OpenAI aligns safety practices with EU AI Act’s GPAI Code
OpenAI details how its safety, security, and transparency measures correspond with the European Union's GPAI Code as enforcement approaches.

Stock photo for illustration only, not from the actual event
- OpenAI outlines alignment with the EU's GPAI Code and Transparency Code
- Relies on internal frameworks including the Preparedness Framework and Frontier Governance Framework
- Launches the EU Cyber Action Plan in May 2026 to support cybersecurity agencies
OpenAI has outlined the ways its safety, security, and transparency operations align with the EU AI Act’s General-Purpose AI (GPAI) Code ahead of upcoming enforcement. The company has contributed to and endorsed both the EU’s GPAI Code of Practice and the Code of Practice on Transparency of AI-Generated Content, which were developed through multi-stakeholder processes.
The GPAI Code establishes a shared baseline for transparency, safety, and security across general-purpose models deployed within the EU. OpenAI points to existing practices as proof of its alignment, including pre-release model testing, published system cards for major launches, third-party red-teaming via its Red Teaming Network, and a public Model Spec document detailing behavioral guidelines.
OpenAI's proactive alignment with the EU AI Act highlights how European regulations are increasingly shaping global artificial intelligence standards. Complying with these rigorous frameworks is essential for tech giants seeking to operate within the European market, establishing a precedent for accountability and risk management across the broader technology sector.
Underpinning these efforts are two internal frameworks. The Preparedness Framework, active since 2023 and updated in 2025, dictates how the company identifies and manages serious risks from advanced systems. A separate Frontier Governance Framework builds upon this foundation, mapping safety practices directly to legal requirements such as the GPAI Code.

Stock photo for illustration only, not from the actual event
To tackle transparency challenges regarding AI-generated content, OpenAI utilizes two complementary mechanisms: Content Credentials based on the C2PA standard to attach metadata directly to files, and SynthID watermarking as a fallback signal if metadata is stripped away. Coverage is actively expanding from images into audio and other modalities.
Furthermore, OpenAI launched its EU Cyber Action Plan in early May 2026 under its Trusted Access for Cyber programme, providing vetted European cybersecurity agencies and infrastructure operators with access to advanced cyber models in alignment with the European Commission's cybersecurity directives.
Source: AI News
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment