Philadelphia Live News

collapse
Home / Daily News Analysis / OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI aligns safety practices with EU AI Act’s GPAI Code

Aug 03, 2026  Twila Rosenbaum  6 views
OpenAI aligns safety practices with EU AI Act’s GPAI Code

OpenAI has taken a significant step toward regulatory compliance by aligning its safety practices with the European Union’s Artificial Intelligence Act, specifically the Code of Practice for General-Purpose AI (GPAI). The announcement signals a proactive approach to emerging governance frameworks, as the EU continues to refine its rules for the responsible development and deployment of powerful AI models.

What is the EU AI Act and the GPAI Code?

The EU AI Act is a landmark regulatory framework designed to govern the development, deployment, and use of artificial intelligence across the European Union. It adopts a risk-based approach, categorizing AI applications into different levels of risk, from minimal to unacceptable. The Act includes specific obligations for general-purpose AI models, which are systems capable of performing a wide range of tasks, such as large language models that power chatbots, code generators, and other AI tools.

The GPAI Code, which falls under the EU AI Act, is a key mechanism for ensuring that developers of general-purpose AI adhere to high standards of safety, transparency, and accountability. The Code is intended to translate the Act’s high-level principles into practical, actionable measures. It covers areas such as risk assessment, data governance, model documentation, and incident reporting, among others. The European Commission, along with the AI Office, has worked with stakeholders to draft the Code, which is expected to become an important benchmark for AI developers operating in the EU.

OpenAI’s Alignment with the GPAI Code

OpenAI’s decision to align its safety practices with the GPAI Code represents a major milestone in the company’s regulatory strategy. According to the company, this alignment involves updating internal safety protocols, improving transparency, and ensuring that its models are developed with robust safeguards against misuse. The move is likely intended to demonstrate OpenAI’s commitment to responsible AI, especially as the EU tightens its regulatory oversight.

One of the central elements of the alignment is the adoption of a comprehensive risk management framework. This framework is designed to identify, assess, and mitigate risks associated with general-purpose AI, including potential for generating harmful content, enabling cyberattacks, or spreading disinformation. OpenAI has stated that it will incorporate the GPAI Code’s requirements into its existing safety practices, which already include red-team testing, adversarial evaluations, and continuous monitoring.

Transparency is another key aspect of the alignment. Under the GPAI Code, developers are expected to provide detailed documentation about their models, including information about training data, intended uses, known limitations, and potential risks. OpenAI has committed to enhancing its model documentation to meet these expectations, making it easier for downstream developers and regulators to understand the capabilities and limitations of its systems.

Background: The Development of the GPAI Code

The GPAI Code has been in development for several months, with input from a broad range of experts, including representatives from academia, industry, civil society, and government. The European Commission initiated the drafting process in 2023, following the political agreement on the EU AI Act. The Code is designed to complement the Act’s legal obligations by providing a practical framework for compliance. It is structured around several key pillars, each addressing a specific area of concern.

The first pillar focuses on transparency and copyright. This pillar requires developers of general-purpose AI to publish detailed summaries of their training data, including information about copyrighted material. It also mandates that models adhere to EU copyright laws and clearly label AI-generated content. The second pillar addresses risk assessment and mitigation. This involves identifying systemic risks that may arise from high-impact models and implementing measures to reduce those risks. The third pillar covers internal governance, requiring developers to establish clear accountability structures and robust cybersecurity controls. The fourth pillar is about transparency for downstream providers, ensuring that businesses that integrate AI models into their products have access to the information they need.

OpenAI’s alignment with the GPAI Code suggests that the company is prepared to meet these evolving expectations. The company has previously faced criticism over the opacity of its models and its handling of safety concerns. By voluntarily aligning with the Code, OpenAI may be seeking to build trust with regulators and the public, while also influencing the development of future regulations.

Key Safety Practices at OpenAI

OpenAI has long been recognized for its commitment to AI safety, although its approach has evolved over time. The company was founded in 2015 with a mission to ensure that artificial general intelligence benefits all of humanity. Since then, it has developed a range of safety practices that are now being aligned with the GPAI Code.

One of the most important practices is the use of reinforcement learning from human feedback (RLHF). This technique involves training models to align with human preferences and values, reducing the likelihood of harmful outputs. RLHF has been used in the development of models such as GPT-4, which powers ChatGPT. OpenAI also employs a team of safety researchers who conduct extensive testing, looking for vulnerabilities that could be exploited by malicious actors.

Red-teaming is another critical component. In this process, external experts attempt to find ways to bypass safety measures or cause the model to behave incorrectly. The results of red-teaming are used to improve the model before release. OpenAI has also implemented usage policies and moderation systems to prevent the generation of illegal or harmful content. These systems are constantly updated based on new threats and user feedback.

In addition to these technical measures, OpenAI has committed to principle-based governance. The company has published an AI Safety Framework, which outlines how it identifies risks, sets thresholds for acceptable risk, and decides when a model is ready for deployment. The framework is designed to be iterative, allowing for continuous improvement as models become more capable.

Implications of the Alignment

OpenAI’s alignment with the GPAI Code has several important implications for the AI industry. First, it sets a precedent for other companies developing general-purpose AI. By voluntarily adopting the standards outlined in the Code, OpenAI is signaling that compliance with the EU AI Act is not necessarily onerous but can be integrated into existing practices. This may encourage other developers to follow suit, especially those that operate in the EU market.

Second, the alignment could influence the final shape of the GPAI Code. The European Commission has been seeking input from stakeholders, and a major company like OpenAI endorsing the Code adds legitimacy to the framework. It may also lead to a more collaborative relationship between AI developers and regulators, reducing the likelihood of adversarial conflicts.

Third, the move has implications for global AI governance. The EU AI Act is often viewed as a model for other jurisdictions, and OpenAI’s compliance could serve as a reference point for regulators outside Europe. As countries around the world consider their own AI rules, the practices adopted by leading companies will likely inform these efforts.

However, there are also potential challenges. Some critics argue that voluntary alignment is insufficient because it falls short of binding legal requirements. The GPAI Code will eventually become a mandatory reference for many AI developers, but until it is fully enforced, companies like OpenAI may be able to pick and choose which aspects to implement. Additionally, aligning with a European regulatory framework may create friction with other regional requirements, as local laws and norms can differ significantly.

What’s Next for OpenAI and the EU?

OpenAI has indicated that it will continue to refine its safety practices and work with the EU AI Office to support the implementation of the GPAI Code. The company has also pledged to share best practices and contribute to the ongoing development of safety standards. This engagement is likely to be a two-way process, with OpenAI providing technical expertise and regulators offering guidance on societal expectations.

In the coming months, the European Commission is expected to finalize the GPAI Code, incorporating feedback from the current consultation period. Once adopted, the Code will serve as a benchmark for assessing whether developers meet the requirements of the EU AI Act. OpenAI’s early alignment may give it an advantage in this assessment, as it will already have systems in place to demonstrate compliance.

For the broader AI ecosystem, this development underscores the importance of regulatory readiness. Companies that adopt robust safety practices early on will be better positioned to navigate the evolving legal landscape. It also highlights the role of private standards in shaping public policy, as companies transition from mere compliance to active participation in the creation of governance norms.

The alignment between OpenAI’s safety practices and the GPAI Code is not just a procedural exercise; it reflects a deeper recognition that AI safety is a societal concern that requires collective action. As models become more capable, the potential for both benefits and harms grows. Responsible development practices, transparent reporting, and ongoing risk assessment are essential to building trust among users and policymakers alike.

OpenAI’s announcement comes at a time when the AI industry is facing intense scrutiny over issues like data privacy, copyright, and the spread of misinformation. By aligning with the EU’s framework, the company is making a public commitment to addressing these challenges. It remains to be seen how other developers will respond, but the direction is clear: regulatory compliance is becoming a central component of AI research and deployment.


Source: AI News News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy