News

OpenAI Pauses Scaling and Promises Zero Data Retention for Frontier Models

5 min read Editorial

OpenAI has unveiled a series of operational shifts designed to address mounting concerns regarding the security and privacy of its artificial intelligence systems. The announcements, released over Tuesday and Wednesday, include a temporary reduction in the pace of model scaling, a two-week halt on reinforcement learning training, and a new commitment to zero data retention for eligible API customers.

These moves come at a critical juncture for the company, which has faced increasing scrutiny over the safety implications of increasingly capable AI models. Industry analysts suggest the timing is strategic, potentially positioning OpenAI for an imminent initial public offering (IPO) by demonstrating a commitment to safety standards that investors and regulators increasingly demand.

A close-up photograph of a server rack in a data center, with blue LED lights blinking, symbolizing cloud computing and
Data centers like this handle the compute power behind AI models, raising questions about data retention and security.

#1 Temporary Scaling Slowdown

In its Tuesday announcement, OpenAI confirmed it has “temporarily” slowed the pace of its scaling efforts. This decision follows a period where the company reportedly hardened its research environment, conducted red-teaming exercises, and expanded its monitoring capabilities. The statement emphasized that the company’s largest planned frontier reinforcement learning (RL) run remains on hold.

Advertisement

During this pause, OpenAI intends to conduct smaller-scale training and evaluations. The goal is to assess model behavior, validate safeguards, and establish more robust evidence of alignment before proceeding with larger deployments. The company stated it will now require stronger evidence of aligned behavior throughout all stages of training, building on research and evaluations already underway.

OpenAI also highlighted other recent procedural improvements, including workload isolation, network isolation, and continuous security testing. However, the company noted that its newly proposed monitoring system will generate overhead costs of roughly 20% of the inference compute being monitored. These costs vary substantially across training and evaluation workloads. OpenAI promised to share more technical details about this monitoring system in a forthcoming blog post.

Analysts have weighed in on the rationale behind this decision. Carmi Levy, an independent technology analyst, described the statements as a “slickly conceived move to win PR points” as safety concerns around agentic AI continue to mount. He suggested that without explicit regulations forcing vendors to permanently prioritize safety, a two-week pause is “little more than window dressing designed to deflect criticism.”

A conceptual image of a handshake between two digital avatars, one representing a corporation and the other a user, with
Enterprise partnerships and direct customer relationships are key to understanding OpenAI's new data policies.

#2 Zero Data Retention Program

On Wednesday, OpenAI announced a new program offering zero data retention for “eligible API customers.” The announcement did not specify the criteria for eligibility, nor did it detail the technical implementation. However, it confirmed the program will launch in September, at which point the company will publish a technical white paper outlining the specifics.

Jason Andersen, principal analyst at Moor Insights & Strategy, noted that this move must be viewed in the context of OpenAI’s complex vendor relationships. Much of OpenAI’s revenue flows through partners like Microsoft and AWS. Andersen explained that if an enterprise uses a tool like Amazon Kiro, which can access OpenAI via API without the user’s knowledge, the enterprise is technically a customer of Amazon, not OpenAI.

To access the zero data retention protection, an enterprise would need to provide its own API key directly to the tool. This would make the enterprise a direct customer of OpenAI, granting “lockbox access” while AWS loses out on revenue and margins. This distinction highlights the potential friction between direct customer relationships and partner ecosystems.

Brian Levine, executive director of FormerGov, added that the data retention promise is complicated by existing legal processes. He noted that OpenAI claims it can monitor for abuse across interactions without staff ever reading the underlying content. While he called this a “strong technical promise,” he pointed out that “zero is never quite zero because CSAM-flagged content is still retained for legal reporting.”

#3 Industry Reaction and Skepticism

Reactions from the security and enterprise community have been mixed, with many experts urging caution. Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, suggested the moves might be a preemptive strike against potential legislation. He believes OpenAI is attempting to show a desire for self-regulation to avoid more “draconian legislation in the future.”

Mike Wilkes, enterprise CISO at Aikido Security, used the metaphor of “Pause the Kraken” to describe the situation. He observed that “sincerity is not the same thing as permanence” and questioned what conditions must be met before OpenAI decides to release the “kraken” again.

Justin St-Maurice, technical counselor at Info-Tech Research Group, argued that OpenAI seems to want credit for doing the bare minimum of what a major AI firm should have always done. He compared it to a carmaker announcing it would take basic safety testing more seriously before production, suggesting it would be “embarrassing that something so fundamental needed clarifying to a skeptical public.”

St-Maurice advised enterprises to “stop treating these announcements as diligence.” He urged customers to ask for evidence of what they are actually getting, rather than what they have been promised. He noted that if a vendor can pause development for security reasons, and the way you found out was through a blog post, you should be asking what your contract requires them to disclose to you.

What This Means for You

For enterprise users and developers relying on OpenAI’s API, these announcements signal a shift in how data is handled and how models are developed. The zero data retention program offers a potential solution for organizations with strict privacy requirements, but the lack of current details means you should prepare for a period of uncertainty. The temporary scaling pause may also impact the release timeline for new model capabilities, as OpenAI prioritizes safety validation over rapid deployment.

How to Get It

The zero data retention program is expected to launch in September. OpenAI will publish a technical white paper at that time, which should provide clarity on eligibility criteria and technical implementation. In the meantime, the temporary scaling slowdown is already in effect. Users can monitor the OpenAI blog for updates on the monitoring system and any changes to the scaling schedule.

Source: Computerworld

Over to you: Do you trust OpenAI’s temporary scaling pause and zero data retention promises, or do you see them as PR moves ahead of an IPO?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement