OpenAI details its EU AI Act compliance approach

OpenAI has published a post describing how it is adapting its governance practices to the EU AI Act as the regulation moves into its next implementation phase. The company says it contributed to and endorsed two EU Codes of Practice: the General Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI Generated Content, both produced through multi stakeholder processes. On the safety side, OpenAI points to its Preparedness Framework, in place since 2023 and updated in 2025, which sets out how it identifies, evaluates and manages serious risks from advanced AI systems, and to its newer Frontier Governance Framework, which it says explains how its safety and security practices line up with the GPAI Code's legal requirements. OpenAI also cites external oversight and collaboration mechanisms it takes part in, including its Red Teaming Network, the Frontier Model Forum, and work with the US Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (AISI). On provenance, the company describes a two part system: Content Credentials based on the C2PA standard, which attach context to content as metadata, and SynthID watermarks, which it says preserve a signal even when metadata is stripped out. That provenance work currently covers images and is being extended to audio, with text coverage described as a future goal as standards mature. OpenAI acknowledges the limits of the approach, noting that metadata can be lost and labels can fail to survive across platforms, which is why it says it favors a layered, ecosystem wide approach rather than a single fix. On cybersecurity, OpenAI describes its Trusted Access for Cyber (TAC) program, intended to let legitimate defenders use its models while limiting misuse. It says that since launching the OpenAI EU Cyber Action Plan in early May 2026, it has worked with EU and national cyber agencies, private sector partners and critical infrastructure operators to give them access to its cyber focused models, and frames this as aligned with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence. The post does not name any of the specific partners or agencies involved, nor does it give figures for how many organizations have joined the program. OpenAI closes by saying it will keep updating its compliance resources, including model documentation, system cards, safety information, usage policies and provenance guidance, as the EU AI Act's implementation continues, and argues that rules need to stay pragmatic, proportionate and risk based to let people and businesses benefit from AI.
Key facts
- OpenAI endorsed the EU's GPAI Code of Practice and the Code of Practice on Transparency of AI Generated Content as part of aligning with the EU AI Act.
- Its Preparedness Framework has been in place since 2023 and was updated in 2025; a newer Frontier Governance Framework maps safety practices to the GPAI Code's legal requirements.
- Provenance work rests on two systems, C2PA based Content Credentials and SynthID watermarks, currently covering images and being extended to audio.
- Since launching the OpenAI EU Cyber Action Plan in early May 2026, OpenAI has worked with EU and national cyber agencies, private sector partners and critical infrastructure operators through its Trusted Access for Cyber program.
- No individual partners, agencies or participation figures for the Cyber Action Plan are disclosed in the post.
Why it matters
The EU AI Act is moving into a new implementation phase, and how a major model provider like OpenAI positions itself on compliance sets a reference point other companies operating in Europe will be compared against. The post signals that OpenAI wants to be seen as a cooperative participant in shaping how the law's general purpose AI rules get applied in practice, rather than simply reacting to enforcement.
Who it affects
The post targets European businesses, governments, and individual users of OpenAI's tools, along with regulators and the national cyber agencies OpenAI says it is working with under its EU Cyber Action Plan. It also speaks to developers building on OpenAI's models who need to meet their own transparency obligations under the Act.
How to use it
OpenAI points readers to its Help Center article on the EU AI Act for practical resources: model documentation, system cards, safety information, usage policies, and guidance on provenance and verification tools. Businesses building on OpenAI's models can use Content Credentials and SynthID signals as part of meeting their own AI content transparency obligations.
How solid is it
The claims come directly from OpenAI's own blog post, which is a company statement about its own compliance posture rather than an independent assessment. It names the frameworks, codes and dates involved but gives no figures on users, partners, or program participation in Europe, and does not name any of the private sector partners or critical infrastructure operators referenced.
Risks and caveats
This is self reported positioning from the company being regulated, not third party verification that its practices actually satisfy EU AI Act requirements. OpenAI itself flags that provenance signals are imperfect: metadata can be lost and labels can fail to survive across platforms, so watermarking and content credentials do not guarantee traceability. The Cyber Action Plan's real reach is hard to judge without named partners or participation numbers.
“Such rules must be pragmatic, proportionate and risk-based in order to advance governance while supporting innovation.”
— OpenAI