OpenAI’s compliance playbook for the EU AI Act
OpenAI has published a detailed breakdown of how its safety, security, and transparency work maps onto the European Union’s General-Purpose AI (GPAI) Code of Practice — the rulebook that will govern how foundation models are built and deployed across the bloc. The timing is deliberate. Enforcement of the EU AI Act is creeping closer, and the company wants to show it’s not starting from zero.
The GPAI Code, alongside a separate Code of Practice on Transparency of AI-Generated Content, emerged from multi-stakeholder processes led by the European Commission. Both are meant to translate the AI Act’s broad obligations into concrete, actionable standards. OpenAI says it contributed to and endorsed both documents.
For companies building on OpenAI’s models in Europe, this is more than a regulatory update. It’s a signal about what due diligence will look like in practice.
What OpenAI already does — and what it’s adding
OpenAI’s argument is simple: much of what the GPAI Code demands, it already does. The company points to a stack of existing practices as evidence it operates near the bar set by the Code.
- Pre-release testing of models before they reach the public.
- Published system cards accompanying major launches, detailing capabilities and limitations.
- External red-teaming through its Red Teaming Network, which brings in outside experts to probe for vulnerabilities.
- A public Model Spec document that explains how the company shapes model behavior.
Underneath that work sit two internal governance frameworks. The Preparedness Framework, in place since 2023 and updated in 2025, sets out how OpenAI identifies, evaluates, and manages serious risks from advanced systems. A separate Frontier Governance Framework builds on it, explicitly mapping the company’s safety and security practices onto legal requirements — including the GPAI Code itself.
Together, these two documents govern risk assessment, safeguards, model reporting, security posture, incident response, and how external experts get pulled into the process. That’s a lot of paperwork, but it’s the kind of documentation regulators will expect to see.
The transparency problem: provenance gets harder
The Transparency Code tackles a different problem: helping people tell when content was made or altered by AI. OpenAI’s approach rests on two mechanisms that are meant to reinforce each other.
Content Credentials, built on the C2PA standard, attach context directly to a file — think of it as a digital signature that travels with the content. SynthID watermarking provides a fallback signal for cases where that metadata gets stripped out somewhere along the way. Coverage is expanding from images into audio outputs, and OpenAI says it’s working toward extending provenance measures across further modalities, including text, as the underlying standards mature.
None of this solves provenance outright. Metadata gets lost. Labels don’t always survive a transfer between platforms. No single signal — whether cryptographic or watermark-based — catches everything on its own. OpenAI’s response is a layered approach paired with continued work across the wider standards community, rather than a claim that any one mechanism closes the gap.
Cybersecurity as the test case for adaptive governance
Here’s the tension at the heart of AI regulation: capabilities that help defenders spot and patch vulnerabilities are the same capabilities that could help an attacker find them first. OpenAI believes the answer is its Trusted Access for Cyber programme, designed to give vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse.
That programme now has a European deployment arm. OpenAI says it launched its EU Cyber Action Plan in early May 2026, working with EU and national cyber agencies, private sector partners, and infrastructure operators. The stated aim is to strengthen cyber resilience across the continent. Whether “most advanced” translates into measurable defensive gains inside these agencies is a claim from OpenAI itself; the source material offers no independent verification of outcomes.
The company positions this work as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated handling of AI’s risks alongside its use in strengthening defensive capability — including secure access arrangements for cybersecurity purposes specifically.
What this means for developers and enterprises
The GPAI Code and the Transparency Code are still relatively new instruments, and OpenAI’s compliance documentation is a moving target rather than a finished product. Teams building on OpenAI’s models in regulated European markets should treat the current system cards and Frontier Governance Framework as a starting point for their own due diligence, not a substitute for it.
OpenAI says it will keep adjusting its compliance approach as EU AI Act implementation continues, and that it expects to keep learning from regulators and the wider community involved in shaping the rules. The company argues that rules need enough flexibility to adapt as the technology moves, so that businesses and organisations can keep benefiting from it.
For a deeper look at how these rules are shaping up, check out our coverage of AI regulation in Europe and the broader AI safety landscape.