- OpenAI formally endorsed the EU’s GPAI Code of Practice and Transparency Code on July 31, 2026, ahead of new enforcement powers.
- OpenAI’s EU Cyber Action Plan provides advanced AI systems to EU agencies through its Trusted Access for Cyber program.
- OpenAI aligns its safety and transparency practices with EU law through frameworks, red teaming, system cards, and a layered approach to synthetic content.
Two days before the European Commission gained enforcement powers over large general-purpose AI models, OpenAI published detailed documentation aligning its safety, security and transparency practices with EU law. The July 31, 2026 announcement covered two instruments: the EU’s General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Whether this counts as genuine regulatory leadership or well-timed compliance management depends on what the documentation actually commits the company to, and what enforcement will look like in practice.
What the GPAI Code Requires
The General-Purpose AI Code of Practice sets shared transparency, safety and security requirements for general-purpose AI model providers. For OpenAI, the operational commitments are specific. Pre-release testing is mandatory under the code, and OpenAI has pointed to its Red Teaming Network, which draws on external experts to probe model vulnerabilities and misuse pathways, as evidence of compliance. The code mandates a systematic approach to such testing, not merely ad hoc evaluation.
Continuous monitoring matters as much as pre-release checks. OpenAI publishes system cards alongside major model releases, documenting capabilities, limitations and safety features. These serve as transparency mechanisms for developers, deployers and regulators. The company also maintains a public Model Spec, which details how model behaviour is shaped and what safeguards apply. Together, these disclosures are designed to create a traceable audit record, allowing regulators to follow governance decisions across a model’s lifecycle rather than relying on point-in-time snapshots.
Synthetic Content Transparency
The Code of Practice on Transparency of AI-Generated Content addresses a distinct but related challenge: how to reliably distinguish AI-generated material from human-produced content. OpenAI’s commitment covers multiple modalities, including audio and text. The practical significance is regulatory: Article 50(2) of the EU AI Act, which establishes transparency obligations for GPAI models generating synthetic content, becomes applicable on December 2, 2026.
The technical mechanisms here typically involve embedding digital watermarks or provenance metadata in AI-generated outputs. OpenAI has not publicly detailed the specific implementations it will use across modalities. The company’s stated approach is layered, signals, tools and guidance, on the basis that no single technical solution covers every content type or deployment context. Whether that layered approach will satisfy Article 50(2) when enforcement begins is a question the Commission has not yet answered publicly.
Cybersecurity as a Live Test
OpenAI launched its EU Cyber Action Plan in early May 2026, engaging EU and national cyber agencies, private sector partners and critical infrastructure operators. The plan’s core mechanism is the Trusted Access for Cyber program, which provides secure access to advanced AI systems for defensive cybersecurity purposes. This aligns with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated mitigation of AI risks alongside investment in AI-enhanced cyber defence.
The provision of secure access to advanced AI systems for defensive cybersecurity purposes aligns with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated mitigation of AI risks alongside investment in AI-enhanced cyber defence. The dual-use tension is real.
The dual-use tension is real. Advanced AI capabilities that help defenders detect intrusions can, in other hands, assist attackers. OpenAI’s stated strategy is to minimise misuse risk while enabling legitimate defenders. How that boundary is maintained in practice, and who audits it, is precisely the kind of question the EU’s new enforcement powers are designed to answer. The cyber domain is one of the more credible early tests of whether adaptive AI governance can move faster than the threat environment.
Mapping Risk to Compliance
OpenAI’s internal governance rests on two frameworks. The Preparedness Framework, first published in 2023 and revised in 2025, documents the company’s methodology for identifying and managing serious risks from advanced AI systems before deployment. The Frontier Governance Framework builds on that foundation by explicitly connecting OpenAI’s safety practices to the GPAI Code’s legal requirements.
Four risk domains are named: cyber offense, chemical, biological, radiological and nuclear threats, harmful manipulation, and loss of human control. Each maps to specific compliance language, model reporting protocols and incident response requirements. The significance for regulators is practical: rather than assessing abstract safety claims, the Commission can work from OpenAI’s own documentation to evaluate whether internal controls match stated commitments. That structure is auditable in a way that general principles are not.
Competitive Pressure on Peers
By converting voluntary safety commitments into detailed, public compliance documentation, OpenAI sets a market expectation that other frontier model providers will find difficult to ignore. Anthropic and Google DeepMind have their own safety frameworks, but OpenAI’s explicit mapping of those frameworks to GPAI Code requirements creates a specificity benchmark. Regulators now have a reference point for what “alignment with the GPAI Code” looks like in practice, which raises the floor for everyone operating in the EU market.
Regulators now have a reference point for what “alignment with the GPAI Code” looks like in practice. The formal classification of frontier AI models as dual-use systems, subject to national security-style oversight, not just consumer product regulation, is the more significant structural shift in OpenAI’s framing.
The formal classification of frontier AI models as dual-use systems, subject to national security-style oversight, not just consumer product regulation, is the more significant structural shift in OpenAI’s framing. That classification has direct implications for how these models are developed, deployed and monitored across the EU. California’s Transparency in Frontier AI Act operates from similar assumptions, meaning companies building for both markets face a converging compliance architecture rather than two separate regimes.
The Enforcement Timeline
From August 2, 2026, the European Commission holds powers to demand information from model providers, conduct safety evaluations, order corrective measures and impose fines of up to 3% of total annual turnover. The AI Omnibus, published on July 24, 2026, refined the implementation timeline and extended the list of prohibited practices under Article 5.
The staggered deadlines matter. The GPAI Code was published on July 10, 2025, and rules on general-purpose AI models became applicable on August 2, 2025. The Article 50(2) synthetic content transparency obligations arrive December 2, 2026. Providers that placed models on the market before August 2, 2025 have until August 2, 2027 to comply fully. The early enforcement period will reveal whether the Commission treats its new powers as a genuine accountability instrument or deploys them selectively against high-profile cases, a question the AI industry is watching closely. For more on how that enforcement picture is developing, see our AI Policy & Regulation coverage.
Flexibility vs. Accountability
OpenAI has argued publicly that AI regulation must be flexible enough to adapt as the technology advances. The GPAI Code and Transparency Code are, by design, living instruments, the compliance documentation OpenAI has published is positioned as a starting point, not a settled record. That framing suits a company whose model capabilities change materially with each release cycle.
The tension this creates is genuine. Regulatory flexibility is necessary when technology moves faster than legislation can follow; it also creates space for commitments that are harder to enforce. The value of OpenAI’s detailed compliance architecture, the system cards, the Model Spec, the risk-domain mappings, depends entirely on whether regulators have the technical capacity to assess it. The Commission’s ability to evaluate frontier AI documentation is still developing, and the gap between published commitments and verified compliance is where enforcement credibility will be built or lost.
Beyond the EU
The company participates in the Frontier Model Forum and works with US and UK government AI safety bodies on shared safety research, external testing and evaluation standards.
The EU AI Act is the most detailed AI governance framework currently in force, and its GPAI Code is the first instrument of its kind to attract formal endorsement from a major frontier model provider. How the Commission exercises its enforcement powers over the next 12 months will determine whether that endorsement carries legal weight, or whether it remains, for now, a well-documented statement of intent. The approaches Meta and Microsoft are taking to the same August 2026 deadline offer a useful comparison point.



