A careful, partial compliance narrative
With EU AI Act enforcement powers set to activate on August 2, OpenAI published a sweeping compliance narrative on July 31 outlining how its safety, security, and transparency practices align with the bloc's General-Purpose AI Code of Practice.
The statement covers two of the three chapters of the GPAI Code in detail. On transparency, OpenAI points to its existing system cards, red-teaming network, public Model Spec, and the Preparedness Framework it has maintained since 2023 and updated in 2025. On safety and security, it describes the new Frontier Governance Framework, which maps those internal practices onto specific regulatory obligations.
The third chapter, the one requiring a publicly available training data summary under Article 53(1)(d) of the AI Act and a documented copyright compliance policy, is conspicuously absent from the statement.
The gap is specific
The Copyright chapter of the GPAI Code, which the European Commission published in template form on July 24, 2025, requires model providers to disclose category-level information about training data types, main sources, and collection methods. It does not require disclosure of proprietary datasets in full, just the shape of the data pipeline.
OpenAI is a signatory to the GPAI Code. Signing the Code provides a "presumption of conformity" with the underlying AI Act obligations, which means regulators presume compliance rather than investigating from scratch. That presumption is not the same as certification, and a 2026 benchmark study found that signatories score only marginally better than non-signatories on training data documentation quality.
Starting August 2, the European AI Office gains the power to request information, access models, and impose fines of up to €15 million, roughly $17.2 million, or 3% of global annual turnover for non-compliance.
Why the missing chapter matters
OpenAI's framing of the statement is consistent. It describes its practices as supportive of the EU framework rather than claiming verified compliance, acknowledges that provenance technology is imperfect, and notes that standards are still evolving.
The omission is harder to explain. OpenAI's pre-August 2025 models have until August 2, 2027 under a transitional deadline, but GPT-5 and any newer release have no such window. The Copyright chapter applies to all GPAI providers, including OpenAI. The European AI Office can now begin verifying compliance through information requests and, where necessary, enforcement actions.
The July 31 statement is best read as OpenAI opening a public dialogue about how it intends to comply while reserving room to negotiate the specifics. Whether that posture survives the AI Office's first round of information requests is the next test.