OpenAI has outlined its compliance with the EU's General-Purpose AI (GPAI) and Transparency codes, detailing internal frameworks and new cybersecurity initiatives for the European market.

Key facts
- •OpenAI has endorsed both the GPAI Code of Practice and the Code of Practice on Transparency of AI-Generated Content.
- •The company's Preparedness Framework for managing risks from advanced systems has been in place since 2023.
- •OpenAI utilizes the C2PA standard and SynthID watermarking to help identify AI-generated or altered content.
- •The EU Cyber Action Plan was launched in early May 2026 to assist European cyber agencies.
- •OpenAI participates in the Frontier Model Forum and collaborates with the UK AI Security Institute.
OpenAI has announced its alignment with the EU AI Act’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. The company states that its existing safety, security, and transparency measures, including internal risk frameworks and provenance tools, are designed to meet these new regulatory standards as enforcement begins.
Internal Risk and Governance Frameworks
OpenAI manages risk through two primary internal documents: the Preparedness Framework, updated in 2025, and the Frontier Governance Framework. These documents govern the company's approach to risk assessment, incident response, and the integration of external experts. The company also utilizes pre-release model testing, system cards, and its Red Teaming Network to maintain safety standards.
Transparency and Content Provenance
To address AI-generated content transparency, OpenAI employs a layered approach using C2PA-based Content Credentials and SynthID watermarking. While currently focused on images and audio, the company is working to extend these provenance measures to other modalities, including text. OpenAI acknowledges that metadata can be lost during transfers and that no single signal is sufficient to identify all AI-generated content.
Cybersecurity Initiatives in the EU
In May 2026, OpenAI launched its EU Cyber Action Plan to provide vetted cyber agencies and infrastructure operators with access to its advanced cyber models. This program, part of its Trusted Access for Cyber initiative, aims to strengthen European cyber resilience. The company positions this effort as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence.
Timeline
- 2023OpenAI implemented its initial Preparedness Framework.
- 2025OpenAI updated its Preparedness Framework.
- Early May 2026OpenAI launched its EU Cyber Action Plan.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by Artificial Intelligence News.

