OpenAI maps safety, provenance and cyber controls to the EU AI Act

On July 31, 2026, OpenAI outlined how it is adapting its safety, security, transparency and provenance controls for the next phase of the EU AI Act. It also confirmed its endorsement of two instruments: the EU General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content.
Why implementation matters
Millions of Europeans use OpenAI tools, while businesses and public bodies increasingly embed them in everyday operations. The challenge is to manage serious model risks without imposing static controls that quickly become obsolete or prevent legitimate deployment.
For customers and developers, compliance depends on evidence rather than broad assurances. Model documentation, risk assessments, usage policies, incident procedures and reliable information about generated content must work together as the regulation evolves.
Safety, provenance and cyber controls
OpenAI’s Preparedness Framework, introduced in 2023 and updated in 2025, governs the assessment of severe risks from advanced systems. Its current governance stack builds on OpenAI’s Frontier Governance Framework for AI safety, linking safeguards, model reporting, security, incident response and external expert input to emerging legal requirements.
The company also uses pre-release testing, system cards, its public Model Spec and the Red Teaming Network. Work through the Frontier Model Forum, US CAISI and UK AISI supports third-party evaluation and shared safety research.
For provenance, OpenAI combines C2PA Content Credentials with SynthID watermarks because metadata or labels may disappear between platforms. Coverage is expanding from images to audio, with broader measures for text planned as standards and tooling mature.
Cybersecurity in practice
Since launching the OpenAI EU Cyber Action Plan in early May 2026, the company has worked with European cyber agencies, private partners and critical infrastructure operators. Its Trusted Access for Cyber program is intended to give legitimate defenders controlled access to advanced capabilities while reducing misuse.
For businesses, the practical priority is a living control system: inventory every AI use, retain supplier evidence, assign risk owners and test incident response. That approach is more durable than treating EU AI Act readiness as a one-time legal review.

