OpenAI has outlined the way it aligns security, safety, and transparency work with the EU AI Act’s GPAI Code as enforcement approaches.
The corporate has contributed to and endorsed the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Each emerged from multi-stakeholder processes.
The GPAI Code units a shared bar for transparency, security, and safety throughout general-purpose fashions bought or deployed within the EU. OpenAI factors to a stack of present practices as proof it already operates close to that bar: pre-release testing of fashions, revealed system playing cards accompanying main launches, and out of doors red-teaming via what it calls its Pink Teaming Community. The corporate additionally maintains a public Mannequin Spec doc describing the way it shapes mannequin behaviour.
Two inside frameworks sit beneath that work. The Preparedness Framework has been in place since 2023 and was up to date in 2025; it units out how OpenAI identifies, evaluates and manages severe dangers from superior techniques. A separate Frontier Governance Framework builds on it, explaining how the corporate’s security and safety practices map onto authorized necessities together with the GPAI Code particularly.
Collectively, OpenAI says, these two paperwork govern threat evaluation, safeguards, mannequin reporting, safety posture, incident response, and the way exterior consultants get pulled into the method.
OpenAI cites its participation within the Frontier Model Forum alongside collaborations with the US Center for AI Standards and Innovation and the UK AI Security Institute, plus contributions to third-party analysis requirements extra broadly. The acknowledged objective is shared security analysis and clearer testing benchmarks throughout the business, not simply inside one firm’s partitions.
Provenance will get tougher as modalities multiply
The Transparency Code commitments centre on a special drawback: serving to folks inform when content material was made or altered by AI.
OpenAI’s method rests on two mechanisms that should reinforce one another. Content material Credentials, constructed on the C2PA normal, connect context on to a file. SynthID watermarking gives a fallback sign for instances the place that metadata will get stripped out someplace alongside the way in which.
Protection is increasing from photos into audio outputs, and OpenAI says it’s working towards extending provenance measures throughout additional modalities, together with textual content, because the underlying requirements and tooling mature. The corporate can be constructing indicators and steerage aimed toward builders who want to satisfy their very own transparency obligations when constructing on prime of its fashions.
None of this solves provenance outright. Metadata will get misplaced and labels don’t all the time survive a switch between platforms. No single sign, whether or not cryptographic or watermark-based, catches all the pieces by itself. OpenAI’s response is a layered method paired with continued work throughout the broader requirements neighborhood quite than a declare that anyone mechanism closes the hole.
Cybersecurity because the take a look at case for adaptive governance
Capabilities that help defenders spot and patch vulnerabilities are the identical capabilities that would assist an attacker discover them first. OpenAI believes the reply is its Trusted Entry for Cyber programme, designed to present vetted defenders entry to extra superior cyber capabilities whereas limiting publicity for misuse.
That programme now has a European deployment arm. OpenAI states it launched its EU Cyber Motion Plan in early Might 2026, working with EU and nationwide cyber businesses, non-public sector companions, and infrastructure operators to present them entry to its extra superior cyber fashions.
The acknowledged intention of the plan is to strengthen cyber resilience throughout the continent. Whether or not “most superior” interprets into measurable defensive good points inside these businesses is a declare from OpenAI itself; the supply materials presents no impartial verification of outcomes from the programme.
The corporate positions this work as in keeping with the European Fee’s Action Plan on Cybersecurity and Artificial Intelligence, which requires coordinated dealing with of AI’s dangers alongside its use in strengthening defensive functionality, together with safe entry preparations for cybersecurity functions particularly.
OpenAI says it’ll maintain adjusting its compliance method as EU AI Act implementation continues, and that it expects to continue to learn from regulators and the broader neighborhood concerned in shaping the principles. The corporate argues that guidelines want sufficient flexibility to adapt because the expertise strikes, so that companies and organisations can maintain benefiting from it.
The GPAI Code and the Transparency Code are nonetheless comparatively new devices, and OpenAI’s compliance documentation is a transferring goal quite than a completed product. Groups constructing on OpenAI’s fashions in regulated European markets ought to deal with the present system playing cards and Frontier Governance Framework as a place to begin for their very own due diligence, not an alternative choice to it.
See additionally: Zuckerberg particulars Meta’s private AI superintelligence technique
Wish to be taught extra about AI and massive knowledge from business leaders? Try AI & Big Data Expo going down in Amsterdam, California, and London. The great occasion is a part of TechEx and is co-located with different main expertise occasions together with the Cyber Security & Cloud Expo. Click on here for extra info.
AI Information is powered by TechForge Media. Discover different upcoming enterprise expertise occasions and webinars here.
