AI Briefing
KO

Zero Data Retention in AI Gateway

·2026.04.08 16:00

Key point

AI Gateway automatically enforces data policies with team-wide and per-request ZDR.

1 / 2

Details

Using multiple AI model providers together increases management burden because data policies differ across providers. Teams have to check each provider's terms individually, meet security requirements, and make sure developers don't forget to opt out on every request.

AI Gateway handles this negotiation and enforcement for you. It routes only to providers covered by Zero Data Retention (ZDR) agreements with OpenAI, Anthropic, Google, and others, so teams no longer need to run separate policies per provider.

The core of this update is team-wide ZDR. Turn it on once in the Dashboard settings, and from then on all requests use only ZDR-compliant providers, applying the same policy across the whole team with no code changes. This feature is available for Pro and Enterprise teams.

The controls that come with it are as follows.

  • per-request ZDR: apply ZDR on a per-request basis for sensitive workflows only
  • Disallow Prompt Training: block providers from using prompt data for training
  • audit metadata: leave a trace in the response of which providers were considered and which were filtered out

The team-wide setting and the per-request setting work together, and ZDR is enforced if either one is turned on. Since ZDR is a broader concept that also includes prompt training opt-out, enabling ZDR automatically satisfies the training block as well.

This policy works with AI SDK, Chat Completions API, Responses API, Anthropic Messages API, and OpenResponses API. As a result, data protection can be managed consistently at the gateway infrastructure level, instead of being handled through custom logic scattered across application code.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.