BIP America

collapse
Home / Daily News Analysis / OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI aligns safety practices with EU AI Act’s GPAI Code

Aug 02, 2026  Twila Rosenbaum  8 views
OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI has moved to align its internal safety and governance practices with the European Union’s Artificial Intelligence Act, specifically with the Code of Practice for General-Purpose AI. This strategic decision signals the company’s intention to meet regulatory expectations in the EU while maintaining its leading position in the race toward advanced AI systems. By publishing a clear commitment to the GPAI Code’s principles, OpenAI is acknowledging that large-scale AI development carries responsibilities beyond technical performance.

The EU AI Act, which entered into force in August 2024, introduced a risk-based framework for regulating AI systems across member states. General-purpose AI models—those capable of performing a wide variety of tasks, such as large language models and multimodal systems—are subject to a distinct set of obligations under the Act. The GPAI Code of Practice, developed by the EU AI Office with input from independent experts, industry stakeholders, and academia, provides concrete guidance for demonstrating compliance with these obligations. OpenAI’s alignment with this code is not merely a formality; it represents a deliberate effort to shape the emerging regulatory landscape and to set an example for other developers.

What the GPAI Code Requires

Under the EU AI Act, providers of general-purpose AI models must comply with several core requirements. These include providing technical documentation, drafting instructions for downstream use, and establishing a copyright compliance policy. For models with systemic risk—defined by high cumulative compute and impact—the obligations are more stringent. Providers must carry out model evaluations, engage in adversarial testing, track and report serious incidents, and ensure adequate cybersecurity protections.

The GPAI Code of Practice translates these statutory requirements into a structured framework. It is divided into several pillars: transparency and copyright, risk assessment and mitigation, and internal governance. Each pillar contains detailed commitments that signatories are expected to implement. OpenAI’s announcement focuses on adopting these commitments across its model development lifecycle, from initial research to post-deployment monitoring.

OpenAI’s Voluntary Commitments

OpenAI has stated that it will incorporate the GPAI Code’s principles into its existing safety framework. This includes publishing comprehensive model documentation that goes beyond basic technical reports. The company already produces model cards, system cards, and safety evaluations for its frontier models. Under the new alignment, these documents will be structured to align with the EU’s expectations for technical documentation and systemic risk assessment.

One notable area is the approach to systemic risk. OpenAI has developed internal risk matrices to gauge potential harms from its models, including cyber capabilities, chemical or biological threats, and persuasive manipulation. The GPAI Code asks providers to assess these risks with the same rigor as high-stakes sectors. OpenAI’s alignment means it will actively use the severity categories and mitigation protocols laid out in the code, rather than relying solely on its own internal metrics. This is expected to produce a more uniform comparison across different AI providers.

Transparency and Copyright Considerations

The GPAI Code emphasizes transparency in a direct and practical way. It requires providers to make publicly available a summary of the data used for training, especially for copyrighted material. OpenAI has previously been criticized for not being sufficiently open about its training datasets. Aligning with the EU code will likely force the company to enhance its documentation of data sourcing, usage, and the measures taken to respect intellectual property rights.

In response, OpenAI has indicated that it will update its data governance policies to comply with the EU’s standards. This could include more granular disclosures about the provenance of training data and the implementation of tools to allow rightsholders to exercise their rights. While the AI Act does not mandate full open-sourcing, it does require that providers have a policy to comply with copyright law. OpenAI’s commitment under the GPAI Code aims to make this policy transparent and enforceable.

Internal Governance and Oversight

Another critical aspect of the GPAI Code is internal governance. Providers are encouraged to establish a structure that ensures accountability at the highest level. OpenAI already has a Safety and Security Committee that oversees risk assessments for major releases. Under the new alignment, this committee’s role will be expanded to incorporate GPAI-specific compliance checks. The company is also expected to create formal escalation paths for systemic risks, ensuring that critical decisions are not left solely to engineering teams.

OpenAI’s move also involves routine independent audits. Although the EU AI Act does not yet require mandatory third-party audits for all GPAI providers, the code recommends regular external review. OpenAI is likely to adopt such reviews as a best practice, giving regulators and the public confidence in its voluntary alignment. This could also help the company prepare for future mandatory assessments that may come into effect once the Act is fully applied in 2026.

Industry Context and Timing

The decision to align with the GPAI Code comes at a time when major AI developers are racing to secure a competitive advantage in Europe. Microsoft, Google, Meta, and other companies have also engaged with the EU AI Office. However, OpenAI’s public announcement frames the issue in terms of safety and proactive responsibility. In doing so, it differentiates itself from firms that have sought to resist regulation. OpenAI appears to understand that being seen as a cooperative partner can ease market access and build user trust.

Moreover, the EU AI Act’s GPAI obligations apply directly to providers with a substantial user base in Europe. OpenAI’s ChatGPT and other products have a significant number of users across EU member states. The company is therefore obligated to comply with the Act regardless of its voluntary alignment. By embracing the GPAI Code early, OpenAI gains the advantage of helping to interpret and shape the code’s real-world implementation. The company is positioned to influence technical standards and best practices before the rules become more rigidly enforced.

Challenges and Ambiguities

Despite the positive framing, there are challenges. The GPAI Code is still evolving. The final text was published in the spring of 2025, but some commitments remain open to interpretation. OpenAI’s alignment may therefore require adjustments as the EU AI Office releases additional clarifications. There is also a risk that divergences between internal and external standards create bureaucratic burdens, slowing down agile development and research iterations.

Another challenge lies in measuring compliance. Systemic risk assessments, for instance, require sophisticated methodologies that are still being invented. OpenAI has published research on evaluating dangerous capabilities, but there is no universal benchmark. The GPAI Code attempts to provide a common framework, but its thresholds are not always mathematically precise. OpenAI’s safety team will have to define practical metrics that are both honest and future-proof. This is a difficult task that many other AI labs will also face.

Implications for AI Safety and Global Regulation

OpenAI aligning with the GPAI Code sends a strong signal to regulators outside Europe. Countries such as Japan, South Korea, and even the United States are developing their own AI governance frameworks. If OpenAI’s voluntary compliance with EU standards becomes a de facto global baseline, it could make the GPAI Code an international reference point. This would be consistent with the EU’s ambition to export its standards through the “Brussels effect.”

From a safety perspective, the alignment is a step toward making AI safety a measurable and auditable discipline. OpenAI has long argued that safety cannot be separated from capability development. The GPAI Code provides a concrete structure for that argument. It forces companies to document uncertainty, manage risks, and communicate with the public about the limits of their knowledge. That is a meaningful development.

OpenAI’s commitment to the GPAI Code is not a one-off announcement. It is part of a broader trend where AI developers must engage with public policy. In the coming months, OpenAI will need to show how its internal practices map onto the specific commitments of the code. The company will also need to maintain a transparent dialogue with the EU AI Office and other stakeholders. If successful, this alignment could serve as a model for responsible AI development in a regulated world.

The article above demonstrates how OpenAI’s strategic decision reflects an evolving balance between innovation and governance. The company is not simply checking boxes; it is attempting to embed regulatory values into its research and deployment culture. As the EU AI Act becomes fully enforceable, the true test will be in the details—how quickly OpenAI can adapt, how honestly it reports incidents, and how effectively it mitigates risk. Those details are still being written, but the direction is now clear.


Source: AI News News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy