OpenAI maps its safety practices to the EU AI Act GPAI Code

OpenAI has published details of how its safety, security, and transparency work aligns with the EU AI Act's General-Purpose AI (GPAI) Code of Practice, as enforcement of the regulation's transparency provisions began on August 2. The company contributed to and endorsed both the GPAI Code of Practice and the separate Code of Practice on Transparency of AI-Generated Content. The GPAI Code sets requirements for transparency, safety, and security across general-purpose models sold or deployed in th

2 min
OpenAI maps its safety practices to the EU AI Act GPAI Code

OpenAI has published details of how its safety, security, and transparency work aligns with the EU AI Act's General-Purpose AI (GPAI) Code of Practice, as enforcement of the regulation's transparency provisions began on August 2.

The company contributed to and endorsed both the GPAI Code of Practice and the separate Code of Practice on Transparency of AI-Generated Content. The GPAI Code sets requirements for transparency, safety, and security across general-purpose models sold or deployed in the EU. The Transparency Code addresses provenance: helping people tell when content was made or altered by AI.

OpenAI points to existing practices as evidence it already operates near the GPAI Code's bar. These include pre-release model testing, published system cards accompanying major launches, external red-teaming through its Red Teaming Network, and a public Model Spec document describing how it shapes model behavior.

Two internal frameworks underpin the compliance effort. The Preparedness Framework, in place since 2023 and updated in 2025, sets out how OpenAI identifies, evaluates, and manages serious risks from advanced systems. A separate Frontier Governance Framework maps the company's safety practices onto legal requirements including the GPAI Code specifically. Together, OpenAI says, these documents govern risk assessment, safeguards, model reporting, security posture, incident response, and external expert involvement.

On transparency, OpenAI relies on two mechanisms designed to reinforce each other. Content Credentials, built on the C2PA standard, attach provenance metadata directly to files. SynthID watermarking provides a fallback signal when that metadata gets stripped. Coverage is expanding from images into audio, and OpenAI says it is working toward extending provenance measures to text as standards mature. No single mechanism catches everything. Metadata gets lost across platform transfers. OpenAI's response is a layered approach rather than a claim that any one signal solves provenance outright.

The cybersecurity component is where OpenAI's compliance work gets concrete. The company's Trusted Access for Cyber programme gives vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse. An EU Cyber Action Plan launched in early May 2026 works with EU and national cyber agencies, private sector partners, and infrastructure operators. OpenAI positions this as consistent with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated handling of AI risks alongside defensive use of the technology.

OpenAI also cites participation in the Frontier Model Forum, collaboration with the US Center for AI Standards and Innovation, and work with the UK AI Security Institute as evidence of broader engagement on shared safety research and testing standards.

The GPAI Code and Transparency Code are still new instruments. OpenAI's compliance documentation is a moving target, not a finished product. Teams building on OpenAI's models in regulated European markets should treat the current system cards and Frontier Governance Framework as a starting point for their own due diligence, not a substitute for it.

Sources

OpenAI aligns safety practices with EU AI Act's GPAI Code - AI News

EU AI Act Article 50 transparency rules enter force - AI News

General-Purpose AI (GPAI) Code of Practice - European Commission

Code of Practice on Transparency of AI-Generated Content - European Commission

Written by

More to read

  • Amazon Data Center Could Be Powered by One of the Nation's Most Polluting Power Plants

    Amazon is investing in a new natural-gas power plant in Pecos County, Texas, to supply a West Texas data center, and the project holds a permit that would allow it to emit more carbon dioxide than any coal plant in the country, according to The Verge and the New York Times. The plant, tracked as GW Ranch by Cleanview, a service that monitors data center power projects, would deploy 35 natural-gas turbines generating about 7.65 gigawatts. At least initially, the plant would not connect to

    1 min
  • Claude Code Defaults to Auto Mode. The Classifier Catches More Than Humans.

    Claude Code Defaults to Auto Mode. The Classifier Catches More Than Humans. Claude Code will ship with Auto Mode enabled by default starting August 14 for Pro, Max, and Team subscribers, shifting the developer role further from active coding toward reviewing AI-generated output. Only Enterprise customers will need to opt in. Auto Mode lets the agent execute steps without waiting for manual approval at each one. A classifier intercepts actions the model judges dangerous or irreversible and paus

    1 min