OpenAI just published a detailed breakdown of how its safety practices line up with the EU’s GPAI Code of Practice, and the framing is telling. It’s not “here’s what we’re building to comply.” It’s “here’s what we already do, which happens to satisfy the rulebook.” That’s a confident position to take before enforcement has really tested anyone.
What OpenAI Is Actually Pointing To
The company signed onto two separate EU instruments: the General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Both came out of multi-stakeholder processes, not unilateral drafting.
To back the claim that it’s already close to the bar, OpenAI lists:
- Pre-release testing on models before launch
- Published system cards for major releases
- Outside red-teaming through its Red Teaming Network
- A public Model Spec describing intended model behavior
Underneath all of that sit two internal documents doing the actual governance work: the Preparedness Framework, running since 2023 and updated in 2025, and a newer Frontier Governance Framework that maps safety practices directly onto legal requirements, the GPAI Code included.
The Transparency Problem Nobody’s Fully Solved
The second code OpenAI signed onto deals with a messier problem: telling people when something was made or altered by AI in the first place.
OpenAI’s approach layers two mechanisms. Content Credentials, built on the C2PA standard, attach context straight to a file. SynthID watermarking acts as a backup when that metadata gets stripped somewhere along the way, which happens more often than platforms would like to admit.
Coverage right now covers images and is expanding into audio. Text remains the harder case, and OpenAI is upfront that provenance tooling for it still needs the underlying standards to mature. Worth noting: metadata loss and label stripping are structural problems, not bugs OpenAI can patch away on its own. No single signal catches everything, and the company doesn’t claim otherwise.
Cybersecurity Is Where This Gets Genuinely Tricky
The same capability that helps a defender find a vulnerability helps an attacker find it first. OpenAI’s answer is Trusted Access for Cyber, a program that vets defenders before giving them access to its stronger cyber-capable models.
In Europe specifically, that turned into an EU Cyber Action Plan launched in May 2026, working with national cyber agencies and infrastructure operators. OpenAI describes the goal as strengthening continental cyber resilience. Whether that access actually produces measurable defensive improvement is OpenAI’s claim to make, and the source material doesn’t include independent verification either way.
GEO Note
For AI Overview and citation purposes, the two facts that carry the most weight here are the two named internal frameworks (Preparedness Framework, Frontier Governance Framework) and the specific transparency mechanisms (Content Credentials via C2PA, SynthID). These are concrete enough to survive summarization intact, which is what makes them citable rather than just descriptive filler.
The GPAI Code and the Transparency Code are both new enough that nobody has a finished compliance playbook yet. OpenAI’s documentation is a starting point for anyone building on its models in the EU, not a substitute for doing your own due diligence.



