BIP NYC

collapse
Home / Daily News Analysis / OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI aligns safety practices with EU AI Act’s GPAI Code

Aug 03, 2026  Twila Rosenbaum  6 views
OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI has taken a significant step toward regulatory alignment by updating its safety practices to conform with the General-Purpose AI (GPAI) Code established under the European Union's Artificial Intelligence Act. The announcement signals a proactive approach to compliance as the EU's landmark regulatory framework moves into its implementation phase. By aligning with the GPAI Code, OpenAI aims to demonstrate its commitment to responsible AI development while ensuring that its flagship models meet the strict expectations of European regulators.

The EU AI Act, adopted in 2024, introduces a risk-based framework for regulating artificial intelligence. It applies to all AI systems deployed or sold within the EU, regardless of where they are developed. General-purpose AI models, which include large language models like GPT-4 and other foundation models, face specific obligations under the Act. These obligations are further elaborated in the GPAI Code of Practice, a comprehensive set of guidelines that translates the Act's principles into actionable requirements for developers and deployers.

Understanding the GPAI Code

The GPAI Code of Practice is a central component of the EU AI Act's governance structure. It was developed through a multi-stakeholder process involving AI developers, civil society organizations, and independent experts. The Code covers several critical areas, including transparency, risk management, data governance, and incident reporting. For model developers like OpenAI, complying with the Code means embedding these requirements into the entire lifecycle of an AI system, from design and training to deployment and ongoing monitoring.

One of the foundational requirements of the GPAI Code is transparency. Model providers must ensure that users and downstream developers have sufficient information to understand how a model operates, its limitations, and its potential risks. This includes publishing model documentation, also known as model cards or system cards, that describe training data, evaluation results, and intended use cases. OpenAI has already adopted system cards for its major releases, but alignment with the GPAI Code requires even more detailed and accessible information.

Another key pillar of the GPAI Code is the requirement to conduct thorough risk assessments. System providers must identify and evaluate foreseeable risks associated with their models, including those related to bias, discrimination, privacy, and misuse. For generative AI models, risks may also include the production of harmful or misleading content, facilitation of illegal activities, and the potential for large-scale disinformation. The Code mandates that these risk assessments be documented, updated regularly, and used to inform mitigation strategies.

Data governance and copyright compliance are additional areas of focus. The EU AI Act places specific obligations on developers regarding the use of training data, particularly when it involves copyrighted material. OpenAI has faced several legal challenges and public scrutiny over the use of publicly available web data in its training sets. Aligning with the GPAI Code entails implementing policies and procedures to respect intellectual property rights and to ensure that training data is sourced lawfully and ethically.

OpenAI's Safety Framework Evolution

OpenAI has long emphasized the importance of AI safety. The company has established a structured safety framework that includes pre-deployment testing, adversarial testing, and post-deployment monitoring. With the new commitment to align with the GPAI Code, OpenAI is now integrating regulatory expectations into its existing safety protocols. This evolution means that safety practices are not only driven by internal research findings but also by external legal standards and societal requirements.

One notable change involves the way OpenAI manages model risk. Previously, risk assessments were conducted primarily by internal safety teams, with results summarized in system cards and public research papers. Under the GPAI Code, these assessments will be more closely tied to specific regulatory categories and must include measurable metrics. OpenAI has introduced a risk taxonomy that maps potential harms to concrete evaluation benchmarks, allowing for more consistent and comparable risk reporting.

Incident reporting is another area where OpenAI is making significant adjustments. The GPAI Code requires providers to establish a mechanism for reporting and tracking serious incidents involving their models. These incidents might include cases where a model produces harmful content, violates privacy, or causes financial or physical harm. OpenAI has created a centralized incident management system that logs all reports, coordinates response teams, and ensures timely communication with the European Commission and national authorities when required.

Transparency documentation is being redesigned to meet the Code's specificity. OpenAI now publishes comprehensive model cards that include detailed sections on training data composition, evaluation results, known limitations, and recommended safe usage. These cards are intended to be accessible to both technical and non-technical audiences. In addition, OpenAI is providing more granular information about the system's capability in areas such as reasoning, multilingual performance, and generation of factually accurate content.

Key Facts Behind the Alignment

The alignment announcement is driven by a mix of regulatory pressure, market strategy, and ethical commitment. The EU AI Act is not just a set of recommendations; it is a binding legal instrument with substantial fines for non-compliance. Companies that fail to meet the GPAI obligations can face penalties of up to 7% of their global annual turnover. This financial risk is a powerful motivator for OpenAI and other major AI labs to ensure their practices are fully compliant before the enforcement deadlines arrive.

Timing is critical. The EU AI Act was published in the EU Official Journal in 2024, and its provisions are being phased in over a period of several years. The rules for GPAI systems are scheduled to become applicable twelve months after the Act's entry into force, which puts the compliance deadline in the first half of 2025. This gives companies like OpenAI a narrow window to complete all necessary changes to their systems, documentation, and internal governance structures.

