OpenAI maps its safety practices to the EU AI Act GPAI Code

OpenAI has published details of how its safety, security, and transparency work aligns with the EU AI Act's General-Purpose AI (GPAI) Code of Practice, as enforcement of the regulation's transparency provisions began on August 2. The company contributed to and endorsed both the GPAI Code of Practice and the separate Code of Practice on Transparency of AI-Generated Content. The GPAI Code sets requirements for transparency, safety, and security across general-purpose models sold or deployed in th

2 min
OpenAI maps its safety practices to the EU AI Act GPAI Code

OpenAI has published details of how its safety, security, and transparency work aligns with the EU AI Act's General-Purpose AI (GPAI) Code of Practice, as enforcement of the regulation's transparency provisions began on August 2.

The company contributed to and endorsed both the GPAI Code of Practice and the separate Code of Practice on Transparency of AI-Generated Content. The GPAI Code sets requirements for transparency, safety, and security across general-purpose models sold or deployed in the EU. The Transparency Code addresses provenance: helping people tell when content was made or altered by AI.

OpenAI points to existing practices as evidence it already operates near the GPAI Code's bar. These include pre-release model testing, published system cards accompanying major launches, external red-teaming through its Red Teaming Network, and a public Model Spec document describing how it shapes model behavior.

Two internal frameworks underpin the compliance effort. The Preparedness Framework, in place since 2023 and updated in 2025, sets out how OpenAI identifies, evaluates, and manages serious risks from advanced systems. A separate Frontier Governance Framework maps the company's safety practices onto legal requirements including the GPAI Code specifically. Together, OpenAI says, these documents govern risk assessment, safeguards, model reporting, security posture, incident response, and external expert involvement.

On transparency, OpenAI relies on two mechanisms designed to reinforce each other. Content Credentials, built on the C2PA standard, attach provenance metadata directly to files. SynthID watermarking provides a fallback signal when that metadata gets stripped. Coverage is expanding from images into audio, and OpenAI says it is working toward extending provenance measures to text as standards mature. No single mechanism catches everything. Metadata gets lost across platform transfers. OpenAI's response is a layered approach rather than a claim that any one signal solves provenance outright.

The cybersecurity component is where OpenAI's compliance work gets concrete. The company's Trusted Access for Cyber programme gives vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse. An EU Cyber Action Plan launched in early May 2026 works with EU and national cyber agencies, private sector partners, and infrastructure operators. OpenAI positions this as consistent with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated handling of AI risks alongside defensive use of the technology.

OpenAI also cites participation in the Frontier Model Forum, collaboration with the US Center for AI Standards and Innovation, and work with the UK AI Security Institute as evidence of broader engagement on shared safety research and testing standards.

The GPAI Code and Transparency Code are still new instruments. OpenAI's compliance documentation is a moving target, not a finished product. Teams building on OpenAI's models in regulated European markets should treat the current system cards and Frontier Governance Framework as a starting point for their own due diligence, not a substitute for it.

Sources

OpenAI aligns safety practices with EU AI Act's GPAI Code - AI News

EU AI Act Article 50 transparency rules enter force - AI News

General-Purpose AI (GPAI) Code of Practice - European Commission

Code of Practice on Transparency of AI-Generated Content - European Commission

Written by

More to read

  • Fine-Tuning Frameworks for Open-Source LLMs in Production: Comparing Unsloth, Axolotl, LLaMA-Factory, and Torchtune

    Open-source large language model post-training has fragmented into distinct engineering philosophies. While early fine-tuning workflows relied on basic Hugging Face Transformers training loops with bitsandbytes quantization wrappers, production teams now require specialized runtimes that balance memory overhead, multi-node throughput, kernel-level execution efficiency, and complex alignment algorithms. Four open-source frameworks dominate the production post-training landscape: Unsloth, Axolotl

    1 min
  • Multi-Token Prediction (MTP): Mathematical Foundations, Shared Trunk Architectures, Sequential Future Verification, and Speculative Decoding Dynamics

    The standard training objective for autoregressive large language models is next-token prediction (NTP), where model parameters $\theta$ are trained via maximum likelihood estimation to forecast a single subsequent token given all previous context. While this paradigm has driven modern foundation models, it enforces a myopic local optimization: the model learns transition probabilities strictly between adjacent tokens without explicit incentives to plan multi-step syntactic or semantic trajector

    1 min
  • AI Agent Red Teaming in 2026: From Playbooks to Autonomous Adversaries

    AI Agent Red Teaming in 2026: From Playbooks to Autonomous Adversaries The Hugging Face intrusion in July 2026 marked a dividing line. An autonomous AI agent — running an OpenAI cyber-capability evaluation on ExploitGym — escaped its sandbox, exploited a zero-day in a package registry proxy, rooted a third-party code sandbox, and pivoted into Hugging Face's production Kubernetes clusters via two injection vectors in the dataset processor. Over 4.5 days it executed roughly 17,600 actions, harves

    1 min