OpenAI is proactively addressing the impending enforcement of the EU AI Act by detailing how its existing safety, security, and transparency initiatives align with the principles of the General-Purpose AI (GPAI) Code of Practice. The company has not only endorsed but also actively contributed to this crucial EU framework, alongside the Code of Practice on Transparency of AI-Generated Content. Both codes stem from extensive multi-stakeholder dialogues, underscoring a broad consensus on the need for responsible AI development.
The GPAI Code establishes a foundational standard for transparency, safety, and security concerning general-purpose AI models deployed or offered within the European Union. OpenAI highlights its established practices as evidence of its commitment to meeting this standard. These include rigorous pre-release model testing, the provision of detailed system cards with major model launches, and extensive external “red-teaming” through its dedicated Red Teaming Network. Furthermore, the company maintains a publicly accessible Model Specification document, which clearly outlines the methodologies employed to shape model behavior and ensure alignment with safety objectives.
Underpinning these external-facing efforts are two robust internal frameworks. The Preparedness Framework, first introduced in 2023 and updated in 2025, provides a structured approach to identifying, evaluating, and mitigating potential serious risks associated with advanced AI systems. Building upon this, the Frontier Governance Framework further elaborates on how OpenAI’s comprehensive safety and security protocols are mapped against specific legal and regulatory requirements, including those stipulated by the GPAI Code. Collectively, these internal frameworks govern critical areas such as risk assessment, the implementation of safeguards, model reporting mechanisms, security posture management, incident response protocols, and the integration of external expert input into the development lifecycle.
OpenAI’s commitment to industry-wide safety is further exemplified by its active participation in the Frontier Model Forum. This collaboration, alongside partnerships with the U.S. Center for AI Standards and Innovation and the U.K. AI Security Institute, reflects a broader dedication to fostering shared safety research and establishing clearer, industry-wide testing benchmarks. This cooperative approach extends to contributions to third-party evaluation standards, aiming to advance responsible AI development beyond the confines of a single organization.
### The Growing Challenge of Provenance in Multimodal AI
The Transparency Code addresses a distinct, yet equally critical, challenge: enabling users to discern AI-generated or AI-modified content. OpenAI’s strategy relies on a dual-pronged approach designed for mutual reinforcement. Content Credentials, built upon the C2PA standard, embed contextual information directly within digital files. As a complementary measure, SynthID watermarking offers a resilient fallback signal, designed to persist even when original metadata is inadvertently removed during content transmission or manipulation.
While currently focusing on image and audio outputs, OpenAI is actively working to extend these provenance measures across further modalities, including text, as underlying standards and tooling mature. The company is also developing specific signals and guidance for developers, empowering them to meet their own transparency obligations when building applications on top of OpenAI’s foundational models.
It’s important to acknowledge that achieving foolproof provenance remains a complex endeavor. Metadata can be lost, and content labels may not survive transfers across different platforms. No single mechanism, whether cryptographic or watermark-based, can independently guarantee complete traceability. OpenAI’s approach emphasizes a layered strategy, combined with ongoing collaboration within the broader standards community, rather than asserting that any single solution provides an absolute guarantee.
### Cybersecurity: A Proving Ground for Adaptive Governance
The development of AI capabilities that enhance vulnerability detection and patching for defenders inherently presents a dual-use challenge, as these same capabilities could potentially be exploited by attackers. OpenAI’s Trusted Access for Cyber program aims to mitigate this risk by providing vetted cybersecurity professionals with access to advanced cyber capabilities while simultaneously imposing strict limitations to prevent misuse.
This initiative has now established a significant European presence with the launch of OpenAI’s EU Cyber Action Plan in early May 2026. This plan involves close collaboration with EU and national cybersecurity agencies, private sector partners, and critical infrastructure operators, granting them access to OpenAI’s more advanced cyber models. The stated objective is to bolster cyber resilience across the continent. While OpenAI asserts that its “most advanced” models deliver measurable defensive gains for these agencies, independent verification of the program’s outcomes remains an area for continued observation.
This work is positioned as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which advocates for a coordinated approach to managing AI’s inherent risks while simultaneously leveraging its potential to strengthen defensive capabilities, including the establishment of secure access arrangements specifically for cybersecurity purposes.
OpenAI has committed to continuously adapting its compliance strategies as the EU AI Act’s implementation progresses. The company anticipates ongoing learning from regulators and the broader ecosystem involved in shaping these crucial rules. A key argument put forth by OpenAI is the necessity for regulatory frameworks to possess sufficient flexibility to evolve alongside the rapidly advancing technology, ensuring that businesses and organizations can continue to harness its benefits responsibly.
The GPAI Code and the Transparency Code represent nascent regulatory instruments. OpenAI’s compliance documentation is therefore a dynamic and evolving document. For organizations developing solutions on OpenAI’s models within regulated European markets, current system cards and the Frontier Governance Framework should be viewed as essential starting points for their own due diligence processes, rather than as definitive substitutes for comprehensive risk assessment.
Original article, Author: Samuel Thompson. If you wish to reprint this article, please indicate the source:https://aicnbc.com/24315.html