OpenAI has outlined how the company is aligning its safety and transparency practices with the European Union AI Act as the regulation enters its next implementation phase. The AI developer, whose tools serve millions of European users daily alongside businesses and government entities across the continent, has detailed the frameworks and initiatives now in place to meet the regulatory requirements while maintaining operational flexibility as artificial intelligence technology continues to evolve.
Endorsement of EU Codes of Practice
The company has contributed to and formally endorsed two key regulatory instruments: the General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Both codes emerged from multi-stakeholder consultations and establish shared standards for transparency, safety, and security across general-purpose AI systems. OpenAI's participation reflects the company's stated commitment to pragmatic, risk-based governance that balances innovation with responsible development.
Internal Governance and External Collaboration
OpenAI has implemented multiple internal frameworks to manage advanced AI risks. The Preparedness Framework, established in 2023 and revised in 2025, defines how the organization identifies, evaluates, and mitigates serious risks associated with advanced AI systems. The Frontier Governance Framework builds on this foundation, mapping the company's safety protocols to emerging legal obligations under the EU AI Act's GPAI Code. These structures inform decisions on risk assessment, model reporting, security protocols, incident response procedures, and engagement with external experts.
The company has also engaged in broader industry collaboration through the Frontier Model Forum and partnerships with the US CAISI and UK AISI, supporting shared safety research and the development of standardized third-party evaluation practices. Prior to releases, OpenAI conducts extensive model testing, publishes system cards documenting capabilities and limitations, and involves external specialists through the Red Teaming Network.
Content Provenance and Cybersecurity Initiatives
To address transparency requirements for AI-generated content, OpenAI has deployed dual provenance systems. Content Credentials using the C2PA standard embed detailed metadata, while SynthID watermarks provide resilience when metadata is stripped. The company is extending these measures to audio outputs and plans to expand coverage across additional modalities, including text, as technical standards mature.
In cybersecurity, OpenAI launched the Trusted Access for Cyber program and the OpenAI EU Cyber Action Plan in early May 2026. The initiative provides EU and national cyber agencies, private sector partners, and critical infrastructure operators with access to advanced cyber defense models. This approach aligns with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence.
OpenAI continues to develop compliance resources for customers and developers, including model documentation, system cards, usage policies, and provenance tool guidance, available through the company's Help Center.
Most Read











