OpenAI、フロンティアモデルでゼロデータ保持オプションを提供開始
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
OpenAI News
OpenAI は Frontier モデル向けにゼロデータ保持(ZDR)を維持しつつ、複数回の対話パターンを検知する「プライベートセーフティ処理」のプレビューを発表し、顧客データの暗号化制御や安全監視の両立を図る。
AI深層分析を開く2026年8月20日 05:17
AI深層分析
キーポイント
ゼロデータ保持の確約と新機能発表
OpenAI は API カスタマーに対し、リクエスト処理後にプロンプトやレスポンスを保持しないことを約束し、モデル学習への利用には明示的なオプトインが必要であると明言した。
プライベートセーフティ処理の仕組み
単発の対話評価を超え、関連する複数回のやり取りから有害なパターンを自動システムが検知する新機能を導入し、OpenAI 社員がコンテンツにアクセスすることなく安全監視を可能にする。
データ保存と暗号化の選択肢
顧客制御インフラでの保存に加え、OpenAI インフラ上に保存する場合でも顧客が管理する鍵で暗号化するオプションを開発中であり、安全信号のみを返却してコンテンツを露出させない。
安全性システムの進化の必要性
複雑なタスクやエージェント型 AI において、単一の対話では見えないリスクが複数回のやり取りを通じて顕在化するため、文脈を考慮した安全監視の強化が不可欠であると説明している。
顧客制御鍵による暗号化とアクセス制限
OpenAIが提供するストレージにおいても顧客コンテンツは顧客が管理する鍵で暗号化され、社員のアクセスは不可能である。リスク検知時にも社員は通知信号のみを受け取り、コンテンツ自体にはアクセスできない。
重要な引用
Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed.
Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without giving OpenAI personnel access to the underlying content.
For ZDR deployments, customer content remains on infrastructure the customer controls.
"Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service."
編集コメントを表示
編集コメント
顧客のデータ主権と AI の安全性を両立させるための技術的アプローチが示された。特に、複数回の対話履歴からリスクを検知する仕組みは、実務的な導入障壁を下げる重要な一歩となる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
ゼロデータ保持(Zero Data Retention)は、対象となる API 顧客に対して明確な約束を提示します。OpenAI は、リクエスト処理が完了した後にプロンプトやモデルの応答データを保持しないという方針です。顧客のコンテンツは、OpenAI の担当者がレビューするために利用されることはありません1。また、エンタープライズ顧客のデータも、顧客が明示的にオプトインしない限り、モデルの学習には使用されません。
モデルがより長く複雑なタスクを担うにつれ、重大なリスクは単一のやり取りでは見えず、複数のやり取りにわたって初めて顕在化することがあります。既存の ZDR 対応セーフティシステムは、それぞれのやり取りを個別に評価する仕組みです。そこで今回、関連するやり取り全体のパターンを検出しながらも、OpenAI の担当者が基盤となるコンテンツにアクセスできないように設計された「プライベート・セーフティ・プロセッシング(Private Safety Processing)」のプレビューを開始します。
ZDR 環境では、顧客のコンテンツは顧客が管理するインフラ上に留まります。また、OpenAI が管理するインフラ上にデータを保存し、暗号化キーを顧客が制御するオプションも開発中です。いずれの場合も、自動化されたシステムが潜在的な悪用を検出し、基盤となるプロンプトや応答を OpenAI の担当者に開示することなく、限定的なセーフティ信号を返すことが可能になります。
なぜセーフティシステムの進化が必要なのか
最も深刻な AI セーフティリスクは、必ずしも単一の対話から見えるわけではありません。有害な意図が明確になるのは、複数の対話をまとめて見た場合であることがほとんどです。同様のリスクは、悪意のある行為者がセーフガードを繰り返し試したり、複数アカウント間で連携したり、脅威を通常の研究活動に偽装したりする際にも発生します。また、エージェント型タスクの進行中にリスクが蓄積することもあります。例えば、停止を指示されたにもかかわらず行動し続けることで、システムがユーザーの意図から逸れてしまうケースなどが該当します。
AI システムがより長く複雑なタスクを引き受けるようになると、正当な活動と悪用を見分けるため、また AI エージェントが意図された権限の範囲内に留まるようにするために、こうした広範な文脈がますます重要になります。
最近のフロンティアモデルの導入事例では、顧客にセーフティモニタリングのために機密コンテンツをプロバイダーが保持することを許可するよう求めるケースがありました。多くの組織にとって、このような要件はセキュリティ上の義務や、サービスを提供する人々へのコミットメントと矛盾します。
「プライベート・セーフティ・プロセッシング」は、ZDR(ゼロ・データ・リテンション)を継続して提供できるように設計されています。
プライベート・セーフティ・プロセッシングの仕組み
プライベート・セーフティ・プロセッシングは、ZDR や他の導入事例で既に使用されている自動保護機能を基盤としています。既存の ZDR 互換セーフティシステムは対話を個別に評価しますが、プライベート・セーフティ・プロセッシングはこの保護を関連する対話全体に拡張します。これにより、自動化されたシステムがパターンを特定できるようになりますが、OpenAI の担当者が顧客の保持コンテンツにアクセスすることはできません。
Private Safety Processing(プライベート・セーフティ・プロセッシング)は、顧客のコンテンツがどこに保存されていても、その処理を行います。インフラを顧客自身が管理する ZDR 環境での展開であっても、OpenAI が提供するストレージ上にあっても同様です。
OpenAI が提供するストレージを利用する場合、顧客のコンテンツは顧客が管理する鍵を用いて暗号化されます。OpenAI の従業員はその鍵のコピーを持っていないため、暗号化されたコンテンツそのものにアクセスすることはできません。
リスクが検出された際、OpenAI は既存の安全システムと同様に、関与している活動の種類を示す限定的なシグナルを受け取ります。このシグナルは、是正措置が必要かどうかを判断するために利用されます。ただし、顧客のコンテンツがフラグ付けされた場合でも、OpenAI の従業員がそのコンテンツにアクセスすることはできません。
顧客は、自社のシステムで入手可能な情報を用いてアラートや是正決定の調査を行うことができます。もし異議申し立てを行いたい場合、正当な活動の説明を加えたい場合、あるいは確認された不正行為に関する調査を支援したい場合は、関連情報を OpenAI と共有することを選択できます。
Private Safety Processing は現在、初期顧客とのテスト段階にあります。このプレビューを公開する理由は、AI システムの能力が高まるにつれ、コンテンツがどのように保護されるかについて顧客から明確な予測可能性が必要であるという声が強く寄せられているからです。
顧客と共に、そして顧客のために構築されたプライバシーと安全性
私たちが目指すのは、汎用人工知能が人類全体に利益をもたらすことです。効果的なセーフガードを構築するには、顧客やパートナーとの協力が不可欠です。
私たちの原則にも明記されている通り、どの AI ラボも新興リスクを単独で解決することはできません。「プライベート・セーフティ・プロセッシング」はこうした考え方を反映したものであり、業界や地域、企業規模を超えた多様な顧客のフィードバックによって形作られています。
私たちが連携する組織は、金融記録、健康データ、機密性の高い事業計画、独自研究など、各分野で最も機微な情報を扱っています。こうした情報の保護は、規制要件への対応や顧客からの信頼維持、競争優位性の確保に不可欠です。
顧客からのフィードバックは、情報を完全に顧客が管理したまま、より強固なセーフガードを構築する上で重要な役割を果たしています。
「エンタープライズ AI の普及は、データに対する顧客の完全なコントロールにかかっています。選択されたサービス以外で直接または派生的に利用されることはなく、OpenAI の学習不使用の約束と ZDR(ゼロ・データ・リテンション)が、Glean に OpenAI を活用して構築する自信を与えています。モデルの能力が高まるにつれ、OpenAI はプライバシーや制御を損なうことなく、安全性も向上できることを示しています。」
—Sunil Agrawal 氏、Glean 最高情報セキュリティ責任者
当社は、顧客の皆様と引き続き技術的・運用的な詳細について協議を続けてまいります。9 月には「プライベートセーフティプロセッシング」の展開を開始し、技術白書も公開する予定です。今後の進捗については随時ご連絡を差し上げます。既存の契約への影響についても早期に共有し、その意味を明確に説明するとともに、顧客の皆様が事前に計画を立てるために必要な時間とサポートを提供してまいります。
原文を表示
Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review1, and enterprise customer data is not used to train our models unless customers explicitly opt-in.
As models take on longer, more complex tasks, some serious risks may only become visible across multiple interactions. Existing ZDR-compatible safety systems evaluate each interaction individually. Today, we’re previewing Private Safety Processing, which is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.
For ZDR deployments, customer content remains on infrastructure the customer controls. We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel.
Why safety systems need to evolve
The most serious AI safety risks are not always visible in a single interaction. Often, potentially harmful intentions become clear only when multiple interactions are viewed together. Similar risks can arise when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Risks can also develop over the course of an agentic task—for example, if a system becomes misaligned with the user’s intent by continuing to act after being told to stop.
As AI systems take on longer and more complex tasks, this broader context becomes increasingly important for distinguishing legitimate activity from misuse and ensuring that AI agents remain within the bounds of their intended authority.
Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve.
Private Safety Processing is designed so we can continue to offer ZDR.
How Private Safety Processing works
Private Safety Processing builds on the automated protections already used in ZDR and other deployments. Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content.
Private Safety Processing utilizes customer content regardless of where it is stored—whether in infrastructure customers control (ZDR deployments) or in storage provided by OpenAI. With OpenAI-provided storage, customer content is encrypted using keys controlled by the customer. OpenAI personnel do not have a copy of those keys, so they cannot access the underlying content.
When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved, similar to our existing safety systems today. That signal can be used to determine whether enforcement is necessary. OpenAI personnel do not receive access to the customer content even when it is flagged.
Customers can investigate alerts and enforcement decisions using information available in their own systems. If they want to appeal, clarify legitimate activity, or support an investigation into verified abuse, they can choose to share relevant information with OpenAI.
Private Safety Processing is currently being tested with early customers. We are sharing this preview now because we’ve heard our customers loud and clear that they need predictability about how their content will be protected as AI systems become more capable.
Privacy and safety built with and for our customers
Our mission is to ensure that artificial general intelligence benefits all of humanity. Collaboration with customers and partners is essential to how we build effective safeguards. As our principles make clear, no AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes.
The organizations we work with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans, and proprietary research. Protecting that information is essential to meeting regulatory obligations, maintaining customer trust, and preserving their competitive advantage.
Their feedback is helping us build stronger safeguards while keeping their information under their control.
“Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.”
—Sunil Agrawal, Chief Information Security Officer, Glean
We will continue working with customers on the technical and operational details of our approach. We plan to start rolling out Private Safety Processing, and share a technical white paper, in September. We’ll keep customers informed every step of the way, sharing updates early, explaining what they mean for existing commitments, and providing the time and support customers need to plan ahead.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み