Hutchinson Kansas Newspaper

collapse
Home / Daily News Analysis / OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI aligns safety practices with EU AI Act’s GPAI Code

Aug 01, 2026  Twila Rosenbaum 5 views
OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI has announced that it is aligning its safety and governance practices with the European Union’s Artificial Intelligence Act, specifically the General-Purpose AI Code of Practice. The decision reflects a broader effort by the company to prepare for evolving regulatory expectations in Europe and beyond. As AI models become more powerful and widely deployed, policymakers have demanded clearer accountability and stronger safeguards. OpenAI’s alignment is a response to those demands.

The EU AI Act is the first comprehensive legal framework for artificial intelligence in the world. It introduces a risk-based approach that categorizes AI systems according to the level of harm they may pose to individuals and society. Within this framework, general-purpose AI models—such as those used in chatbots, image generators, and other foundation models—are subject to specific obligations. The General-Purpose AI Code, often referred to as the GPAI Code, translates these obligations into concrete practical measures.

OpenAI’s commitment to the GPAI Code signals a notable shift in how the company approaches regulatory compliance. Rather than waiting for enforcement actions or legal challenges, the company appears to be taking a proactive stance. This move may also serve as a signal to other AI developers that voluntary alignment with emerging regulatory standards is both feasible and strategically advantageous.

What the GPAI Code requires

The GPAI Code is designed to provide detailed guidance on how developers of general-purpose AI models can comply with the EU AI Act. It covers several key areas, including transparency, risk management, data governance, and systemic risk mitigation. For OpenAI, aligning with these requirements means making technical documentation more robust and ensuring that safety practices are auditable and verifiable.

One of the central requirements of the GPAI Code is the creation of detailed model documentation. This includes information about the model’s architecture, training data, intended use, and known limitations. For a company like OpenAI, which has historically emphasized safety research, this documentation requirement aligns with existing internal practices. However, it also introduces new levels of external scrutiny, as regulators and third-party auditors may now have access to more detailed information about how models are built and tested.

Risk management is another critical element of the GPAI Code. Developers are expected to implement robust risk assessment methodologies that can identify, evaluate, and mitigate potential harms before deployment. This includes not only technical risks such as bias and robustness failures but also broader societal risks related to misinformation, privacy, and security. OpenAI has already published research on topics such as adversarial robustness and fairness, but the GPAI Code requires these efforts to be formalized within a health and safety framework.

Systemic risk and frontier models

The GPAI Code also introduces special obligations for models that are considered to pose systemic risks. These are models with high computational power or large-scale impact thresholds. OpenAI’s most advanced models are likely to fall into this category, given the scale of their training runs and the breadth of their deployment. For these models, the code calls for additional safety measures, including continuous monitoring, incident reporting, and more rigorous evaluation methods.

Systemic risk mitigation is one of the most challenging aspects of the GPAI Code because it requires companies to anticipate worst-case scenarios. These may include malicious use of AI, large-scale disinformation campaigns, or even catastrophic failures that could undermine public trust. OpenAI has long discussed the importance of safe artificial general intelligence, and the GPAI Code provides a structured way to turn those principles into operational practice.

Transparency and copyright considerations

Transparency is another pillar of the GPAI Code. Developers must clearly inform users when they are interacting with an AI system. They must also disclose the capabilities and limitations of the model in a way that is understandable to non-experts. For OpenAI, this likely means updating user interfaces, terms of service, and model documentation to meet the EU’s standards.

Copyright and data governance are also addressed in the code. General-purpose AI models are typically trained on massive datasets that include publicly available content from the internet. The EU AI Act requires developers to respect copyright law and to implement policies that allow rights holders to seek recourse if their content is used without authorization. OpenAI has already introduced mechanisms for content creators to opt out of training data, but the GPAI Code may require further procedural enhancements.

The company has also committed to maintaining a transparent record of the measures it takes to comply with these requirements. That includes regular reviews of its safety policies and an openness to external audits. Such measures are intended to build trust not only with regulators but also with enterprises and individual users who rely on AI systems.

Broader implications for the AI industry

OpenAI’s decision to align with the GPAI Code could have significant ripple effects throughout the AI industry. Many other developers of large language models and foundation models are based in the United States or operate globally. To serve European customers, they will need to demonstrate compliance with EU rules. By being an early mover, OpenAI may shape the interpretation of the GPAI Code and establish benchmarks for what constitutes adequate safety practice.

European regulators have welcomed voluntary commitments that go beyond the letter of the law. The AI Office, which is responsible for overseeing the implementation of the EU AI Act, has encouraged companies to adopt best practices early. Early alignment can reduce the risk of enforcement actions and can also create a positive relationship with regulators, which may be useful as the legal landscape continues to evolve.

At the same time, compliance costs can be substantial. Implementing new documentation standards, conducting additional risk assessments, and maintaining ongoing monitoring systems require significant engineering and legal resources. For larger companies such as OpenAI, these costs are likely manageable. For smaller startups, however, the GPAI Code could present a taller hurdle. The EU has stated that it intends to provide support for small and medium-sized enterprises, but the practical details remain in development.

What changed in OpenAI’s safety practices

The alignment announced by OpenAI includes several concrete adjustments. The company has enhanced its internal safety review processes, making them more rigorous and more closely tied to the requirements of the GPAI Code. This includes earlier identification of potential risks during the model development cycle, as well as more comprehensive evaluations before models are released to the public.

OpenAI has also updated its approach to monitoring how its models are used. This involves not only analyzing user interactions for signs of misuse but also coordinating with independent researchers and policymakers. The company has previously made notable efforts to share safety research and to engage with the broader AI community. The GPAI Code alignment formalizes some of these engagements.

There is also a renewed emphasis on record keeping. Under the GPAI Code, developers must maintain records that demonstrate compliance. This institutional memory is important because regulation is likely to be enforced through audits and inspections. Having clear documentation can help avoid disputes and ensure that safety decisions are explainable after the fact.

Reactions from experts and stakeholders

Policy analysts have generally responded positively to OpenAI’s announcement. Many believe that voluntary alignment with the GPAI Code will push the entire sector toward higher standards. Some civil society groups have expressed cautious optimism, but they have also called for stronger enforcement mechanisms. The concern is that self-regulation may not be sufficient without independent verification.

Industry observers note that OpenAI’s move creates competitive pressure. If AI providers are expected to meet integrity and transparency standards, companies that fail to do so could lose access to European markets. That is a powerful incentive, given the size and economic significance of the EU market. Over time, these standards could also influence regulations in other jurisdictions, such as the United States and Japan, which are still developing their own AI governance frameworks.

The development also comes at a time when public trust in AI is a central issue. High-profile incidents involving “hallucinating” chatbots, biased decisions, and deepfakes have made users wary. By demonstrating an institutional commitment to safety, OpenAI hopes to reinforce its status as a responsible leader in the field.

Looking ahead

As the EU AI Act moves from text to implementation, the exact details of the GPAI Code will continue to evolve. OpenAI has said that it will remain engaged with the regulatory process and will adapt its practices as further guidance is released. The goal is not simply to check compliance boxes but to integrate safety into every part of the AI lifecycle.

The company’s alignment is not a one-time action. It represents an ongoing commitment to improve risk management and transparency in line with European norms. That means investing in new evaluation tools, expanding the workforce of safety researchers, and maintaining a strong culture of responsibility within the organization.

Other AI developers are likely to follow OpenAI’s example. The combination of legal obligations and market incentives makes compliance almost unavoidable for major industry players. Still, the path to full alignment is complex, and many issues remain unresolved, including how to decide which models count as “systemic,” how to conduct audits effectively, and how to balance trade secrets with the need for transparency.

OpenAI’s move also highlights a broader trend toward global standards in the digital economy. As governments confront the challenges of advanced AI, they are increasingly looking for common principles such as safety, transparency, and accountability. The EU AI Act is a landmark in that effort, and the voluntary alignment by a major developer marks an important milestone. The coming years will determine whether these principles lead to meaningful changes in the way AI systems are built, deployed, and governed. For now, OpenAI has positioned itself as a company that is willing to adapt to the new regulatory climate, and its actions will be closely watched by both supporters and critics of AI innovation.


Source:AI News News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy