XT.PT AI regulation → This story
Analysis AI regulation

OpenAI's compliance-day post says a lot about safety, and nothing about copyright

The substantive alignment predates the post; what is new is a provenance expansion to audio and a conspicuous silence on training data.

OpenAI logo on keyboard

On 31 July, two days before the European Commission began enforcing the AI Act's rules for general-purpose models, OpenAI published "Advancing responsible AI across Europe." The framing is a checkpoint: "As the EU AI Act enters its next phase, we're sharing how we have strengthened our approach to safety, security, transparency and provenance in line with the EU framework."

The timing is the story's spine, so it is worth pinning the dates down first — and then noticing what the post does and does not say.

What actually changes on 2 August

The EU AI Act's obligations for general-purpose AI providers entered into application on 2 August 2025. What arrives a year later is teeth. Per the Commission's own FAQ: "from 2 August 2026 onwards, the Commission will enforce full compliance with all obligations for providers of general-purpose AI models, including through fines." The same day brings new transparency duties — chatbots must disclose they are AI, deepfakes must be labeled, and AI-generated content must carry machine-readable marks.

So the deadline OpenAI's post is timed to is real, and it is an enforcement deadline, not a rule-change deadline. The rules have been in application for a year; the penalties start now.

The alignment mostly already happened

Read as a description of new action, "aligns" oversells. The substantive work the post points to predates it:

  • OpenAI announced its intention to sign the GPAI Code on 11 July 2025.
  • The document that actually maps its practices to the law — the Frontier Governance Framework — was published on 28 May 2026, and even then said so explicitly: it "explains how our safety and security practices align with emerging legal requirements, including... the EU AI Act's Code of Practice for General Purpose AI."

The 31 July statement builds on that foundation rather than breaking new ground: "Our Frontier Governance Framework builds on that foundation and explains how our safety and security practices align with emerging legal requirements, including the EU AI Act's GPAI Code." This is a compliance-day summary, not a compliance-day change.

There is one genuinely new commitment worth extracting. On provenance, OpenAI says it is broadening its Content Credentials and SynthID watermarking work: "Consistent with our commitments under the Code, we are working to expand provenance measures for OpenAI's systems across modalities, including text, as standards and tooling continue to mature." The post specifies audio outputs joining images now, with text as the harder frontier — which is the honest ordering, since text watermarking remains the least solved of the three.

The chapter that goes unmentioned

The GPAI Code has three chapters: Transparency, Copyright, and Safety and Security. OpenAI's statement engages the first and third in detail. It endorses, in its words, "two Codes of Practice: the EU's General-Purpose AI Code of Practice and the Code of Practice on Transparency of AI-Generated Content." It covers safety, security, transparency, provenance.

The word copyright does not appear in it. Neither does training data. For a compliance statement published on the eve of enforcement, addressing two of the Code's three chapters and leaving the most contested one — the Copyright chapter, which asks signatories to adopt a policy to comply with EU copyright law — unaddressed is not a small omission. It is arguably the most newsworthy thing in the document, precisely because it is the thing the document declines to discuss.

A reader should be careful here: silence is not violation. OpenAI is a listed signatory to the full Code, alongside Anthropic, Google, Microsoft, Amazon and Mistral, and signature covers all three chapters. The Copyright chapter may be handled elsewhere in OpenAI's compliance materials. But a public statement chooses what to foreground, and this one foregrounds the chapters where the story is favorable and steps around the one where the litigation is.

What to take from it

Stripped of the announcement framing, the substance is: a year-old set of obligations becomes enforceable on 2 August; OpenAI, already a signatory, has restated its safety and transparency alignment and added a concrete provenance step for audio; and it has said nothing, on the record, about how its training data squares with the Code's copyright expectations. For a magazine that reads compliance documents for what they omit as much as what they claim, that last silence is the line worth watching as the fines regime begins.

Primary sources: OpenAI — Advancing responsible AI across Europe (31 July 2026); OpenAI — Frontier Governance Framework (28 May 2026); OpenAI — The EU Code of Practice and future of AI in Europe (11 July 2025); European Commission — The General-Purpose AI Code of Practice; European Commission — Guidelines on obligations for GPAI providers (FAQ), read 2026-08-04.

Corrections and source documents: contact the desk
Read next →
Read next
The API · 3 min

Gemini retires the temperature knob: ignored today, an HTTP 400 tomorrow

The API · 3 min

A refusal is a 200: the Claude stop_reason that breaks lazy clients