OpenAI publishes its EU AI Act compliance blueprint as GPAI enforcement looms

With the EU AI Act’s general-purpose AI obligations already in force and high-risk rules scheduled to bite in August 2026, OpenAI has gone public with the internal machinery it says already meets the bar. The disclosure walks through the company’s Preparedness and Frontier Governance frameworks and maps them onto the General-Purpose AI (GPAI) Code of Practice, a voluntary instrument designed to help model providers demonstrate compliance with the Act.

OpenAI argues it already operates near the code’s bar. It points to pre-release testing of models, published system cards accompanying major launches, external red-teaming through its Red Teaming Network, and a public Model Spec document describing how model behavior is shaped. Internally, two frameworks govern the work: the Preparedness Framework, in place since 2023 and updated in 2025, which covers how serious risks from advanced systems are identified and managed, and the Frontier Governance Framework, which maps those safety practices onto legal requirements including the GPAI Code.

The transparency half of the plan leans on two reinforcing mechanisms. Content Credentials, built on the C2PA standard, attach provenance context directly to files, while SynthID watermarking provides a fallback signal when metadata is stripped. OpenAI says the coverage is expanding from images into audio and is working toward text as standards and tooling mature, and it will provide guidance for developers building on its models who carry their own transparency obligations.

The company is candid about the limits. Metadata gets lost in platform-to-platform transfers, labels do not always survive, and no single cryptographic or watermark-based signal catches everything. The stated answer is a layered approach plus continued work in the standards community, not a claim that any one mechanism closes the gap.

Support independent reporting built on evidence, transparency, and scientific rigor.

Become a supporter

Cybersecurity is the other pillar. OpenAI frames the core tension as capabilities that help defenders patch vulnerabilities being the same capabilities that could help attackers find them first. Its Trusted Access for Cyber program gives vetted defenders access to more advanced cyber capabilities while limiting exposure to misuse, and in early May 2026 the company launched an EU Cyber Action Plan working with EU and national cyber agencies, private-sector partners, and infrastructure operators. The plan aligns with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, though OpenAI’s claims about defensive gains inside those agencies have not been independently verified.

OpenAI announced its intention to sign the GPAI Code earlier, subject to formal approval of the current version by the EU AI Board, and has positioned itself as a constructive partner in the multi-stakeholder process that produced both the GPAI Code and the companion Code of Practice on Transparency of AI-Generated Content.

For developers operating in regulated European markets, the practical implication is that OpenAI’s system cards and Frontier Governance Framework are a starting point for their own due diligence, not a substitute for it. The compliance documentation itself is described as a moving target, expected to keep adjusting as the EU AI Act’s implementation proceeds.

Sources: OpenAI aligns safety practices with EU AI Act’s GPAI Code (AI News, July 31, 2026); The EU Code of Practice and future of AI in Europe (OpenAI); A Primer on the EU AI Act (OpenAI); The General-Purpose AI Code of Practice (European Commission)

Scroll to Top