Skip to content

Data, privacy, and security for Models sold by Azure changed Microsoft, Sep 17, 2024

Microsoft · Sep 17, 2024 · 30 added, 22 removed · found in an Internet Archive capture

  1. Added: This article provides details regarding how data provided by you to the Azure OpenAI service is processed, used, and stored. Azure OpenAI stores and processes data to provide the service and to monitor for uses that violate the applicable product terms. Please also see the Microsoft Products and Services Data Protection Addendum , which governs data processing by the Azure OpenAI Service. Azure OpenAI is an Azure service; learn more about applicable Azure compliance offerings.
  2. Removed: This article provides details regarding how data provided by you to the Azure OpenAI service is processed, used, and stored. Azure OpenAI stores and processes data to provide the service and to monitor for uses that violate the applicable product terms. Please also see the Microsoft Products and Services Data Protection Addendum , which governs data processing by the Azure OpenAI Service except as otherwise provided in the applicable Product Terms .
  3. Added: are NOT used to train, retrain, or improve Azure OpenAI Service foundation models.
  4. Added: are NOT used to improve any Microsoft or 3rd party products or services without your permission or instruction.
  5. Removed: are NOT used to improve any Microsoft or 3rd party products or services.
  6. Removed: are NOT used for automatically improving Azure OpenAI models for your use in your resource (The models are stateless, unless you explicitly fine-tune models with your training data).
  7. Added: The Azure OpenAI Service is operated by Microsoft as an Azure service; Microsoft hosts the OpenAI models in Microsoft's Azure environment and the Service does NOT interact with any services operated by OpenAI (e.g. ChatGPT, or the OpenAI API).
  8. Removed: The Azure OpenAI Service is fully controlled by Microsoft; Microsoft hosts the OpenAI models in Microsoft's Azure environment and the Service does NOT interact with any services operated by OpenAI (e.g. ChatGPT, or the OpenAI API).
  9. Added: Prompts and generated content . Prompts are submitted by the user, and content is generated by the service, via the completions, chat completions, images, and embeddings operations.
  10. Added: Uploaded data . You can provide your own data for use with certain service features (e.g., fine-tuning , assistants API , batch processing ) using the Files API or vector store.
  11. Added: Data for stateful entities . When you use certain optional features of Azure OpenAI service, such as the Threads feature of the Assistants API , the service will create a data store to persist message history and other content, in accordance with how you configure the feature.
  12. Added: Augmented data included with or via prompts . When using data associated with stateful entities, the service retrieves relevant data from a configured data store and augments the prompt to produce generations that are grounded with your data. Prompts may also be augmented with data retrieved from a source included in the prompt itself, such as a URL.
  13. Removed: Prompts and generated content . Prompts are submitted by the user, and content is generated by the service, via the completions, chat completions, images and embeddings operations.
  14. Removed: Augmented data included with prompts . When using the "on your data" feature, the service retrieves relevant data from a configured data store and augments the prompt to produce generations that are grounded with your data.
  15. Added: The diagram below illustrates how your data is processed. This diagram covers several types of processing:
  16. Added: How the Azure OpenAI Service processes your prompts via inferencing to generate content (including when additional data from a designated data source is added to a prompt using Azure OpenAI on your data, Assistants, or batch processing).
  17. Added: How the Assistants feature stores data in connection with Messages, Threads, and Runs.
  18. Added: How the Batch feature processes your uploaded data.
  19. Added: How the Azure OpenAI Service creates a fine-tuned (custom) model with your uploaded data.
  20. Added: How the Azure OpenAI Service and Microsoft personnel analyze prompts and completions (text and image) for harmful content and for patterns suggesting the use of the service in a manner that violates the Code of Conduct or other applicable product terms.
  21. Removed: The diagram below illustrates how your data is processed. This diagram covers three different types of processing:
  22. Removed: How the Azure OpenAI Service processes your prompts to generate content (including when additional data from a connected data source is added to a prompt using Azure OpenAI on your data).
