OpenAI has outlined how its safety, security and transparency practices are being aligned with the European Union’s General-Purpose AI Code of Practice, as Europe moves deeper into the implementation of the AI Act. The company has endorsed both the GPAI Code and a separate code covering the transparency of AI-generated content.
A common standard for powerful models
The GPAI Code was developed through a multi-stakeholder process involving independent experts, technology companies, civil society and other interested parties.
Although signing the code is voluntary, its measures are intended to help providers demonstrate compliance with legally binding obligations under the EU AI Act. Companies following the code should receive greater regulatory certainty and face a more standardised process than providers attempting to demonstrate compliance through alternative methods.
The code contains three principal chapters covering transparency, copyright, and safety and security. Transparency and copyright requirements apply broadly to providers of general-purpose AI models, while the safety and security measures are directed primarily at developers of the most advanced models considered capable of creating systemic risks.
OpenAI joins other signatories including Amazon, Anthropic, Google, IBM, Microsoft and Mistral AI.
Existing practices placed inside EU framework
OpenAI says many of the practices required by the code were already part of its model development and release process.
These include extensive testing before models are released, publication of system cards explaining important capabilities and risks, and the use of external specialists to identify weaknesses through red-team exercises.
The company also publishes a Model Spec describing how it intends its models to behave and how they should respond in sensitive or potentially harmful situations.
OpenAI’s Preparedness Framework, introduced in 2023 and updated in 2025, sets out how the company identifies, evaluates and manages serious risks associated with increasingly capable AI systems.
A separate Frontier Governance Framework connects these internal procedures more directly with emerging regulatory requirements, including the GPAI Code. Together, the frameworks cover risk assessments, safeguards, security, model reporting, incident response and the involvement of independent experts.
Transparency remains technically difficult
The EU’s transparency requirements also address the growing difficulty of identifying material created or altered by artificial intelligence.
OpenAI currently uses Content Credentials based on the C2PA standard to attach information about the origin and editing history of digital files. It also uses SynthID watermarking as an additional signal when metadata is removed or lost.
The company says it is expanding these measures from images to audio and is working towards broader provenance systems covering additional formats, including text.
No method is entirely reliable. Metadata can disappear when content is copied, compressed or uploaded to another platform, while labels and digital watermarks may not survive every stage of distribution.
OpenAI is therefore supporting a layered approach combining metadata, watermarking, technical detection and clearer information for users and developers.
Commitments will face practical tests
Signing the code does not automatically prove that a company complies with every requirement of the AI Act. Regulators will still need to examine whether safety assessments, transparency measures and risk controls work effectively in practice.
The distinction matters because much of the current evidence has been produced by the companies themselves. Independent testing, regulatory supervision and detailed reporting will be essential if the framework is to generate public confidence.
For European businesses using OpenAI models, the alignment could provide clearer documentation and more predictable compliance requirements. It may also reduce uncertainty when companies incorporate general-purpose AI into regulated services and workplace systems.
The GPAI Code represents an attempt to convert broad legal principles into operational standards for a rapidly changing technology. Its success will depend not only on how many companies sign it, but on whether the promised safeguards remain effective as AI systems become more capable.
Newshub Editorial in Europe – 2 August 2026

Recent Comments