As the European Union prepares to enforce its AI Act, OpenAI has detailed how its existing safety, security, and transparency initiatives align with the bloc’s newly introduced General-Purpose AI (GPAI) Code of Practice.
The company has formally endorsed both the EU’s GPAI Code of Practice and the Code of Practice on Transparency of AI-Generated Content, two frameworks created through collaboration between regulators, industry experts, and other stakeholders. OpenAI says its current governance model already reflects many of the principles these codes establish.
Existing safety framework
OpenAI highlighted several practices that have become standard before launching its AI models. These include extensive pre-release testing, publishing system cards that explain model capabilities and limitations, and conducting independent red-team evaluations through its Red Teaming Network. The company also maintains a public Model Spec that outlines how it designs and governs model behavior.
Supporting these efforts are two internal governance systems. The Preparedness Framework, first introduced in 2023 and later updated, provides guidance for identifying, evaluating, and mitigating risks associated with advanced AI models. Complementing it is the Frontier Governance Framework, which explains how OpenAI’s safety policies map to legal obligations, including those outlined in the EU’s GPAI Code.
Together, these frameworks cover areas such as risk management, security controls, incident response, external expert involvement, and transparency reporting.
Industry collaboration
OpenAI says its compliance efforts extend beyond its own organization through partnerships with several industry groups and research initiatives.
The company participates in the Frontier Model Forum and works alongside organizations including the U.S. Center for AI Standards and Innovation and the UK AI Security Institute. According to OpenAI, these collaborations help establish shared evaluation methods, improve safety research, and encourage consistent testing standards across the AI industry.
Improving AI content transparency
A major focus of the EU’s transparency requirements is helping users determine whether digital content has been generated or modified by artificial intelligence.
OpenAI currently relies on two primary technologies to address this challenge. The first is Content Credentials, based on the C2PA standard, which embeds metadata directly into supported files. The second is SynthID watermarking, providing an additional signal when metadata may be removed as content moves between different platforms.
The company is expanding these transparency tools beyond images to include audio and is exploring broader support across additional content formats, including text, as industry standards continue to evolve.
OpenAI acknowledges that no single technology can fully solve the problem of AI content provenance. Metadata can be stripped, watermarks are not always preserved, and different platforms handle files differently. Instead, the company advocates for multiple complementary technologies combined with continued industry collaboration.
Cybersecurity initiatives
OpenAI also addressed how advanced AI capabilities can be used responsibly within cybersecurity.
The company says its Trusted Access for Cyber program is designed to provide qualified cybersecurity professionals with access to more advanced AI capabilities while reducing opportunities for misuse.
To support European organizations, OpenAI has expanded the initiative through its EU Cyber Action Plan, working with European institutions, national cybersecurity agencies, infrastructure operators, and private-sector partners. The objective is to strengthen cyber defenses by giving trusted organizations access to advanced AI tools for vulnerability detection and defensive operations.
OpenAI says this approach aligns with the European Commission’s broader strategy for combining AI innovation with stronger cybersecurity protections.
Compliance will continue evolving
As implementation of the EU AI Act progresses, OpenAI expects its compliance practices to evolve alongside new regulatory guidance and industry feedback.
The company argues that effective AI regulation should remain adaptable as technology advances, allowing organizations to continue innovating while maintaining appropriate safeguards.
Although the GPAI Code and Transparency Code establish important expectations for AI developers, OpenAI notes that its published documentation—including system cards and governance frameworks—should serve as a foundation rather than a complete compliance solution. Organizations deploying AI systems within regulated European markets will still need to conduct their own assessments and ensure they meet applicable legal requirements.


