
OpenAI details EU AI Act compliance with safety and transparency frameworks

OpenAI has published a blog post outlining how its responsible AI practices align with the EU AI Act as it enters its next phase. The post details the company’s governance frameworks, safety practices, and transparency measures, emphasizing a pragmatic and risk-based approach to regulation.
The company states its mission is to ensure artificial general intelligence benefits all humanity, which includes maximizing benefits, broadening access, and managing risks. It contributed to the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content.
For safety and security, OpenAI uses internal governance and external collaboration. This includes testing models before release, publishing system cards, a Red Teaming Network, and a public Model Spec. They have established a Preparedness Framework (updated in 2025) to identify and manage serious risks, and a Frontier Governance Framework to align practices with legal requirements like the EU AI Act. Collaboration happens through the Frontier Model Forum and partnerships with US and UK AI safety institutes.
On transparency, OpenAI supports the Code of Practice on Transparency of AI-Generated Content. Its provenance approach uses Content Credentials (C2PA) and SynthID watermarks for images and audio, and aims to expand these to other modalities like text as standards mature. They acknowledge that metadata can be lost and labels can fail, so a layered approach is needed.
Cybersecurity is highlighted as an area needing dynamic governance. OpenAI balances helping defenders with reducing misuse through its Trusted Access for Cyber (TAC) program. Since May 2026, its EU Cyber Action Plan has worked with EU agencies and partners to strengthen cyber resilience, aligning with the European Commission’s cybersecurity action plan.
OpenAI commits to continuously strengthening its compliance approach as the EU AI Act is implemented, providing resources like model documentation and usage policies for customers and developers.


