicts · We have no paid relationship with featured vendors