
For six straight months, "zdr" did exactly 880 searches a month in the US. Then in March 2026 it moved to 1,300, held there through May, jumped to 1,900 in June and 2,400 in July 2026. That is up 173% in a year, and our series stops before the thing you would expect to have caused it.
OpenAI published its zero data retention post on August 19, 2026. The demand had already doubled by then. Enterprise buyers were asking their AI vendors this question months before the vendors wrote it up, which is the pattern that makes ZDR worth understanding now rather than after the next procurement cycle.
Key takeaways:
- "zdr" grew from 880 to 2,400 US monthly searches in a year, up 173% and 85% in the last three months, classified as EXPONENTIAL in the Rising Trends database (data as of July 2026).
- The unambiguous long form, "zero data retention", is up 247% in the same period at 590 searches a month.
- OpenAI's definition: the provider "does not retain their prompts or model responses after a request is processed", staff cannot review the content, and enterprise data is not used for training without an explicit opt-in.
- There is an exception written into it. Images flagged as potential child sexual abuse material are still retained for review and reporting, because US law requires it.
- Anthropic's comparable Enterprise control is a retention floor, not zero: the minimum retention period is 30 days.
- SOC 2 compliance, at 9,900 searches a month, has not grown at all in a year. The static audit is flat while the live data questions are up triple digits.
Let's get into it.
What the curve shows
Here is "zdr" over the last two years. The interesting part is the flat stretch, not the climb.

Eighteen months between 590 and 880, then five months that nearly triple it. March 2026 is the first step, the same month Anthropic published its Enterprise retention controls. June and July are the sharp part, both before OpenAI's August post.
One honest caveat, because the number deserves it. ZDR is also the name of the planet in Nintendo's Metroid Dread, and our database tags the term with both Artificial Intelligence and Gaming, with HIGH seasonality. Some of those 2,400 searches are people looking for a video game. That is why the cleaner signal sits in the long form: "zero data retention" is up 247% year over year, with no ambiguity at all.
Put it next to the rest of the enterprise trust vocabulary and the picture sharpens.

SOC 2 compliance is still four times bigger than ZDR at 9,900 searches a month. It is the incumbent question, the one every enterprise buyer has asked for a decade. Now look at which of these are moving.

SOC 2 compliance: 0% growth in a year. Continuous compliance up 333%. Zero data retention up 247%. Even "ai privacy", the vague version of the question, is down 18%.
The checklist is not growing. The questions about what happens to your data in real time are. That is the whole shift in one chart.
What ZDR actually means
The clearest definition comes from the company that has the most to lose by writing it down.

From OpenAI's August 19, 2026 post: "Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train our models unless customers explicitly opt-in."
Three separate promises are bundled in there, and they are worth separating because vendors mix and match them:
| Promise | What it rules out |
|---|---|
| No retention | Your prompts and outputs are not stored after the request |
| No human review | Vendor staff cannot read your content |
| No training | Your content does not shape future models |
A vendor can offer the third without the first two, which is the most common arrangement and the reason the acronym matters. As OpenRouter's documentation puts it plainly, "we do have some endpoints and providers who do not train on your data but do retain it", for abuse scanning or legal reasons.
There is also a limit that is written into OpenAI's own footnote. Images flagged as potential child sexual abuse material are retained for manual review and reporting, even in ZDR deployments, because US law requires that reporting. Zero is not literally zero, and the honest vendors say so.
Why it broke out now
Because agents made the old safety architecture and the old privacy promise incompatible.
OpenAI is unusually direct about the bind. Its post says the most serious risks "are not always visible in a single interaction", and that judging behaviour across many interactions requires seeing them together. Then it concedes the consequence: "Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations."
That is a vendor admitting that its safety systems and its enterprise contracts were pulling in opposite directions. The answer it previewed is Private Safety Processing, which is designed to spot patterns across related interactions "without giving OpenAI personnel access to the underlying content". For ZDR deployments, content stays on infrastructure the customer controls, with an encrypted-on-OpenAI-infrastructure option in development. Rollout and a technical white paper were promised for September 2026.
The customers listed as shaping it are the tell: Glean, Databricks, Abridge and Microsoft. Search, data platforms, medical scribing, and the company selling the same models through Azure.
Here is the comparison buyers are actually running, published three weeks ago.
Note the framing. Not "is AI safe" but "whose retention policy is better". That is a procurement question, and it is what a 173% search increase on an acronym looks like from the inside.
Who offers what
The three approaches in the market right now are genuinely different, and the differences are checkable.
OpenAI offers ZDR to eligible API customers, with the definition above and the CSAM exception. The new part is safety monitoring that works without staff access to content.
Anthropic takes a different shape for its Enterprise plans. Its custom data retention controls, documented on March 16, 2026, let an organisation set how long conversation and project data is kept, measured from the last activity. The floor is explicit: "The minimum retention period is 30 days." That is a retention dial, not a zero.
OpenRouter, the routing layer, turns the policy into a setting. You can enforce ZDR globally, per model group, per guardrail, or per request, across five scopes. Enabling it for Anthropic removes first-party Anthropic endpoints while leaving Bedrock and Vertex available; the OpenAI scope removes first-party endpoints while Azure remains. The most useful line in its documentation is the default: where OpenRouter cannot establish a clear policy, it assumes the endpoint "both retains and trains on data".
Two practical warnings sit in that same page. A provider's general policy can differ from a specific endpoint's. And ZDR enforcement covers inference routing only, not the plugins and tools you switch on, such as web search, which have their own policies.
What it means for buyers
The compliance question changed shape. SOC 2 asks whether you had controls in place last year. ZDR asks what happens to this request, right now. That is why one is flat at 9,900 searches and the other is up 173%, and it is the same movement we track across cybersecurity trends: point-in-time assurance losing ground to continuous evidence.
Regulated industries are writing it into contracts. Health, finance and legal buyers cannot send content to a system that retains it, whatever the vendor's intentions. Abridge sitting on OpenAI's list of named customers is medical dictation, which is the sharpest version of the problem.
The alternative answer is hardware. If a vendor will not promise zero retention, the other way to guarantee it is to run the model yourself, which is the entire pitch behind local AI machines and the 143,700 monthly searches around them. ZDR and local inference are two answers to one question.
Read the endpoint, not the brand. The single most useful thing in OpenRouter's docs is that the same model from the same company can carry different policies depending on which cloud serves it. Procurement that names a vendor and not an endpoint has not actually bought anything.
What to watch next
Whether the curve keeps climbing after August. Our data ends at 2,400 for July 2026, before OpenAI's announcement. If August and September go higher, the post created a second wave on top of the demand that was already there. The live ZDR trend page is where that shows up, and the zero data retention term is the cleaner one to watch because no video game shares its name.
The Private Safety Processing white paper. OpenAI promised the technical details in September 2026. Whether independent reviewers accept that pattern detection can work without content access is the question that decides if ZDR survives the agent era intact.
Whether anyone matches the promise below enterprise pricing. Today ZDR is an enterprise API feature and a 30-day floor on the other side. The first provider to offer it by default, at self-serve prices, takes every regulated small buyer in the market.
The thing worth remembering is the sequence. Buyers doubled their searching for this before the largest vendor in the category published anything about it. When demand for a contractual term runs ahead of the vendors' own marketing, it is not a trend in the usual sense. It is a requirement arriving.
Want to catch enterprise requirements while they are still search curves? Read our guide on how to identify market trends, follow the live ZDR trend data, or browse what is breaking out right now on the Rising Trends dashboard.



