OpenAI Strategy for EU AI Act Compliance and Responsible AI
OpenAI is aligning its safety, security, and transparency frameworks with the EU AI Act to ensure that general-purpose AI (GPAI) supports European competitiveness and prosperity. The company is implementing a risk-based governance approach centered on two key regulatory frameworks: the EU's General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content.
Alignment with the EU AI Act and GPAI Code
OpenAI has endorsed and contributed to the EU's General-Purpose AI (GPAI) Code of Practice to establish a shared framework for transparency and safety. This alignment is supported by several internal governance mechanisms:
- Preparedness Framework: Established in 2023 and updated in 2025, this framework identifies and manages serious risks from advanced AI systems.
- Frontier Governance Framework: This framework aligns safety and security practices with emerging legal requirements, including those specified in the GPAI Code.
- Model Transparency: OpenAI utilizes system cards for major releases, the Red Teaming Network for external expert testing, and a public Model Spec to define model behavior.
Beyond internal efforts, OpenAI collaborates with the Frontier Model Forum, US CAISI, and UK AISI to develop shared safety research and evaluation standards.
AI-Generated Content Provenance and Transparency
To meet the requirements of the Code of Practice on Transparency of AI-Generated Content, OpenAI employs a layered approach to provenance to ensure users can identify AI-generated or edited media:
- C2PA (Content Credentials): Provides detailed context and metadata for content.
- SynthID Watermarking: Preserves a signal of AI origin when metadata is removed or lost.
OpenAI is expanding these provenance measures from images to include audio outputs and is working toward expanding them to text as standards and tooling mature. The company also provides signals and tools to help developers and customers meet their own transparency obligations.
Cybersecurity Governance and the EU Cyber Action Plan
OpenAI manages the dual-use nature of AI in cybersecurity—where tools can assist both defenders and attackers—through a targeted access model.
In early May 2026, OpenAI launched the EU Cyber Action Plan. This initiative works with EU and national cyber agencies, private sector partners, and critical infrastructure operators to provide secure access to advanced cyber models. This approach is designed to strengthen collective resilience and aligns with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence.
To facilitate this, OpenAI uses the Trusted Access for Cyber (TAC) program to reduce misuse risks while enabling legitimate defenders to utilize AI capabilities.
Resources for EU Developers and Customers
OpenAI provides a suite of resources to help customers and developers navigate the implementation of the EU AI Act. These include:
- Model documentation and system cards.
- Safety information and usage policies.
- Guidance on provenance and verification tools.
OpenAI advocates for a pragmatic, proportionate, and risk-based approach to AI governance to ensure that regulations remain flexible enough to adapt as the technology evolves.