OpenAI published a compliance statement endorsing the EU's General-Purpose AI (GPAI) Code of Practice, submitted hours before enforcement powers activate on August 2, 2026. The company outlined alignment on two of three Code chapters: Transparency and Safety & Security, detailing its Preparedness Framework (in place since 2023, updated 2025) and Frontier Governance Framework (published May 28, 2026) to identify, assess, and report serious risks from advanced systems. OpenAI also committed to C2PA Content Credentials and SynthID watermarking for provenance.
The company notably omitted discussion of the Code's Copyright chapter, which requires published training data summaries and documented copyright compliance policies. Starting August 2, the European AI Office can conduct audits, request model access, and impose fines up to €15 million (3% of global annual turnover) for non-compliance. Separately, OpenAI launched an EU Cyber Action Plan (May 2026) providing Trusted Access for Cyber (TAC) model access to EU/national cyber agencies and critical infrastructure operators.
For architects: OpenAI's partial compliance signals real enforcement risk on training data transparency. The Copyright chapter gap is particularly notable given recent copyright litigation exposure. Downstream deployers should request the full information package (system cards, known biases, use restrictions, capabilities summary) from OpenAI before August 2 if not already provided. The EU's soft-touch regulatory approach is ending; audits and corrective orders now become routine.