OpenAI has provided new details on how its existing safety, security, and transparency measures align with the European Union’s General-Purpose AI (GPAI) Code of Practice as the implementation of the EU AI Act moves closer to enforcement.
The AI company stated that it actively contributed to and endorsed both the EU’s GPAI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. These frameworks were developed through multi-stakeholder discussions involving industry participants, policymakers, researchers, and other stakeholders.
As AI regulation becomes a central issue across Europe, OpenAI says many of its current governance and safety initiatives already support the standards outlined in the GPAI framework. The company highlighted a range of established practices designed to improve transparency, manage risks, and strengthen security around advanced AI systems deployed within the European market.
OpenAI Highlights Existing Safety and Transparency Measures
The GPAI Code establishes common expectations for transparency, security, and safety among providers of general-purpose AI systems operating in the European Union. According to OpenAI, several of its existing procedures already reflect these requirements.
Among the measures cited by the company are comprehensive pre-release model testing, publication of system cards accompanying major model launches, and independent red-teaming exercises conducted through its Red Teaming Network. These activities are intended to identify vulnerabilities, evaluate risks, and improve model reliability before wider deployment.
OpenAI also pointed to its publicly available Model Spec, a document that outlines the principles used to shape model behavior and guide AI responses. The company considers this documentation an important part of its transparency strategy.
Preparedness Framework and Frontier Governance Framework
At the core of OpenAI’s safety structure are two internal governance systems that guide risk management and regulatory compliance.
The first is the Preparedness Framework, originally introduced in 2023 and updated in 2025. This framework outlines how OpenAI identifies, assesses, and mitigates significant risks associated with increasingly advanced AI models.
Complementing this is the Frontier Governance Framework, which expands upon the Preparedness Framework and explains how OpenAI’s safety, security, and governance practices correspond with legal obligations, including those outlined in the EU’s GPAI Code.
Together, these frameworks serve as the foundation for the company’s approach to:
- Risk assessment and monitoring
- Implementation of safety safeguards
- Model documentation and reporting
- Security management
- Incident response procedures
- Engagement with independent experts and researchers
OpenAI says these structures help ensure that safety considerations remain integrated throughout the development and deployment lifecycle of advanced AI systems.
Industry Collaboration Remains a Key Part of AI Safety Efforts
Beyond its internal governance systems, OpenAI emphasized the importance of collaboration across the broader AI ecosystem.
The company referenced its participation in the Frontier Model Forum, an industry initiative focused on advancing AI safety research and establishing best practices for frontier AI systems.
OpenAI also highlighted ongoing collaboration with the US Center for AI Standards and Innovation and the UK AI Security Institute. In addition, the company has contributed to the development of third-party AI evaluation standards designed to create more consistent testing benchmarks across the industry.
According to OpenAI, these partnerships are intended to support shared research, improve risk assessment methodologies, and encourage greater alignment around AI safety practices globally.
Addressing Transparency Challenges in AI-Generated Content
A separate area of focus involves compliance with the EU’s Transparency Code, which aims to help users identify when content has been created or modified using artificial intelligence.
OpenAI explained that its transparency strategy relies on a layered approach using multiple technologies rather than a single solution.
One component is Content Credentials, based on the Coalition for Content Provenance and Authenticity (C2PA) standard. This technology attaches contextual information directly to digital files, helping users verify the origin and history of content.
To complement this system, OpenAI also uses SynthID watermarking technology. Watermarking serves as an additional signal that may help identify AI-generated content when metadata is removed or lost during file sharing and distribution.
The company noted that transparency coverage is expanding beyond images and increasingly includes audio outputs. OpenAI is also exploring ways to extend provenance and authenticity measures across additional content types, including text, as industry standards and supporting technologies continue to evolve.
In parallel, the company is developing tools, guidance, and signals designed to help developers comply with their own transparency obligations when building applications on top of OpenAI models.
Provenance Challenges Continue Across Digital Platforms
Despite these efforts, OpenAI acknowledged that content provenance remains a complex challenge.
Metadata can be removed as files move between platforms, while labels and identifiers may not always survive transfers. Similarly, neither watermarking nor cryptographic verification methods provide complete coverage on their own.
Because of these limitations, OpenAI supports a multi-layered approach that combines different technologies and standards. The company believes ongoing collaboration with industry groups and standards organizations will be essential for improving transparency systems over time.
Rather than presenting any single technology as a complete solution, OpenAI argues that effective provenance management requires continuous development and cooperation across the broader digital ecosystem.
Cybersecurity Emerges as a Major AI Governance Test Case
Cybersecurity represents one of the most significant examples of the governance challenges created by advanced AI systems.
The same AI capabilities that can help security professionals identify vulnerabilities and strengthen defenses can also potentially be misused by malicious actors seeking to exploit weaknesses.
To address this balance, OpenAI has introduced its Trusted Access for Cyber program. The initiative is designed to provide qualified and vetted cybersecurity professionals with access to advanced cyber-related AI capabilities while reducing opportunities for misuse.
The company views this program as an example of adaptive governance, where access to powerful AI capabilities is managed according to risk levels and intended use cases.
Expansion of Cybersecurity Support Across Europe
OpenAI revealed that its cybersecurity initiatives now include a dedicated European component.
According to the company, the EU Cyber Action Plan was launched in early May 2026. Through this initiative, OpenAI is working with European Union institutions, national cybersecurity agencies, private-sector organizations, and critical infrastructure operators.
The program provides selected partners with access to advanced cyber-focused AI models that can assist in defensive cybersecurity activities.
OpenAI states that the objective is to strengthen cyber resilience throughout Europe and support organizations responsible for protecting critical systems and infrastructure.
However, the company’s statements regarding the effectiveness of these advanced capabilities remain self-reported. The available information does not include independent verification demonstrating measurable defensive outcomes resulting from the program.
Alignment With European Cybersecurity Strategy
OpenAI positions its cybersecurity initiatives as being aligned with the European Commission’s broader Action Plan on Cybersecurity and Artificial Intelligence.
That policy framework encourages a coordinated approach to managing AI-related risks while also leveraging AI technologies to improve defensive capabilities. The plan specifically supports secure access arrangements that allow cybersecurity professionals to benefit from advanced AI tools under appropriate safeguards.
By linking its Trusted Access for Cyber initiative and EU Cyber Action Plan to these objectives, OpenAI argues that its programs support both innovation and responsible risk management.
Ongoing Compliance Efforts Under the EU AI Act
As implementation of the EU AI Act continues, OpenAI says its compliance efforts will evolve alongside regulatory guidance and industry feedback.
The company expects to continue working with regulators, policymakers, researchers, and industry participants as practical interpretations of the legislation develop over time.
OpenAI maintains that AI governance frameworks should remain flexible enough to adapt to rapid technological advancements while still protecting users and addressing emerging risks.
At the same time, the company acknowledges that both the GPAI Code and Transparency Code remain relatively new regulatory instruments. As a result, compliance documentation and governance processes are likely to continue changing as implementation progresses.
For organizations developing products or services using OpenAI technologies in regulated European markets, the company recommends treating resources such as system cards and the Frontier Governance Framework as useful starting points for compliance assessments. However, these materials should not replace independent due diligence, risk evaluation, or legal review.
With AI safety regulations becoming increasingly important across Europe, OpenAI’s latest disclosures provide insight into how one of the world’s leading AI developers is preparing for a new era of regulatory oversight while continuing to refine its approach to safety, transparency, and cybersecurity governance.
Discover more from AiTechtonic - AI & Informative News
Subscribe to get the latest posts sent to your email.