OpenAI's Game-Changing Move: Adopts EU AI Act's Strict Safety Guidelines

OpenAI is actively aligning its AI safety, security, and transparency practices with the EU AI Act’s GPAI Code and Transparency Code, demonstrating existing measures like pre-release testing and internal governance frameworks. The company employs a layered approach for identifying AI-generated content and is expanding its "Trusted Access for Cyber" program to strengthen European cyber resilience. This evolving compliance framework emphasizes adaptability while urging developers to conduct their own thorough due diligence.
Uche Emeka
Uche EmekaAI12 hours ago5 minute read
Key Points
OpenAI is actively aligning its safety, security, and transparency efforts with the EU AI Act D5s General-Purpose AI (GPAI) Code and the Code of Practice on Transparency of AI-Generated Content.
The company employs internal governance frameworks like the Preparedness Framework and Frontier Governance Framework, alongside external partnerships, to manage AI risks and advance shared safety standards.
OpenAI is implementing provenance mechanisms such as Content Credentials and SynthID, and launched an EU Cyber Action Plan to strengthen European cyber resilience.
OpenAI's Game-Changing Move: Adopts EU AI Act's Strict Safety Guidelines

OpenAI is actively aligning its safety, security, and transparency efforts with the impending enforcement of the EU AI Act’s General-Purpose AI (GPAI) Code. The company has played a role in contributing to and endorsing both the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content, both of which emerged from collaborative multi-stakeholder processes. OpenAI asserts that its existing operational practices already meet the rigorous standards set by the GPAI Code. As evidence, it points to a range of measures including pre-release testing of its models, the publication of detailed system cards accompanying major launches, and engaging in outside red-teaming exercises through its specialized Red Teaming Network. Additionally, OpenAI maintains a public Model Spec document that outlines how the company intentionally shapes model behavior.

Supporting these initiatives are two internal governance frameworks. The Preparedness Framework, which has been in place since 2023 and received an update in 2025, delineates OpenAI’s methodology for identifying, evaluating, and managing serious risks associated with advanced AI systems. Building upon this, a separate Frontier Governance Framework explains how the company’s comprehensive safety and security practices are mapped onto various legal requirements, with specific attention to the GPAI Code. OpenAI states that these two documents collectively govern critical aspects such as risk assessment, the implementation of safeguards, model reporting protocols, maintaining a robust security posture, efficient incident response mechanisms, and the strategic involvement of external experts in the process. Furthermore, OpenAI underscores its participation in collaborative forums like the Frontier Model Forum, as well as its partnerships with organizations such as the US Center for AI Standards and Innovation and the UK AI Security Institute. The company also contributes to broader third-party evaluation standards, with the overarching goal of fostering shared safety research and establishing clearer testing benchmarks across the entire AI industry, extending beyond its internal operations.

The commitments outlined in the Transparency Code are specifically designed to address the complex problem of helping individuals discern when content has been created or altered by artificial intelligence. OpenAI’s strategy for provenance relies on two mutually reinforcing mechanisms. Firstly, Content Credentials, developed based on the C2PA standard, are designed to embed contextual information directly into a digital file. Secondly, SynthID watermarking serves as a critical fallback signal, providing a means of identification in scenarios where metadata might be inadvertently stripped or lost during content transfer. OpenAI is continuously expanding the coverage of these provenance measures, initially from images to audio outputs, and is actively working towards extending them across additional modalities, including text, as the underlying industry standards and technological tools mature. The company is also developing specific signals and guidance intended for developers who utilize OpenAI’s models, assisting them in meeting their own transparency obligations. OpenAI acknowledges that these measures alone do not provide a complete solution for provenance, recognizing that metadata can be lost, and labels may not always persist across different platforms. No single signal, whether cryptographic or watermark-based, can capture every instance of AI-generated content on its own. Therefore, OpenAI’s response is a comprehensive, layered approach, coupled with sustained engagement and collaboration across the wider standards community, rather than asserting that any one mechanism fully closes the existing gap.

In the domain of adaptive governance, particularly concerning cybersecurity, OpenAI recognizes the inherent challenge where capabilities that assist defenders in identifying and patching vulnerabilities could potentially also be used by attackers. To mitigate this, OpenAI has developed its Trusted Access for Cyber programme, which is meticulously designed to provide vetted defenders with access to more advanced cyber capabilities while simultaneously limiting the exposure to potential misuse. This critical programme has now established a European deployment arm. OpenAI announced the launch of its EU Cyber Action Plan in early May 2026, which involves strategic collaborations with EU and national cyber agencies, private sector partners, and infrastructure operators. The objective is to grant these entities access to OpenAI’s more advanced cyber models, with the stated aim of significantly strengthening cyber resilience across the European continent. While OpenAI makes the claim that “most advanced” capabilities translate into measurable defensive gains for these agencies, the source material provided does not offer independent verification of the actual outcomes or effectiveness of the programme. The company positions this work as being entirely consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which advocates for a coordinated approach to managing AI’s risks while simultaneously leveraging its potential to enhance defensive capabilities, including through secure access arrangements specifically for cybersecurity purposes.

OpenAI reiterates that its approach to compliance is subject to continuous adjustment and evolution as the implementation of the EU AI Act progresses. The company anticipates ongoing learning from interactions with regulators and the broader community involved in shaping these rules. OpenAI advocates for regulatory frameworks that possess sufficient flexibility to adapt as technology continues to advance rapidly, arguing that such adaptability is essential for businesses and organizations to continually derive benefits from AI innovation. It is important to note that both the GPAI Code and the Transparency Code are relatively new instruments, and OpenAI’s compliance documentation is consequently a moving target rather than a finalized product. Therefore, teams developing solutions on OpenAI’s models within regulated European markets are strongly advised to treat the current system cards and the Frontier Governance Framework as a fundamental starting point for their own rigorous due diligence, rather than a conclusive substitute for it.

Loading...