|

OpenAI aligns safety practices with EU AI Act’s GPAI Code

Banner for the AI & Big Data Expo event series.

OpenAI has outlined the way it aligns safety, safety, and transparency work with the EU AI Act’s GPAI Code as enforcement approaches.

The firm has contributed to and endorsed the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Both emerged from multi-stakeholder processes.

The GPAI Code units a shared bar for transparency, safety, and safety throughout general-purpose fashions offered or deployed within the EU. OpenAI factors to a stack of present practices as proof it already operates close to that bar: pre-release testing of fashions, revealed system playing cards accompanying main launches, and outdoors red-teaming by what it calls its Red Teaming Network. The firm additionally maintains a public Model Spec doc describing the way it shapes mannequin behaviour.

Two inner frameworks sit beneath that work. The Preparedness Framework has been in place since 2023 and was up to date in 2025; it units out how OpenAI identifies, evaluates and manages critical dangers from superior methods. A separate Frontier Governance Framework builds on it, explaining how the corporate’s safety and safety practices map onto authorized necessities together with the GPAI Code particularly. 

Together, OpenAI says, these two paperwork govern threat evaluation, safeguards, mannequin reporting, safety posture, incident response, and the way exterior consultants get pulled into the method.

OpenAI cites its participation within the Frontier Model Forum alongside collaborations with the US Center for AI Standards and Innovation and the UK AI Security Institute, plus contributions to third-party analysis requirements extra broadly. The said purpose is shared safety analysis and clearer testing benchmarks throughout the business, not simply inside one firm’s partitions.

Provenance will get more durable as modalities multiply

The Transparency Code commitments centre on a special downside: serving to folks inform when content material was made or altered by AI.

OpenAI’s method rests on two mechanisms that are supposed to reinforce one another. Content Credentials, built on the C2PA standard, connect context on to a file. SynthID watermarking gives a fallback sign for instances the place that metadata will get stripped out someplace alongside the best way.

Coverage is increasing from pictures into audio outputs, and OpenAI says it’s working towards extending provenance measures throughout additional modalities, together with textual content, because the underlying requirements and tooling mature. The firm can also be constructing alerts and steering aimed toward builders who want to satisfy their very own transparency obligations when constructing on high of its fashions.

None of this solves provenance outright. Metadata will get misplaced and labels don’t at all times survive a switch between platforms. No single sign, whether or not cryptographic or watermark-based, catches every part by itself. OpenAI’s response is a layered method paired with continued work throughout the broader requirements group moderately than a declare that anybody mechanism closes the hole.

Cybersecurity because the check case for adaptive governance

Capabilities that help defenders spot and patch vulnerabilities are the identical capabilities that might assist an attacker discover them first. OpenAI believes the reply is its Trusted Access for Cyber programme, designed to offer vetted defenders entry to extra superior cyber capabilities whereas limiting publicity for misuse.

That programme now has a European deployment arm. OpenAI states it launched its EU Cyber Action Plan in early May 2026, working with EU and nationwide cyber businesses, non-public sector companions, and infrastructure operators to offer them entry to its extra superior cyber fashions.

The said purpose of the plan is to strengthen cyber resilience throughout the continent. Whether “most superior” interprets into measurable defensive good points inside these businesses is a declare from OpenAI itself; the supply materials gives no unbiased verification of outcomes from the programme.

The firm positions this work as constant with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which requires coordinated dealing with of AI’s dangers alongside its use in strengthening defensive functionality, together with safe entry preparations for cybersecurity functions particularly.

OpenAI says it’ll preserve adjusting its compliance method as EU AI Act implementation continues, and that it expects to continue learning from regulators and the broader group concerned in shaping the principles. The firm argues that guidelines want sufficient flexibility to adapt because the expertise strikes, so that companies and organisations can preserve benefiting from it.

The GPAI Code and the Transparency Code are nonetheless comparatively new devices, and OpenAI’s compliance documentation is a transferring goal moderately than a completed product. Teams constructing on OpenAI’s fashions in regulated European markets ought to deal with the present system playing cards and Frontier Governance Framework as a place to begin for their very own due diligence, not an alternative to it.

See additionally: Zuckerberg details Meta’s personal AI superintelligence strategy

Banner for the AI & Big Data Expo event series.

Want to study extra about AI and massive information from business leaders? Check out AI & Big Data Expo going down in Amsterdam, California, and London. The complete occasion is a part of TechEx and is co-located with different main expertise occasions together with the Cyber Security & Cloud Expo. Click here for extra info.

AI News is powered by TechForge Media. Explore different upcoming enterprise expertise occasions and webinars here.

The put up OpenAI aligns safety practices with EU AI Act’s GPAI Code appeared first on AI News.

Similar Posts