  23. Removed: How the Azure OpenAI Service creates a fine-tuned (custom) model with your training data.
  24. Added: Models (base or fine-tuned) deployed in your resource process your input prompts and generate responses with text, images, or embeddings. Customer interactions with the model are logically isolated and secured employing technical measures including but not limited to transport encryption of TLS1.2 or higher, compute security perimeter, tokenization of text, and exclusive access to allocated GPU memory. Prompts and completions are evaluated in real time for harmful content types and content generation is filtered based on configured thresholds. Learn more at Azure OpenAI Service content filtering .
  25. Added: Prompts and responses are processed within the customer-specified geography (unless you are using a Global deployment type), but may be processed between regions within the geography for operational purposes (including performance and capacity management). See below for information about location of processing when using a Global deployment type.
  26. Removed: Models (base or fine-tuned) deployed in your resource process your input prompts and generate responses with text, images or embeddings. Prompts and responses are processed within the customer-specified geography , but may be processed between regions within the geography for operational purposes (including performance and capacity management). The service is configured to synchronously evaluate the prompt and completion data in real time to check for harmful content types and stops generating content that exceeds the configured thresholds. Learn more at Azure OpenAI Service content filtering .
  27. Added: In addition to standard deployments, Azure OpenAI Service offers deployment options labelled as 'Global.' For any deployment type labeled as 'Global,' prompts and responses may be processed in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ); any data stored at rest, such as uploaded data, is stored in the customer-designated geography. Only the location of processing is affected when a customer uses a Global deployment type in Azure OpenAI Service; Azure data processing and compliance commitments remain applicable.
  28. Added: The Azure OpenAI "on your data" feature lets you connect data sources to ground the generated results with your data. The data remains stored in the data source and location you designate; Azure OpenAI Service does not create a duplicate data store. When a user prompt is received, the service retrieves relevant data from the connected data source and augments the prompt. The model processes this augmented prompt and the generated content is returned as described above. Learn more about how to use the On Your Data feature securely .
  29. Added: Some Azure OpenAI Service features store data in the service. This data is either uploaded by the customer, using the Files API or vector store, or is automatically stored in connection with certain stateful entities such as the Threads feature of the Assistants API. Data stored for Azure OpenAI Service features:
  30. Added: Is stored at rest in the Azure OpenAI resource in the customer's Azure tenant, within the same geography as the Azure OpenAI resource;
  31. Added: Can be double encrypted at rest , by default with Microsoft's AES-256 encryption and optionally with a customer managed key (except preview features may not support customer managed keys);
  32. Removed: The Azure OpenAI "on your data" feature lets you connect data sources to ground the generated results with your data. The data remains stored in the data source and location you designate. No data is copied into the Azure OpenAI service . When a user prompt is received, the service retrieves relevant data from the connected data source and augments the prompt. The model processes this augmented prompt and the generated content is returned as described above.
  33. Removed: Creating a customized (fine-tuned) model with your data:
  34. Removed: Customers can upload their training data to the service to fine tune a model. Uploaded training data is stored in the Azure OpenAI resource in the customer's Azure tenant. Training data and fine-tuned models:
  35. Removed: Are available exclusively for use by the customer.
  36. Removed: Are stored within the same region as the Azure OpenAI resource.
  37. Removed: Can be double encrypted at rest (by default with Microsoft's AES-256 encryption and optionally with a customer managed key).
  38. Added: Stored data may be used with the following service features/capabilities:
  39. Added: Creating a customized (fine-tuned) model . Learn more about how fine-tuning works . Fine-tuned models are exclusively available to the customer whose data was used to create the fine-tuned model, are encrypted at rest (when not deployed for inferencing), and can be deleted by the customer at any time. Training data uploaded for fine-tuning is not used to train, retrain, or improve any Microsoft or 3rd party base models.
  40. Added: Batch processing (preview) . Learn more about how batch processing works . Batch processing is a Global deployment type; data stored at rest remains in the designated Azure geography until processing capacity becomes available; processing may occur in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ).
  41. Added: Assistants API (preview) . Learn more about how the Assistants API works . Some features of Assistants, such as Threads, store message history and other content.
