OpenAI says millions of Europeans use its tools daily for learning, creating, working and managing routine tasks. The company also states that its products support businesses of all sizes and government bodies across the region, and that responsible AI can contribute to Europe’s competitiveness and prosperity.
As implementation of the EU AI Act moves forward, OpenAI announced how it has bolstered its practices around safety, security, transparency and provenance to align with the EU framework, and committed to continuing to evolve those practices as AI advances.
Codes of practice and internal governance
OpenAI frames its activity around a stated mission to ensure artificial general intelligence benefits all humanity, a mandate it says carries ongoing responsibilities to maximize benefits, broaden access and manage risks. The company argues that workable rules should be pragmatic, proportionate and risk-based to advance governance while supporting innovation.
To that end, OpenAI contributed to and endorsed two EU-related Codes of Practice: the General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. According to the company, both codes were developed through broad multi-stakeholder processes and build on OpenAI’s work in safety, security, transparency, accountability and provenance.
The GPAI Code provides a shared framework for transparency, safety and security for general-purpose models. OpenAI supports that framework through internal governance and external collaboration: it says it has long carried out extensive pre-release testing of its models, published system cards for major releases, invited outside experts to test models via its Red Teaming Network, and maintained a public Model Spec to offer insight into how it shapes model behaviour.
Risk-management frameworks
OpenAI has strengthened the governance frameworks that underpin this work. The Preparedness Framework has been in place since 2023 and was updated in 2025; it sets out how OpenAI identifies, evaluates and manages serious risks from advanced AI systems. Built on that foundation, the Frontier Governance Framework explains how the company’s safety and security practices align with emerging legal requirements, including the EU AI Act’s GPAI Code. Together, these frameworks guide practical decisions on risk assessment, safeguards, model reporting, security, incident response, external expert input and ongoing updates.
Ecosystem-level cooperation
The company stresses that responsible AI governance requires activity beyond any single organisation. OpenAI participates in the Frontier Model Forum, collaborates with US CAISI and UK AISI initiatives, and works on third-party evaluation practices to support shared safety research, external testing and clearer evaluation standards across the ecosystem.
Provenance and transparency for AI-generated content
OpenAI supports the Code of Practice on Transparency of AI-Generated Content and points to years of research and product work to improve provenance for AI media. It says users should have better context about online content, including whether it was created or edited with AI.
OpenAI’s approach to provenance relies on two reinforcing systems: Content Credentials (C2PA), which attach detailed contextual metadata to content, and SynthID watermarks, which preserve a signal when metadata does not survive. The company is extending this work to include audio outputs in addition to images, and says it plans to expand provenance measures across modalities, including text, as standards and tooling mature. OpenAI acknowledges that provenance remains an evolving field—metadata can be lost, labels may not travel across platforms and no single signal is perfect—so it supports a layered approach and continued cooperation across the ecosystem.
Cybersecurity and Trusted Access for Cyber (TAC)
OpenAI highlights that cybersecurity is an area where dynamic and practical governance is particularly important: capabilities that help defenders can also be misused. To balance these tensions, the company seeks to reduce misuse while enabling legitimate defenders to use AI via its Trusted Access for Cyber (TAC) programme, with the goal of strengthening collective resilience.
OpenAI also reports concrete activity in Europe: since launching the OpenAI EU Cyber Action Plan in early May 2026, the company says it has worked with EU and national cyber agencies, private-sector partners and critical infrastructure operators to equip them with advanced cyber models and strengthen cyber resilience across the continent. OpenAI positions this work as aligned with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated approaches to address advanced AI risks while leveraging AI to bolster cyber resilience.
Compliance support and customer resources
As the EU AI Act is implemented, OpenAI says it will continue to strengthen its compliance approach and learn from regulators and the broader ecosystem. The company argues that rules must remain flexible enough to adapt as technology advances, enabling people, businesses and organisations to benefit.
To assist customers and developers preparing for the EU AI Act, OpenAI provides practical resources such as model documentation, system cards, safety information, usage policies and guidance on provenance and verification tools. It says these resources will be updated as implementation evolves and points readers to its Help Center for more information on OpenAI’s approach to the EU AI Act and customer guidance.
Summary
OpenAI describes a set of internal and external measures designed to align its systems with the EU AI Act and associated codes of practice. The company emphasises its risk-management frameworks, provenance and transparency tools, cybersecurity collaborations, and a commitment to ongoing updates to documentation and guidance for customers.



