Skip to content

Data, privacy, and security for Models sold by Azure changed Microsoft, Jan 1, 2025

Microsoft · Jan 1, 2025 · 13 added, 10 removed · found in an Internet Archive capture

  1. Added: Data for stateful entities . When you use certain optional features of Azure OpenAI service, such as the Threads feature of the Assistants API and Stored completions, the service will create a data store to persist message history and other content, in accordance with how you configure the feature.
  2. Removed: Data for stateful entities . When you use certain optional features of Azure OpenAI service, such as the Threads feature of the Assistants API , the service will create a data store to persist message history and other content, in accordance with how you configure the feature.
  3. Added: In addition to standard deployments, Azure OpenAI Service offers deployment options labelled as 'Global' and 'DataZone.' For any deployment type labeled 'Global,' prompts and responses may be processed in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ). For any deployment type labeled as 'DataZone,' prompts and responses may be processed in any geography within the specified data zone, as defined by Microsoft. If you create a DataZone deployment in an Azure OpenAI resource located in the United States, prompts and responses may be processed anywhere within the United States. If you create a DataZone deployment in an Azure OpenAI resource located in a European Union Member Nation, prompts and responses may be processed in that or any other European Union Member Nation. For both Global and DataZone deployment types, any data stored at rest, such as uploaded data, is stored in the customer-designated geography. Only the location of processing is affected when a customer uses a Global deployment type or DataZone deployment type in Azure OpenAI Service; Azure data processing and compliance commitments remain applicable.
  4. Removed: In addition to standard deployments, Azure OpenAI Service offers deployment options labelled as 'Global.' For any deployment type labeled as 'Global,' prompts and responses may be processed in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ); any data stored at rest, such as uploaded data, is stored in the customer-designated geography. Only the location of processing is affected when a customer uses a Global deployment type in Azure OpenAI Service; Azure data processing and compliance commitments remain applicable.
  5. Added: Some Azure OpenAI Service features store data in the service. This data is either uploaded by the customer, using the Files API or vector store, or is automatically stored in connection with certain stateful entities such as the Threads feature of the Assistants API and Stored completions. Data stored for Azure OpenAI Service features:
  6. Removed: Some Azure OpenAI Service features store data in the service. This data is either uploaded by the customer, using the Files API or vector store, or is automatically stored in connection with certain stateful entities such as the Threads feature of the Assistants API. Data stored for Azure OpenAI Service features:
  7. Added: Azure OpenAI features in preview might not support all of the above conditions.
  8. Added: Stored completions (preview) . Stored completions stores input-output pairs from the customer's deployed Azure OpenAI models such as GPT-4o through the chat completions API and displays the pairs in the Azure AI Foundry portal. This allows customers to build datasets with their production data, which can then be used for evaluating or fine-tuning models (as permitted in applicable Product Terms).
  9. Added: To reduce the risk of harmful use of the Azure OpenAI Service, the Azure OpenAI Service includes both content filtering and abuse monitoring features. To learn more about content filtering, see Azure OpenAI Service content filtering . To learn more about abuse monitoring, see abuse monitoring .
  10. Added: Content filtering occurs synchronously as the service processes prompts to generate content as described above and here . No prompts or generated content are stored in the content classifier models, and prompts and outputs are not used to train, retrain, or improve the classifier models without your consent.
  11. Removed: To reduce the risk of harmful use of the Azure OpenAI Service, the Azure OpenAI Service includes both content filtering, safety evaluation of fine-tuned models, and abuse monitoring features. To learn more about content filtering, see Azure OpenAI Service content filtering . To learn more about safety evaluation, see safety evaluations of fine-tuned models . To learn more about abuse monitoring, see abuse monitoring .
  12. Removed: Content filtering occurs synchronously as the service processes prompts to generate content as described above and here . No prompts or generated results are stored in the content classifier models, and prompts and results are not used to train, retrain, or improve the classifier models.
  13. Added: Azure OpenAI abuse monitoring system is designed to detect and mitigate instances of recurring content and/or behaviors that suggest use of the service in a manner that may violate the code of conduct or other applicable product terms. As described here , the system employs algorithms and heuristics to detect indicators of potential abuse. When these indicators are detected, a sample of customer's prompts and completions may be selected for review. Review is conducted by LLM by default, with additional reviews by human reviewers as necessary. Detailed information about AI and human review is available at Azure OpenAI Service abuse monitoring .
  14. Added: For AI review, customer's prompts and completions are not stored by the system or used to train the LLM or other systems. For human review, the data store where prompts and completions are stored is logically separated by customer resource (each request includes the resource ID of the customer's Azure OpenAI resource). A separate data store is located in each geography in which the Azure OpenAI Service is available, and a customer's prompts and generated content are stored in the Azure geography where the customer's Azure OpenAI service resource is deployed, within the Azure OpenAI service boundary. Human reviewers assessing potential abuse can access prompts and completions data only when that data has already been flagged by the abuse monitoring system. The human reviewers are authorized Microsoft employees who access the data via point wise queries using request IDs, Secure Access Workstations (SAWs), and Just-In-Time (JIT) request approval granted by team managers. For Azure OpenAI Service deployed in the European Economic Area, the authorized Microsoft employees are located in the European Economic Area.
  15. Added: If the customer has been approved for modified abuse monitoring (learn more at Azure OpenAI Service abuse monitoring ), Microsoft does not store the prompts and completions associated with the approved Azure subscription(s), and the human review process described above is not possible and is not performed. However, AI review may still be conducted, leveraging LLMs that review prompts and completions at the time provided or generated, as applicable.
  16. Added: Azure Preview features, including Azure OpenAI models in preview, may employ different privacy practices, including with respect to abuse monitoring. Previews may be subject to supplemental terms at: Supplemental Terms of use for Microsoft Azure Previews .
  17. Removed: Azure OpenAI abuse monitoring detects and mitigates instances of recurring content and/or behaviors that suggest use of the service in a manner that may violate the code of conduct or other applicable product terms. To detect and mitigate abuse, Azure OpenAI stores all prompts and generated content securely for up to thirty (30) days. (No prompts or completions are stored if the customer is approved for and elects to configure abuse monitoring off, as described below.)
  18. Removed: The data store where prompts and completions are stored is logically separated by customer resource (each request includes the resource ID of the customer's Azure OpenAI resource). A separate data store is located in each geography in which the Azure OpenAI Service is available, and a customer's prompts and generated content are stored in the Azure Geography where the customer's Azure OpenAI service resource is deployed, within the Azure OpenAI service boundary. Human reviewers assessing potential abuse can access prompts and completions data only when that data has been flagged by the abuse monitoring system. The human reviewers are authorized Microsoft employees who access the data via point wise queries using request IDs, Secure Access Workstations (SAWs), and Just-In-Time (JIT) request approval granted by team managers. For Azure OpenAI Service deployed in the European Economic Area, the authorized Microsoft employees are located in the European Economic Area.
  19. Removed: How can customers get an exemption from abuse monitoring and human review?
  20. Removed: Some customers may want to use the Azure OpenAI Service for a use case that involves the processing of sensitive, highly confidential, or legally-regulated input data but where the likelihood of harmful outputs and/or misuse is low. These customers may conclude that they do not want or do not have the right to permit Microsoft to process such data for abuse detection, as described above, due to their internal policies or applicable legal regulations. To address these concerns, Microsoft allows customers who meet additional Limited Access criteria and attest to specific use cases to apply to modify Azure OpenAI abuse monitoring features by completing this form .
  21. Removed: If Microsoft approves a customer's request to modify abuse monitoring, then Microsoft does not store any prompts and completions associated with the approved Azure subscription for which abuse monitoring is configured off. In this case, because no prompts and completions are stored at rest in the Service Results Store, the human review process is not possible and is not performed. See Abuse monitoring for more information.
  22. Added: Added information about data processing and storage in connection with new Stored completions feature; added language clarifying that Azure OpenAI features in preview may not support all data storage conditions; removed "preview" designation for Batch processing
  23. Added: Added information about location of data processing for new 'Data zone' deployment types; added information about new AI review of prompts and completions as part of preventing abuse and generation of harmful content
About this change
Page
learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy
Kind
Documentation
Text hash
e374d107f182 to 0b5538e8845e
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.