OpenAI's alignment with the GPAI Code also reflects a strategic decision to maintain access to the European market. The EU is a substantial market for AI products and services, and non-compliance could force OpenAI to restrict its services in the bloc. By proactively aligning with the regulatory framework, OpenAI is positioning itself as a trusted partner for European enterprises and public institutions that increasingly demand compliant AI solutions.

The company also sees this alignment as a competitive advantage. As organizations and individuals become more aware of AI risks, they are more likely to choose AI providers that demonstrate strong governance and safety credentials. OpenAI's public commitment to the GPAI Code signals to its customers that it is serious about responsible AI, which could help it differentiate itself from competitors who are slower to adapt.

Broader Industry Context

OpenAI is not alone in adjusting its safety practices to align with the EU AI Act. Other leading AI developers, including Google DeepMind, Anthropic, and Meta, have also announced plans to comply with the emerging European regulations. However, the approaches vary. Some companies are focusing on technical research around interpretability and robustness, while others are investing in red-team testing and external audits. The GPAI Code encourages a mix of these methods, and the industry is still learning how to implement them in a coherent and effective way.

Civil society organizations have welcomed OpenAI's announcement but are calling for independent oversight. They argue that self-assessment alone is insufficient to ensure accountability. The GPAI Code includes provisions for external audits, and some critics want these audits to be mandatory rather than voluntary. OpenAI has expressed openness to third-party evaluations, but the operational details of such audits are still under discussion. This is a rapidly evolving area, and the final interpretation of the Code may change as enforcement begins.

In addition to regulatory alignment, OpenAI is also investing in new technical safety research that supports its compliance efforts. The company has published work on automated safety testing, adversarial robustness, and alignment with human values. These research efforts are directly relevant to the GPAI Code's requirements for rigorous testing and mitigation of systemic risks. By advancing the science of AI safety, OpenAI is not only meeting regulatory obligations but also contributing to the broader goal of safe AI development.

Implications for European AI Ecosystem

As OpenAI adjusts its practices to comply with the EU AI Act, European users, enterprises, and government agencies will see changes in how the company's models are documented and supported. For example, enterprise customers will receive more detailed transparency reports, enabling them to better assess the suitability of OpenAI models for their specific use cases. This increased clarity is expected to foster greater trust and adoption of AI technologies across regulated sectors such as finance, healthcare, and public services.

Startups and small businesses that rely on OpenAI's platforms will also benefit from higher default safety standards. Because OpenAI's core model API will incorporate many of the GPAI Code's requirements, downstream developers may face fewer burdens in their own compliance efforts. This aligns with the EU's goal of creating a harmonized digital single market where AI innovations can flourish without fragmented regulatory obstacles.

However, some legal experts have pointed out that aligning with the GPAI Code does not automatically guarantee full compliance with all EU AI Act provisions. The Act includes other obligations related to system log record keeping, cybersecurity, and fundamental rights assessments that go beyond the Code. OpenAI will need to maintain a comprehensive compliance program that addresses each of these dimensions. The company is reportedly building a dedicated regulatory affairs team to manage these tasks and to liaise with EU authorities on an ongoing basis.

The move also raises questions about the enforcement of the GPAI Code across international borders. Since OpenAI is a US-based company, the EU regulatory framework will apply to its activities within the EU. The company has stated that it will treat the GPAI Code as a global baseline for safety practices, effectively rolling out the same standards worldwide. This approach could influence other jurisdictions, such as the United States and Canada, that are considering their own AI regulations.

Future Outlook

OpenAI's alignment with the EU AI Act's GPAI Code is a milestone in the maturing relationship between AI developers and regulators. It reflects a growing recognition that voluntary safety commitments, while valuable, are not enough to ensure trust in AI at scale. Binding legal frameworks, backed by strong enforcement, are necessary to hold companies accountable. OpenAI's willingness to adapt its practices accordingly indicates that the company is evolving from a research-focused startup into a regulated global enterprise.

The coming months will reveal how well OpenAI implements its compliance roadmap. Key milestones include the publication of updated system cards for current models, the rollout of new incident reporting mechanisms, and the completion of external audits. The company has promised to publish a transparency report that provides measurable indicators of safety performance, such as the number of critical incidents and how quickly they were resolved. These metrics will be scrutinized by regulators and independent researchers.

As other AI developers follow suit, the GPAI Code is likely to become a reference point in global AI governance. The standards it sets for transparency, risk management, and incident response could be adopted or adapted by other governments. In this way, OpenAI's specific actions, while aimed at satisfying EU law, may contribute to a broader convergence of responsible AI practices around the world.

For now, the burden is on OpenAI and its peers to demonstrate that they can translate the principles of the GPAI Code into everyday engineering and operational decisions. The company is committed to meeting that challenge, but the path forward will involve continuous adjustments as new risks emerge and as the regulatory interpretation becomes clearer. Stakeholders from all sides are watching closely to see whether the balance between innovation and safety is properly struck.


Source: AI News News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy