The EU AI Act Shapes OpenAI’s Governance

OpenAI outlines how the EU AI Act is shaping its governance, from model safety and cybersecurity to transparency and content provenance.

OpenAI has outlined the measures it has taken to align its practices with the European regulatory framework, focusing on safety, security, transparency, and content provenance. The company says it has endorsed both the European Union’s General-Purpose AI Code of Practice and its Code of Practice on the Transparency of AI-Generated Content.

This approach is based in particular on its Preparedness Framework, system cards, public Model Spec, and network of external red-teaming experts. A governance framework dedicated to advanced models connects these practices to the regulation’s requirements, with procedures covering risk assessment, safeguards, security, incident response, and updates.

For generated content, OpenAI combines Content Credentials based on the C2PA standard with SynthID watermarks. The former attach provenance information to files, while the latter are designed to preserve a signal when metadata is removed. The system already covers images and is expected to expand to audio, followed gradually by other modalities, including text.

Cybersecurity is another component of this policy. Through its Trusted Access for Cybersecurity program, OpenAI restricts certain advanced capabilities to actors it considers legitimate. The company also says it is working with European agencies, private-sector partners, and critical infrastructure operators to strengthen the defensive use of its models.

Resources will also be provided to help businesses and developers comply with the EU regulation, including model documentation, system cards, usage policies, and provenance tools.