OpenAI details how it is aligning safety and transparency practices with the EU AI Act
OpenAI published a detailed account of how it is adapting its safety, security, transparency, and provenance practices to the EU AI Act as the regulation moves into its next implementation phase, framing the post as an update on commitments it has already made rather than a new policy launch.
What's new
"As the EU AI Act enters its next phase, we're sharing how we have strengthened our approach to safety, security, transparency and provenance in line with the EU framework," OpenAI wrote, adding: "We believe responsible AI can help drive Europe's competitiveness and prosperity."
The company said it has "contributed to and endorsed" two EU-backed codes of practice: the General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Around that GPAI Code, OpenAI points to existing practices it says satisfy the framework's transparency and safety requirements: testing models before release, publishing system cards with major launches, using an external Red Teaming Network to bring in outside testers, and maintaining a public Model Spec that documents how model behavior is shaped.
Two internal governance documents sit behind that work. The Preparedness Framework, in place since 2023 and updated in 2025, "sets out how we identify, evaluate, and manage serious risks from advanced AI systems." A newer Frontier Governance Framework "explains how our safety and security practices align with emerging legal requirements, including the EU AI Act's GPAI Code." OpenAI also cites external collaboration through the Frontier Model Forum, the US Center for AI Standards and Innovation (CAISI), the UK AI Security Institute (AISI), and unspecified third-party evaluation work.
On provenance, OpenAI says its approach for AI-generated media "relies on two systems that reinforce each other: Content Credentials [C2PA] help content carry detailed context; while SynthID watermarks help preserve a signal when metadata does not survive." The company says it is "expanding that work to include audio outputs in addition to images," with text-based provenance still pending as standards mature.
On cybersecurity, OpenAI points to its Trusted Access for Cyber (TAC) program and says that since launching an "OpenAI EU Cyber Action Plan in early May 2026," it has worked with EU and national cyber agencies, private-sector partners, and critical infrastructure operators to give them access to its cyber-focused models.
Context
The post lands as the EU AI Act's obligations for general-purpose AI model providers continue to phase in, and as other labs make their own compliance moves public — Cohere, for instance, separately signed the EU's Code of Practice on Transparency of AI-Generated Content this week. OpenAI frames its post explicitly as a status update rather than a new commitment, repeatedly citing frameworks and programs that predate this announcement (the Preparedness Framework from 2023, the Cyber Action Plan from May 2026).
Why it matters
The post is a signal that frontier labs are choosing to proactively document EU AI Act compliance rather than wait for enforcement actions, given the Act's extraterritorial reach and the size of the EU market. OpenAI's provenance approach — pairing C2PA content credentials with SynthID watermarking, a technique originally developed by Google DeepMind — points to convergence around a small number of shared technical standards for labeling AI-generated content across the industry, rather than each lab building incompatible tooling. The explicit acknowledgment that "no single signal is perfect" and that a "layered approach" is needed is also a rare moment of a major lab publicly conceding the limits of current AI-content-detection tooling, rather than presenting it as solved.
Corroborating sources
- Openai
https://openai.com/index/advancing-responsible-ai-across-europe
“We believe responsible AI can help drive Europe's competitiveness and prosperity.”