Brief IA

OpenAI Aligns with the EU's GPAI Code for AI

⚖️ Regulation & Ethics·Tom Levy·

OpenAI Aligns with the EU's GPAI Code for AI

OpenAI Aligns with the EU's GPAI Code for AI
Key Takeaways
1OpenAI is adapting its security practices to comply with the EU's GPAI Code, aiming for increased transparency.
2The company is using Content Credits and SynthID watermarking to identify AI-generated content.
3A Trusted Access program for Cybersecurity is being deployed in Europe to enhance cyber resilience.
💡Why it mattersThese measures aim to align AI security with European standards while strengthening trust among users and regulators.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

OpenAI Commits to Compliance with the EU's GPAI Code

OpenAI recently detailed how it is adjusting its security and transparency practices to comply with the EU's General AI Practice Code (GPAI). This initiative comes as the implementation modalities of the EU AI Act become clearer.

The company has played an active role in the development and support of the GPAI Code as well as the Code of Practice on Transparency for AI-Generated Content. These codes were developed through a collaborative process involving various stakeholders, highlighting the importance of a collective approach in regulating AI.

The GPAI Code establishes common standards to ensure transparency, safety, and security of AI models used within the EU. OpenAI has highlighted several of its current practices that already align with these standards, including rigorous testing before launching new models, publishing system cards during major launches, and utilizing an External Testing Network for independent evaluations.

OpenAI also maintains a public document titled Model Specifications, which details how it configures the behavior of its AI models. This document is essential for understanding the company's internal mechanisms regarding security and transparency.

Two internal frameworks support these efforts. The Preparedness Framework, in place since 2023 and updated in 2025, defines methods for identifying, assessing, and managing serious risks associated with advanced systems. In parallel, a Border Governance Framework explains how OpenAI's security practices align with legal requirements, including the GPAI Code.

These documents govern various aspects such as risk assessment, protective measures, model reporting, security posture, incident response, and the integration of external experts into the process.

Increasing Complexity of AI Content Provenance

The Transparency Code focuses on another challenge: enabling users to determine whether content has been generated or modified by AI. OpenAI has developed two complementary mechanisms to address this need.

Content Credits, based on the C2PA standard, add context directly to a file, while SynthID watermarking provides a fallback signal when metadata is lost. These technologies currently cover images and audio outputs, and OpenAI is working to extend these measures to other types of content, including text.

The company is also developing signals and guidelines to help developers meet their own transparency obligations when using OpenAI's models. However, none of these solutions are foolproof. Metadata can be removed, and labels do not always survive transfers between platforms. OpenAI therefore adopts a layered approach, combined with ongoing engagement in the standards community, to address these limitations.

Cybersecurity and Adaptive Governance

The capabilities that allow for detecting and correcting vulnerabilities can also be exploited by attackers. OpenAI has developed a program called Trusted Access for Cybersecurity, aimed at providing verified defenders with access to advanced cyber capabilities while limiting the risks of abuse.

This program was recently expanded to Europe with the launch of the EU Cyber Action Plan in May 2026. This plan, developed in collaboration with EU cybersecurity agencies and private sector partners, aims to enhance cyber resilience across the continent.

OpenAI states that this program aligns with the European Commission's Cybersecurity and Artificial Intelligence Action Plan, which advocates for coordinated risk management related to AI while leveraging this technology to strengthen defensive capabilities.

OpenAI plans to continuously adjust its compliance approach as the EU AI Act evolves. The company emphasizes the importance of flexible regulation that adapts to technological advancements, allowing businesses and organizations to continue benefiting from AI.

Although the GPAI Code and the Transparency Code are still relatively new, OpenAI views its compliance documentation as an evolving process. Companies using OpenAI's models in regulated European markets should use the current system cards and the Border Governance Framework as a basis for their own due diligence, rather than as a complete solution.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.