OpenAI、フロンティアモデルでゼロデータ保持オプションを提供開始
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
OpenAI News
OpenAI は、対象の API ユーザー向けにプロンプトや回答を処理後に保持しない「ゼロデータ保持」機能を導入し、顧客データの学習利用には明示的なオプトインが必要であると発表した。
AI深層分析を開く2026年8月20日 03:20
AI深層分析
キーポイント
ゼロデータ保持の確約と条件
OpenAI は、対象となる API ユーザーに対して、リクエスト処理後にプロンプトやモデル応答を保持しないことを約束し、顧客コンテンツが社員のレビューに供されないこと、および明示的なオプトインがない限り学習データとして使用されないことを明言する。
複数回やり取りにおけるリスク検知の課題
単一のインタラクションでは見えない危険な意図や、エージェントタスク中のアライメント崩れなどのリスクは、複数のやり取りを横断して初めて顕在化するため、既存の個別評価システムでは不十分であると指摘する。
Private Safety Processing の仕組み
顧客が制御するインフラ上、あるいは顧客が鍵を管理する暗号化された OpenAI インフラ上でコンテンツを保持しつつ、自動化されたシステムがパターンを検知して安全信号を返すことで、OpenAI 社員に機密内容を晒さずにリスクを特定する仕組みを提案する。
セキュリティ要件との整合性確保
一部の Frontier モデル導入において、セキュリティ監視のためにプロバイダーが機密コンテンツの保持を要求することが、顧客のセキュリティ義務やコミットメントと矛盾する場合があるため、この新機能はその課題を解決する手段として位置付ける。
顧客制御鍵による暗号化とアクセス制限
OpenAI が提供するストレージでも顧客が管理する鍵で暗号化され、OpenAI の従業員はコンテンツにアクセスできない。リスク検知時も顧客データではなく活動タイプを示す狭義のシグナルのみが開示される。
重要な引用
Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed.
Private Safety Processing builds on the automated protections already used in ZDR and other deployments.
The most serious AI safety risks are not always visible in a single interaction.
"Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service."
編集コメントを表示
編集コメント
データ保持を完全に排除しつつ、高度な安全性監視を両立させる試みは、企業向け AI サービスの信頼性を高める上で決定的な一歩となる。特に暗号鍵管理権限を顧客に委譲するオプションは、セキュリティ意識の高い組織にとって導入の障壁を下げる重要な要素である。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
ゼロデータ保持(Zero Data Retention)は、対象となる API 利用者に対して明確な約束を示します。OpenAI は、リクエスト処理後にプロンプトやモデルの応答を保持しないというものです。顧客のコンテンツは OpenAI の担当者によるレビューの対象とはならず1、企業が明示的にオプトインしない限り、そのデータがモデル学習に使用されることもありません。
モデルがより長く複雑なタスクを引き受けるにつれ、重大なリスクの一部は単一のやり取りでは見えず、複数のやり取りを跨いで初めて顕在化することがあります。既存の ZDR 対応セキュリティシステムは、それぞれのやり取りを個別に評価する仕組みです。そこで今回、OpenAI の担当者が基盤となるコンテンツにアクセスすることなく、関連するやり取り全体からパターンを特定するために設計された「プライベートセーフティプロセッシング」のプレビューを発表します。
ZDR 環境では、顧客のコンテンツは顧客が管理するインフラ上に留まります。また、OpenAI のインフラ上にデータを保存しつつも、鍵を顧客が管理する暗号化方式を採用したオプションも開発中です。いずれの場合も、自動化されたシステムが潜在的な悪用を検知し、基盤となるプロンプトや応答を OpenAI 担当者に露出させることなく、限定的なセキュリティシグナルを返すことができます。
なぜセキュリティシステムは進化が必要なのか
最も深刻な AI セーフティリスクは、必ずしも単一のやり取りの中で顕在化するわけではありません。有害な意図が明確になるのは、複数のやり取りをまとめて分析した時であることがほとんどです。同様のリスクは、悪意のあるアクターが安全対策を繰り返し試したり、複数アカウントで連携したり、脅威を通常の研究活動に偽装したりする際にも発生します。また、エージェント型タスクの進行中にリスクが発生することもあります。例えば、ユーザーから停止指示が出たにもかかわらずシステムが行動を続けてしまい、ユーザーの意図と乖離してしまうケースなどが該当します。
AI システムがより長く複雑なタスクを引き受けるようになると、正当な活動と悪用を見分けるため、また AI エージェントが意図された権限の範囲内に留まるようにするためには、この広範な文脈を把握することがますます重要になります。
最近のフロンティアモデルの導入事例では、顧客に安全監視のために機密コンテンツをプロバイダーが保持することを許可するよう求めるケースがありました。多くの組織にとって、こうした要件はセキュリティ上の義務や、サービスを提供する人々へのコミットメントと矛盾します。
「プライベート・セーフティ・プロセッシング」は、ZDR(ゼロ・データ・リテンション)を継続して提供できるように設計されています。
プライベート・セーフティ・プロセッシングの仕組み
プライベート・セーフティ・プロセッシングは、ZDR や他の導入事例で既に採用されている自動保護機能を基盤としています。既存の ZDR 互換性を持つ安全システムは、個々のやり取りを個別に評価します。一方、プライベート・セーフティ・プロセッシングはこの保護を関連するやり取り全体に拡張し、OpenAI の担当者が顧客コンテンツにアクセスすることなく、自動システムがパターンを特定できるようにします。
Private Safety Processing は、顧客が管理するインフラ(ZDR デプロイメント)に保存されている場合でも、OpenAI が提供するストレージに保存されている場合でも、顧客のコンテンツを処理対象とします。OpenAI 提供のストレージを利用する場合、顧客自身が制御する鍵を用いてコンテンツは暗号化されます。OpenAI の従業員はその鍵のコピーを持っていないため、暗号化されたコンテンツそのものにアクセスすることはできません。
リスクが検出された場合、OpenAI は既存の安全システムと同様に、関与している活動の種類を示す限定されたシグナルを受け取ります。このシグナルは、是正措置が必要かどうかを判断するために利用されます。ただし、コンテンツがフラグ付けされた場合でも、OpenAI の従業員が顧客のコンテンツにアクセスできることはありません。
顧客は、自社のシステムで入手可能な情報を用いてアラートや是正措置の決定を検証できます。異議申し立てを行う場合、正当な活動の明確化が必要な場合、または確認された不正行為に関する調査を支援したい場合は、関連情報を OpenAI と共有することを選択できます。
Private Safety Processing は現在、初期顧客とのテスト段階にあります。このプレビューを公開する理由は、AI システムがより高度化する中で、コンテンツがどのように保護されるかについて顧客から明確な予測可能性が必要であるという声を強く受け止めたからです。
顧客と共に、そして顧客のために構築されたプライバシーと安全性
私どものミッションは、汎用人工知能(AGI)が人類全体に利益をもたらすことを保証することです。効果的なセーフガードを構築するためには、顧客やパートナーとの協力が不可欠です。私たちの原則で明らかなように、どの AI ラボも新興リスクを単独で対処することはできません。
「Private Safety Processing」はこうしたアプローチを反映したものであり、業界・地域・企業規模を超えた顧客たちのフィードバックによって形作られています。
私たちが連携する組織は、財務記録や健康データ、機密性の高い事業計画、独自研究など、各分野で最もセンシティブな情報を取り扱っています。こうした情報の保護は、規制要件への対応、顧客からの信頼維持、競争優位性の確保のために不可欠です。
これらのフィードバックは、私どもがより強固なセーフガードを構築する一方で、情報が常に顧客の管理下にあることを支えるものとなっています。
「エンタープライズ AI の普及は、顧客によるデータの完全なコントロールに依存しています。選択したサービス以外で直接的・派生的な利用が行われないことが条件です。OpenAI の学習不使用コミットメントと ZDR(ゼロデータ保持)により、Glean は OpenAI を活用して構築することに確信を持っています。モデルの能力が向上するにつれ、OpenAI はプライバシーとコントロールを損なうことなく安全性を進化させることができることを示しています。」
—Sunil Agrawal 氏、Glean チーフインフォメーションセキュリティオフィサー
当社は、顧客と共にアプローチの技術的・運用上の詳細について引き続き協議してまいります。9 月には「プライベートセーフティプロセッシング」の展開を開始し、技術白書も公開する予定です。顧客には各段階で随時情報を共有し、早期にアップデートをお伝えするとともに、既存のコミットメントへの影響を説明し、先を見据えた計画に必要な時間とサポートを提供してまいります。
原文を表示
Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review1, and enterprise customer data is not used to train our models unless customers explicitly opt-in.
As models take on longer, more complex tasks, some serious risks may only become visible across multiple interactions. Existing ZDR-compatible safety systems evaluate each interaction individually. Today, we’re previewing Private Safety Processing, which is designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.
For ZDR deployments, customer content remains on infrastructure the customer controls. We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel.
Why safety systems need to evolve
The most serious AI safety risks are not always visible in a single interaction. Often, potentially harmful intentions become clear only when multiple interactions are viewed together. Similar risks can arise when bad actors repeatedly probe safeguards, coordinate across accounts, or disguise threats as routine research. Risks can also develop over the course of an agentic task—for example, if a system becomes misaligned with the user’s intent by continuing to act after being told to stop.
As AI systems take on longer and more complex tasks, this broader context becomes increasingly important for distinguishing legitimate activity from misuse and ensuring that AI agents remain within the bounds of their intended authority.
Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve.
Private Safety Processing is designed so we can continue to offer ZDR.
How Private Safety Processing works
Private Safety Processing builds on the automated protections already used in ZDR and other deployments. Existing ZDR-compatible safety systems evaluate interactions individually. Private Safety Processing extends those protections across related interactions, allowing automated systems to identify patterns without OpenAI personnel having access to retained customer content.
Private Safety Processing utilizes customer content regardless of where it is stored—whether in infrastructure customers control (ZDR deployments) or in storage provided by OpenAI. With OpenAI-provided storage, customer content is encrypted using keys controlled by the customer. OpenAI personnel do not have a copy of those keys, so they cannot access the underlying content.
When a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity involved, similar to our existing safety systems today. That signal can be used to determine whether enforcement is necessary. OpenAI personnel do not receive access to the customer content even when it is flagged.
Customers can investigate alerts and enforcement decisions using information available in their own systems. If they want to appeal, clarify legitimate activity, or support an investigation into verified abuse, they can choose to share relevant information with OpenAI.
Private Safety Processing is currently being tested with early customers. We are sharing this preview now because we’ve heard our customers loud and clear that they need predictability about how their content will be protected as AI systems become more capable.
Privacy and safety built with and for our customers
Our mission is to ensure that artificial general intelligence benefits all of humanity. Collaboration with customers and partners is essential to how we build effective safeguards. As our principles make clear, no AI lab can address emerging risks alone. Private Safety Processing reflects that approach and is being shaped by customers across industries, regions, and company sizes.
The organizations we work with handle some of the most sensitive information in their sectors, including financial records, health data, confidential business plans, and proprietary research. Protecting that information is essential to meeting regulatory obligations, maintaining customer trust, and preserving their competitive advantage.
Their feedback is helping us build stronger safeguards while keeping their information under their control.
“Enterprise AI adoption depends solely on customer control of data, with no direct or derivative use beyond the chosen service. OpenAI’s no-training commitment and ZDR give Glean confidence to build with OpenAI. As models become more capable, OpenAI shows safety can advance without compromising the privacy and control that sustain enterprise trust.”
—Sunil Agrawal, Chief Information Security Officer, Glean
We will continue working with customers on the technical and operational details of our approach. We plan to start rolling out Private Safety Processing, and share a technical white paper, in September. We’ll keep customers informed every step of the way, sharing updates early, explaining what they mean for existing commitments, and providing the time and support customers need to plan ahead.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み