OpenAI

EU AI Act: OpenAI Resources and Customer Guidance

This article sets out helpful information on our compliance with the EU AI Act.

Updated: 2 hours ago

OpenAI is committed to developing models that comply with applicable EU AI Act requirements and to helping customers access information they may need to manage their own compliance. We will update this page periodically with helpful information and resources.

This article is for general information only and is not legal advice. Customers, developers, and users are responsible for assessing and complying with the legal obligations that apply to them.

OpenAI’s approach to the EU AI Act

For more information on OpenAI’s approach to responsible AI governance, including our support for the EU AI Act’s Codes of Practice, see our blog post, Advancing Responsible AI Across Europe [link to updated blog post]. 

OpenAI has also published its Frontier Governance Framework, which explains how our safety and security practices align with emerging legal requirements, including the EU AI Act’s Code of Practice for General Purpose AI. The Frontier Governance Framework builds on our Preparedness Framework, which describes how we evaluate and manage serious risks from advanced AI systems.

For more information about how we approach safety, see our Safety Approach and Deployment Safety Hub, where we share system cards, safety evaluation information, and other technical updates.

Prohibited practices under the EU AI Act

Article 5 of the EU AI Act prohibits certain uses of AI that present an unacceptable level of risk. OpenAI has technical safeguards in place, and we also expect customers, developers, and users to comply with applicable laws, including avoiding prohibited AI practices where the EU AI Act applies.

You should not use OpenAI services to engage in prohibited practices under the EU AI Act, including:

  • Using subliminal, manipulative, or deceptive techniques to materially distort someone’s behavior in a way that is likely to cause harm.

  • Exploiting a person’s or group’s vulnerabilities, including vulnerabilities related to age, disability, or social or economic situation, in a way that is likely to cause significant harm.

  • Assigning social scores to people or groups in ways that lead to unjustified, disproportionate, or unrelated unfavorable treatment.

  • Assessing the risk that a person may commit a crime based solely on profiling or personality traits.

  • Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

  • Inferring emotions in workplace or educational settings, unless a medical or safety exception applies.

  • Using biometric data to categorize people in order to infer sensitive characteristics, such as race, political opinions, trade union membership, religion, sex life, or sexual orientation, except in limited lawful contexts.

  • Conducting real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, except in narrow circumstances permitted by law.

For more information about how OpenAI services may be used, please review our Usage Policies and Terms & Policies. The European Commission has also published guidance on prohibited practices that may help you assess your own obligations.

Transparency and training data summaries

In accordance with our obligations under Article 53(1)(d) of the EU AI Act, OpenAI publishes summaries about the content used to train our general-purpose AI models:

Provenance and AI-generated content

OpenAI is also working to help people better understand when content may have been generated or edited with AI. We use a layered approach to content provenance, including Content Credentials, C2PA conformance, SynthID watermarking for images, and a public verification tool preview.

These tools are designed to provide more context about where content came from and whether it contains provenance signals from OpenAI systems. No single provenance or detection method is perfect, and signals can sometimes be removed or fail to survive edits or platform changes. That is why OpenAI supports a layered approach that combines standards, watermarking, and verification tools.

How OpenAI supports customers with their own compliance with provenance related obligations

  • Our content comes embedded with provenance signals such as C2PA metadata or SynthID watermarks that are easy to carry-forward, without additional investment from customers   

  • In addition to the openai.com/verify web portal, customers can also use our Content Provenance API to detect whether a provenance signal is present. 

For more information, see Advancing content provenance for a safer, more transparent AI ecosystem and our Help Center article.

Contact

Please contact us via our EU AI Act Reporting Form for the following:

  • EU Customer Support related to the EU AI Act, including requesting relevant EU AI Act model documentation 

  • Complaints concerning OpenAI’s compliance with the Copyright Chapter of the Code of Practice for General-Purpose AI Models

If you would like to report a security incident, please let us know immediately by submitting an encrypted report as described in OpenAI’s Coordinated Vulnerability Disclosure Policy.

We will acknowledge and review your report and consider how your feedback may help us improve our processes. 

Was this article helpful?