OpenAI Signs EU’s AI Code of Practice, Prepares for Staggered Compliance Deadlines
OpenAI has committed to the EU’s General-Purpose AI Code of Practice and a new transparency code, becoming the first US company to do so. The moves are part of a broader push to align its safety, provenance, and governance frameworks with the EU AI Act’s phased obligations.

OpenAI has signed the European Union’s General-Purpose AI Code of Practice, becoming the first US company to do so, and has pledged support for a new Code of Practice on Transparency of AI-Generated Content. The commitments, detailed in a blog post titled “Advancing Responsible AI Across Europe,” are part of a broader effort to align the company’s safety, security, and governance practices with the EU AI Act—the world’s first comprehensive AI legal framework—before its key provisions take effect over the next two years.
What happened
On 11 June 2026, the European Commission published the Code of Practice on Transparency of AI-Generated Content, which focuses on detecting and labeling AI-generated or manipulated content. OpenAI announced its support for the code the same day, framing it as “an important step in implementing the EU AI Act and building a more transparent digital ecosystem.” The transparency obligations under the AI Act—including labeling and detection requirements—will become enforceable on 2 August 2026.
Earlier, in July 2025, the Commission released three GPAI instruments: guidelines on obligations, the GPAI Code of Practice, and a template for public summaries of training content. OpenAI decided to sign the GPAI Code, which covers transparency, copyright, and safety and security, and will use it as a tool to demonstrate compliance with its AI Act obligations for general-purpose AI models. The company has also signed the three core commitments of the EU AI Pact (September 2024) and intends to formally adopt the GPAI Code subject to approval by the AI Board.
💡 OpenAI’s dual commitment to both the GPAI Code and the transparency Code signals a proactive strategy to shape—and not just react to—Europe’s evolving regulatory landscape. By being the first US signatory, the company is positioning itself as a cooperative partner, which could help smooth future enforcement interactions.
Why it matters
The EU AI Act, which entered into force in August 2024, introduces a risk-based regime with staggered deadlines. Prohibitions on certain AI uses (e.g., social scoring) took effect in February 2025. Rules for GPAI models—like OpenAI’s GPT series—become effective in August 2025, and transparency obligations for AI-generated content follow in August 2026. For OpenAI, which operates models that may qualify as “systemic-risk GPAI,” compliance is not optional: it must produce technical documentation, publish training data summaries, conduct model evaluations, monitor incidents, and implement cybersecurity measures.
To meet these requirements, OpenAI is leaning on internal frameworks it has been developing since the November 2023 UK AI Safety Summit. Its Preparedness Framework—updated in April 2025—outlines scenario planning, capability evaluations, red-teaming, and deployment thresholds. The Frontier Governance Framework maps these internal processes to AI Act concepts like systemic-risk GPAI, incident monitoring, and cybersecurity. Together, they form the backbone of the company’s claim that it can operate safely and transparently under European law.
What it means for business
For European enterprises using OpenAI’s models, the regulatory push brings both clarity and new obligations. OpenAI has published an EU AI Act primer that explains how its models map to the Act’s categories, and it has created a dedicated EU AI Act Reporting Form through which customers can request model documentation or submit complaints about copyright compliance. The company has also expanded data residency in Europe for ChatGPT Enterprise, ChatGPT Edu, and the API platform, allowing eligible customers to process data in-region with zero data retention—a critical feature for organizations subject to GDPR and national data sovereignty laws.
💡 For businesses, the key practical implication is that OpenAI’s compliance infrastructure is now accessible as a customer-facing tool. The data residency option, combined with the reporting form and detailed documentation, means that companies can more easily demonstrate their own compliance when building on top of OpenAI’s models—a growing requirement under the AI Act’s downstream deployer obligations.
Beyond compliance, OpenAI is coupling its governance commitments with economic initiatives. It launched an EU Economic Blueprint 2.0 with updated AI usage data and an “OpenAI for Countries European Rollout” to help governments and businesses adopt AI. These moves are designed to show that responsible AI governance and economic growth can go hand in hand—a message that resonates with European policymakers eager to boost AI adoption without sacrificing safety.
What to watch next
The true test will come when the AI Act’s GPAI obligations take full effect in August 2025 and the transparency rules in August 2026. Regulators will assess whether OpenAI’s signed codes, frameworks, and transparency tools translate into real-world compliance—or whether gaps remain. Meanwhile, the AI Office continues consultations on technical standards for provenance and labeling, which could force further adjustments. For now, OpenAI has placed a clear bet: that early, public alignment with Europe’s rules is the best path to maintaining its market position and avoiding the kind of regulatory friction that has slowed other tech giants.
Want automation like this for your business?
Get in touch and we'll show you exactly what's possible for your setup.