Advancing Responsible AI Across Europe: OpenAI's Commitment to Safety and Security

·
By Raisink Team

OpenAI has been at the forefront of developing responsible artificial intelligence (AI) in Europe, with millions of people across the continent using its tools for learning, creation, work, and everyday tasks. The company’s mission is to ensure that AI benefits all humanity, while also acknowledging an ongoing responsibility to maximize its benefits, broaden access, and manage risks. This commitment is reflected in OpenAI’s approach to safety, security, transparency, and provenance, which aligns with the EU’s framework for responsible AI.

In line with the European Union’s (EU) Artificial Intelligence Act (AI Act), OpenAI has strengthened its governance frameworks to ensure that its tools are safe, secure, and transparent. The company contributed to and endorsed two Codes of Practice: the General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content. These codes were developed through extensive multi-stakeholder processes and build on OpenAI’s work in safety, security, transparency, accountability, and provenance.

The General-Purpose AI Code creates a shared framework for transparency, safety, and security for general-purpose AI models. To support this framework, OpenAI has implemented internal governance measures and collaborated with external experts, governments, and peer organizations. The company extensively tests its models before releasing them, publishes system cards with major releases, brings outside experts into model testing through the Red Teaming Network, and maintains a public Model Spec as a window into how it shapes model behavior.

OpenAI has also continued to strengthen the governance frameworks behind this work. Its Preparedness Framework, in place since 2023 and updated in 2025, sets out how the company identifies, evaluates, and manages serious risks from advanced AI systems. The Frontier Governance Framework builds on that foundation and explains how OpenAI’s safety and security practices align with emerging legal requirements, including the EU AI Act’s GPAI Code.

Responsible AI governance requires work beyond any one company. Through collaborations such as the Frontier Model Forum, US CAISI, UK AISI, and third-party evaluation practices, OpenAI has supported shared safety research, external testing, and clearer evaluation standards across the ecosystem.

The company’s support for the Code of Practice on Transparency of AI-Generated Content builds on years of research, product development, and collaboration to improve provenance for AI-generated media. People should have better context about the content they see online, including whether it was created or edited with AI. OpenAI’s approach to provenance relies on two systems that reinforce each other: Content Credentials (C2PA) help content carry detailed context; while SynthID watermarks preserve a signal when metadata does not survive.

OpenAI is expanding its work in this area, including audio outputs in addition to images. Consistent with the company’s commitments under the Code, it aims to expand provenance measures for OpenAI’s systems across modalities, including text, as standards and tooling continue to mature. The company also supports customers and developers building with its models by providing signals, tools, and guidance they can use in meeting their own transparency obligations.

Provenance is still an evolving field: metadata can be lost, labels can fail to travel across platforms, and no single signal is perfect. That’s why OpenAI advocates for a layered approach and continued cooperation across the wider ecosystem.

Cybersecurity is another area where dynamic and practical governance is especially important. The same capabilities that can help defenders identify and remediate vulnerabilities can also create new misuse risks. To address this challenge, OpenAI has developed its Trusted Access for Cyber (TAC) program to reduce misuse while helping legitimate defenders use AI through secure access to advanced cyber models.

Since launching the OpenAI EU Cyber Action Plan in early May 2026, the company has worked with EU and national cyber agencies, private sector partners, and critical infrastructure operators to equip them with the most advanced cyber models. This approach aligns with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for a coordinated effort to address the risks of advanced AI while harnessing its potential to strengthen cyber resilience.

As implementation of the EU AI Act continues, OpenAI will keep strengthening its compliance approach and learning from regulators and the broader ecosystem. The company acknowledges that rules must remain flexible enough to adapt as technology advances, enabling people, businesses, and organizations to benefit from responsible AI.

To support customers and developers preparing for the EU AI Act’s implementation, OpenAI provides practical resources including model documentation, system cards, safety information, usage policies, and guidance on provenance and verification tools. The company will continue updating these resources as implementation evolves.

Related news