July 31, 2026, (Inside AI) — As the European Union's AI Act enters its next implementation phase, OpenAI has detailed how it is aligning its safety, security, and transparency practices with the bloc's new regulatory framework. The company announced its endorsement of two key EU codes of practice and outlined updates to its internal governance structures.
OpenAI's mission to ensure artificial general intelligence benefits all of humanity carries an ongoing responsibility to maximize benefits, broaden access, and manage risks. The company has endorsed the EU's General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content, both developed through extensive multi-stakeholder processes.
The GPAI Code creates a shared framework for transparency, safety, and security for general-purpose AI models. OpenAI's support rests on internal governance and collaboration with external experts, governments, and peer organizations. The company has extensively tested models prior to release, published system cards with major releases, and maintained the public Model Spec as a window into how it shapes model behavior.
OpenAI has strengthened the governance frameworks behind this work. Its Preparedness Framework, in place since 2023 and updated in 2025, sets out how it identifies, evaluates, and manages serious risks from advanced AI systems. The Frontier Governance Framework explains how safety and security practices align with emerging legal requirements, including the EU AI Act's GPAI Code.
Provenance Push Expands to Audio and Text
OpenAI's support for the Code of Practice on Transparency of AI-Generated Content builds on years of research into provenance for AI-generated media. The company's approach relies on two reinforcing systems: Content Credentials (C2PA) help content carry detailed context, while SynthID watermarks preserve a signal when metadata does not survive.
The company is expanding provenance measures to include audio outputs in addition to images. Consistent with commitments under the Code, OpenAI is working to expand provenance measures across modalities, including text, as standards and tooling mature. Provenance remains an evolving field: metadata can be lost, labels can fail to travel across platforms, and no single signal is perfect.
OpenAI aims to support customers and developers building with its models by providing signals, tools, and guidance they can use in meeting their own transparency obligations. The company supports a layered approach and continued cooperation across the wider ecosystem.
Cyber Defense Program Aligns with EU Strategy
Cybersecurity is one area where dynamic and practical governance is especially important. The same capabilities that can help defenders identify and remediate vulnerabilities can also create new misuse risks. OpenAI's approach is to reduce misuse while helping legitimate defenders use AI through its Trusted Access for Cyber (TAC) program, in order to strengthen collective resilience.
Since launching the OpenAI EU Cyber Action Plan in early May 2026, the company has worked with EU and national cyber agencies, private sector partners, and critical infrastructure operators to equip them with the most advanced cyber models. This approach aligns with the European Commission's Action Plan on Cybersecurity and Artificial Intelligence, which calls for a coordinated approach to address risks of advanced AI while harnessing its potential to strengthen cyber resilience.
OpenAI's Preparedness Framework and Frontier Governance Framework help translate responsible AI principles into practical decisions about risk assessment, safeguards, model reporting, security, incident response, external expert input, and ongoing updates. The company has also supported shared safety research through the Frontier Model Forum and collaborations with US CAISI and UK AISI.
As implementation of the EU AI Act continues, OpenAI will keep strengthening its compliance approach and learning from regulators and the broader ecosystem. To support customers and developers preparing for the Act's implementation, the company provides practical resources including model documentation, system cards, safety information, usage policies, and guidance on provenance and verification tools.