AI

OpenAI Lays Out EU AI Act Compliance, Skips Copyright Chapter

OpenAI's July 31 EU compliance statement covers safety and transparency but skips the GPAI Code's training data summary requirement. Regulators are watching.

OpenAI published a detailed EU AI Act compliance statement on July 31 covering the GPAI Code's Transparency and Safety and Security chapters, but did not address the Copyright chapter that requires a public training data summary. The omission is conspicuous because OpenAI is a GPAI Code signatory, and starting August 2 the European AI Office can request information and fine non-compliant providers up to €15 million or 3% of global turnover. The statement positions OpenAI's practices as supportive of the framework rather than as verified compliance, leaving room for the next round of regulatory engagement.

A careful, partial compliance narrative

With EU AI Act enforcement powers set to activate on August 2, OpenAI published a sweeping compliance narrative on July 31 outlining how its safety, security, and transparency practices align with the bloc's General-Purpose AI Code of Practice.

The statement covers two of the three chapters of the GPAI Code in detail. On transparency, OpenAI points to its existing system cards, red-teaming network, public Model Spec, and the Preparedness Framework it has maintained since 2023 and updated in 2025. On safety and security, it describes the new Frontier Governance Framework, which maps those internal practices onto specific regulatory obligations.

The third chapter, the one requiring a publicly available training data summary under Article 53(1)(d) of the AI Act and a documented copyright compliance policy, is conspicuously absent from the statement.

The gap is specific

The Copyright chapter of the GPAI Code, which the European Commission published in template form on July 24, 2025, requires model providers to disclose category-level information about training data types, main sources, and collection methods. It does not require disclosure of proprietary datasets in full, just the shape of the data pipeline.

OpenAI is a signatory to the GPAI Code. Signing the Code provides a "presumption of conformity" with the underlying AI Act obligations, which means regulators presume compliance rather than investigating from scratch. That presumption is not the same as certification, and a 2026 benchmark study found that signatories score only marginally better than non-signatories on training data documentation quality.

Starting August 2, the European AI Office gains the power to request information, access models, and impose fines of up to €15 million, roughly $17.2 million, or 3% of global annual turnover for non-compliance.

Why the missing chapter matters

OpenAI's framing of the statement is consistent. It describes its practices as supportive of the EU framework rather than claiming verified compliance, acknowledges that provenance technology is imperfect, and notes that standards are still evolving.

The omission is harder to explain. OpenAI's pre-August 2025 models have until August 2, 2027 under a transitional deadline, but GPT-5 and any newer release have no such window. The Copyright chapter applies to all GPAI providers, including OpenAI. The European AI Office can now begin verifying compliance through information requests and, where necessary, enforcement actions.

The July 31 statement is best read as OpenAI opening a public dialogue about how it intends to comply while reserving room to negotiate the specifics. Whether that posture survives the AI Office's first round of information requests is the next test.