OpenAI adds data controls, narrows access in cyber program
OpenAI restated its zero data retention commitment for API customers and fixed a file-deletion bug in its Codex model. In the same period, the company shut some researchers out of its Daybreak Blue cybersecurity program.
Artificial Intelligence··Morning
Zero data retention for enterprise customers
OpenAI restated its zero data retention commitment for eligible API customers and introduced a service it calls Private Safety Processing. The company says misuse is watched by automated agents without retaining customer data, and conversations get no human review. When the signal fires, the customer decides whether to share data so the review can continue. Enterprises handling sensitive data are uneasy about the 30-day retention windows at other firms, though OpenAI did not say which customer tiers are covered.[1]
Codex file-deletion bug fixed
In Codex, OpenAI's coding agent, a command meant to clear temporary working files could wipe real user data. With the model misusing system variables, the delete targeted the actual home directory instead of the temporary folder. The Decoder says the problem showed up with GPT-5.6 Sol and that OpenAI has fixed it. The report rests on social media posts; it gives no figure for how many users were affected and no link to official release notes.[2]
Access narrows in cyber program
Some researchers lost access to the Daybreak Blue tier of OpenAI's vetted cybersecurity program. All five researchers TechCrunch spoke to live outside the US and Europe. Daybreak Blue, launched on August 10, is used for vulnerability discovery, secure code review, malware analysis and incident response. OpenAI called it a technical error on its own side, saying that a limited set of users' access is no longer active.[3]