**OpenAI Aligns with EU AI Act: Transparency, Safety, and Cybersecurity in Focus**
OpenAI has detailed how its work on safety, security, and transparency aligns with the European Union’s Artificial Intelligence Act (EU AI Act), specifically in relation to the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. These codes, developed through multi-stakeholder processes, set a shared standard for transparency, safety, and security for general-purpose AI models deployed or sold in the EU. OpenAI has contributed to and endorsed both codes, signaling its commitment to operating near the established bar even before formal enforcement.
—
### OpenAI’s Existing Safety and Transparency Measures
According to OpenAI, the company already operates close to the standards outlined in the GPAI Code through a range of established practices. These include:
– **Pre-release testing** of AI models
– **Published system cards** accompanying major model launches
– **External red-teaming** via its Red Teaming Network
– A public **Model Spec document** that outlines how model behavior is shaped
Beneath these public-facing measures are two internal frameworks:
– **The Preparedness Framework** (updated in 2025), which outlines how OpenAI identifies, evaluates, and manages serious risks from advanced AI systems
– **The Frontier Governance Framework**, which maps OpenAI’s safety and security practices onto legal requirements, including the GPAI Code
Together, these documents guide risk assessment, safeguards, model reporting, incident response, and the involvement of external experts. OpenAI also collaborates with initiatives such as the Frontier Model Forum, the U.S. Center for AI Standards and Innovation, and the UK AI Security Institute, emphasizing shared safety research and common testing benchmarks across the industry.
—
### Provenance Challenges in a Multimodal World
A major focus of the EU Transparency Code is helping users distinguish AI-generated or AI-altered content. OpenAI’s strategy relies on two complementary mechanisms:
– **Content Credentials**, based on the C2PA standard, which embed provenance information directly into files
– **SynthID watermarking**, which provides a detectable signal even when metadata is removed
These measures are currently applied to images and audio, with plans to expand to other modalities, including text, as standards and tools evolve. OpenAI also supports developers building on its models in meeting their own transparency obligations.
However, the company acknowledges limitations: metadata can be lost, and labels may not survive platform transfers. No single technical solution is foolproof. OpenAI’s approach therefore emphasizes layered protections and ongoing cooperation with the broader standards community.
—
### Cybersecurity as a Test for Adaptive Governance
OpenAI views cybersecurity as a key area for adaptive governance. Its **Trusted Access for Cyber programme** provides vetted defenders with advanced AI tools while reducing misuse risks. In May 2026, the company expanded this effort into Europe through the **EU Cyber Action Plan**, partnering with EU and national cyber agencies, private sector players, and infrastructure operators.
The stated goal is to strengthen cyber resilience across the EU. OpenAI frames this work as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which promotes secure AI use and controlled access to advanced capabilities for defensive purposes.
—
### FAQs
**Q: What is the EU AI Act’s GPAI Code?**
The GPAI Code sets baseline requirements for transparency, safety, and security for general-purpose AI models placed on the EU market or used there.
**Q: Which OpenAI practices align with the GPAI Code?**
OpenAI highlights pre-release testing, system cards, red-teaming, and its Model Spec as evidence of alignment with the GPAI Code’s expectations.
**Q: How does OpenAI address AI-generated content transparency?**
OpenAI uses Content Credentials and SynthID watermarking to help identify AI-created or modified content, with plans to extend these measures to more modalities.
**Q: What is the EU Cyber Action Plan?**
It is an initiative by OpenAI to provide vetted European cyber defenders with advanced AI tools to improve cyber resilience, while managing potential misuse risks.
**Q: Does OpenAI’s compliance documentation change over time?**
Yes. OpenAI describes its compliance approach as evolving, noting that the GPAI Code and related documents are still new and that the company expects to adjust its practices as regulations and technology develop.
—
### Conclusion
OpenAI is positioning itself as a proactive participant in shaping global AI governance, particularly in the European regulatory landscape. By endorsing the EU’s GPAI Code and Transparency Code, supporting cybersecurity initiatives, and investing in provenance technologies, the company demonstrates alignment with emerging legal and ethical norms. However, it also acknowledges technical limits and the need for continued collaboration. As implementation of the EU AI Act progresses, OpenAI’s frameworks and public documents will likely remain works in progress, shaped by ongoing dialogue with regulators, users, and the wider AI community.