  42. Added: To reduce the risk of harmful use of the Azure OpenAI Service, the Azure OpenAI Service includes both content filtering, safety evaluation of fine-tuned models, and abuse monitoring features. To learn more about content filtering, see Azure OpenAI Service content filtering . To learn more about safety evaluation, see safety evaluations of fine-tuned models . To learn more about abuse monitoring, see abuse monitoring .
  43. Removed: Training data uploaded for fine-tuning is not used to train, retrain, or improve any Microsoft or 3rd party base models.
  44. Removed: To reduce the risk of harmful use of the Azure OpenAI Service, the Azure OpenAI Service includes both content filtering and abuse monitoring features. To learn more about content filtering , see Azure OpenAI Service content filtering. To learn more about abuse monitoring, see abuse monitoring .
  45. Added: Safety evaluations of fine-tuned models evaluate a fine-tuned model for potentially harmful responses using Azure's risk and safety metrics . Only the resulting assessment (deployable or not deployable) is logged by the service.
  46. Added: The data store where prompts and completions are stored is logically separated by customer resource (each request includes the resource ID of the customer's Azure OpenAI resource). A separate data store is located in each geography in which the Azure OpenAI Service is available, and a customer's prompts and generated content are stored in the Azure Geography where the customer's Azure OpenAI service resource is deployed, within the Azure OpenAI service boundary. Human reviewers assessing potential abuse can access prompts and completions data only when that data has been flagged by the abuse monitoring system. The human reviewers are authorized Microsoft employees who access the data via point wise queries using request IDs, Secure Access Workstations (SAWs), and Just-In-Time (JIT) request approval granted by team managers. For Azure OpenAI Service deployed in the European Economic Area, the authorized Microsoft employees are located in the European Economic Area.
  47. Removed: The data store where prompts and completions are stored is logically separated by customer resource (each request includes the resource ID of the customer's Azure OpenAI resource). A separate data store is located in each region in which the Azure OpenAI Service is available, and a customer's prompts and generated content are stored in the Azure region where the customer's Azure OpenAI service resource is deployed, within the Azure OpenAI service boundary. Human reviewers assessing potential abuse can access prompts and completions data only when that data has been flagged by the abuse monitoring system. The human reviewers are authorized Microsoft employees who access the data via point wise queries using request IDs, Secure Access Workstations (SAWs), and Just-In-Time (JIT) request approval granted by team managers. For Azure OpenAI Service deployed in the European Economic Area, the authorized Microsoft employees are located in the European Economic Area.
  48. Added: Some customers may want to use the Azure OpenAI Service for a use case that involves the processing of sensitive, highly confidential, or legally-regulated input data but where the likelihood of harmful outputs and/or misuse is low. These customers may conclude that they do not want or do not have the right to permit Microsoft to process such data for abuse detection, as described above, due to their internal policies or applicable legal regulations. To address these concerns, Microsoft allows customers who meet additional Limited Access criteria and attest to specific use cases to apply to modify Azure OpenAI abuse monitoring features by completing this form .
  49. Removed: Some customers may want to use the Azure OpenAI Service for a use case that involves the processing of sensitive, highly confidential, or legally-regulated input data but where the likelihood of harmful outputs and/or misuse is low. These customers may conclude that they do not want or do not have the right to permit Microsoft to process such data for abuse detection, as described above, due to their internal policies or applicable legal regulations. To address these concerns, Microsoft allows customers who meet additional Limited Access eligibility criteria and attest to specific use cases to apply to modify the Azure OpenAI content management features by completing this form .
  50. Removed: Logging status verification using the Azure portal:
  51. Removed: Logging status verification using the Azure CLI (or other management API):
  52. Added: Added information (and revised existing text accordingly) about data processing for new features including Assistants API (preview), Batch (preview), and Global Deployments; revised language related to location of data processing, in accordance with Azure data residency principles ; added information about data processing for safety evaluations of fine-tuned models; clarified commitments related to use of prompts and completions; minor revisions to improve clarity
About this change
Page
learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy
Kind
Documentation
Text hash
0ab2116485b1 to e374d107f182
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.