Friday, July 31, 2026

OpenAI aligns safety practices with EU AI Act’s GPAI Code

by Ryan Daws
0 comments

OpenAI has outlined how it aligns safety, security, and transparency work with the EU AI Act’s GPAI Code as enforcement approaches.

The company has contributed to and endorsed the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Both emerged from multi-stakeholder processes.

The GPAI Code sets a shared bar for transparency, safety, and security across general-purpose models sold or deployed in the EU. OpenAI points to a stack of existing practices as evidence it already operates near that bar: pre-release testing of models, published system cards accompanying major launches, and outside red-teaming through what it calls its Red Teaming Network. The company also maintains a public Model Spec document describing how it shapes model behaviour.

Two internal frameworks sit underneath that work. The Preparedness Framework has been in place since 2023 and was updated in 2025; it sets out how OpenAI identifies, evaluates and manages serious risks from advanced systems. A separate Frontier Governance Framework builds on it, explaining how the company’s safety and security practices map onto legal requirements including the GPAI Code specifically. 

Together, OpenAI says, those two documents govern risk assessment, safeguards, model reporting, security posture, incident response, and how external experts get pulled into the process.

OpenAI cites its participation in the Frontier Model Forum alongside collaborations with the US Center for AI Standards and Innovation and the UK AI Security Institute, plus contributions to third-party evaluation standards more broadly. The stated goal is shared safety research and clearer testing benchmarks across the industry, not just within one company’s walls.

Provenance gets harder as modalities multiply

The Transparency Code commitments centre on a different problem: helping people tell when content was made or altered by AI.

OpenAI’s approach rests on two mechanisms that are meant to reinforce each other. Content Credentials, built on the C2PA standard, attach context directly to a file. SynthID watermarking provides a fallback signal for cases where that metadata gets stripped out somewhere along the way.

Coverage is expanding from images into audio outputs, and OpenAI says it’s working toward extending provenance measures across further modalities, including text, as the underlying standards and tooling mature. The company is also building signals and guidance aimed at developers who need to meet their own transparency obligations when building on top of its models.

None of this solves provenance outright. Metadata gets lost and labels don’t always survive a transfer between platforms. No single signal, whether cryptographic or watermark-based, catches everything on its own. OpenAI’s response is a layered approach paired with continued work across the wider standards community rather than a claim that any one mechanism closes the gap.

Cybersecurity as the test case for adaptive governance

Capabilities that help defenders spot and patch vulnerabilities are the same capabilities that could help an attacker find them first. OpenAI believes the answer is its Trusted Access for Cyber programme, designed to give vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse.

That programme now has a European deployment arm. OpenAI states it launched its EU Cyber Action Plan in early May 2026, working with EU and national cyber agencies, private sector partners, and infrastructure operators to give them access to its more advanced cyber models.

The stated aim of the plan is to strengthen cyber resilience across the continent. Whether “most advanced” translates into measurable defensive gains inside these agencies is a claim from OpenAI itself; the source material offers no independent verification of outcomes from the programme.

The company positions this work as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated handling of AI’s risks alongside its use in strengthening defensive capability, including secure access arrangements for cybersecurity purposes specifically.

OpenAI says it will keep adjusting its compliance approach as EU AI Act implementation continues, and that it expects to keep learning from regulators and the wider community involved in shaping the rules. The company argues that rules need enough flexibility to adapt as the technology moves, so that businesses and organisations can keep benefiting from it.

The GPAI Code and the Transparency Code are still relatively new instruments, and OpenAI’s compliance documentation is a moving target rather than a finished product. Teams building on OpenAI’s models in regulated European markets should treat the current system cards and Frontier Governance Framework as a starting point for their own due diligence, not a substitute for it.

See also: Zuckerberg details Meta’s personal AI superintelligence strategy

Banner for the AI & Big Data Expo event series.

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

You may also like