Wednesday, September 16, 2026Verified technology journalism

OpenAI endorsed the EU's AI Code of Practice but skipped the Copyright chapter, and enforcement powers activate tomorrow

OpenAI published a sweeping compliance statement Thursday detailing its safety frameworks, provenance watermarking, and cybersecurity cooperation with European agencies, but the statement omits the one chapter of the EU General-Purpose AI Code of Practice that touches its core business model. The Copyright chapter requires a publicly available training data summary and a documented policy for complying with EU copyright law and the text-and-data-mining opt-out regime. OpenAI is a GPAI Code signatory. Starting August 2, the European AI Office gains the power to request information, access models, and impose fines of up to 15 million euros or 3% of global annual turnover for non-compliance. The gap is not new: researchers flagged that GPT-5 shipped last August without the required training data summary, and a 2026 benchmark study found that GPAI Code signatories score only marginally higher than non-signatories on exactly the upstream disclosures the regulation targets.

OpenAI endorsed the EU's AI Code of Practice but skipped the Copyright chapter, and enforcement powers activate tomorrow

OpenAI Signed the EU's AI Code. Its Compliance Statement Skips the Copyright Chapter.

OpenAI published a compliance statement Thursday titled "Advancing Responsible AI Across Europe." The document details safety frameworks, provenance watermarking partnerships, and cybersecurity cooperation with European agencies. It covers two of the three chapters of the EU General-Purpose AI Code of Practice. The third chapter, the one that would require OpenAI to publicly disclose what data trained its models, is absent. 1

The chapters OpenAI chose to showcase and the one it omitted serve different audiences. Safety frameworks help regulators evaluate how models behave. Provenance watermarking helps users identify synthetic content. Both describe work OpenAI had already committed to independently of EU regulation. A training data summary serves a different constituency: the creators, publishers, and rights holders who want to know whether their copyrighted work helped build the models now competing with them. That is the disclosure OpenAI has consistently declined to make.

Starting August 2, the omission stops being theoretical. The European Commission's enforcement powers activate, giving the AI Office authority to request information, access models, and impose fines of up to 15 million euros or 3% of global annual turnover for non-compliance with GPAI obligations. 2 1 The Code's Copyright chapter, which OpenAI's statement does not mention, requires signatories to publish a training data summary and maintain a documented policy for complying with EU copyright law and the text-and-data-mining opt-out regime. 1

The strategic logic is not complicated. Signing voluntary chapters that align with work you already do costs nothing. Publishing a training data summary invites scrutiny from two directions at once: copyright litigation from every publisher and creator whose work appears in the dataset, and competitive exposure from rival labs eager to learn what data gave your models their edge. The European Commission describes the Code of Practice as a voluntary, practical tool that explains how providers can fulfil their obligations. 2 A provider can endorse the chapters that reinforce its regulatory reputation and skip the one that threatens its legal and competitive position. Thursday's statement does exactly that.

This gap predates the statement. When OpenAI released GPT-5 on August 7, 2025, five days after GPAI obligations took legal effect, Euractiv reported that the model appeared to lack the required training data summary. 1 The compliance statement published this week describes the Preparedness Framework, C2PA watermarking, an EU Cyber Action Plan, and other governance mechanisms, but does not close that gap. 1

The pattern is industry-wide. A benchmark study published in mid-2026 found that GPAI Code signatories perform only slightly better than non-signatories on documentation quality, with the advantage concentrated in downstream disclosures rather than the upstream disclosures on training data and copyright-relevant data use that the regulation primarily targets. 1

That finding reframes what the Code actually measures. If signatories and non-signatories perform nearly identically on the disclosures the regulation cares about most, then signing the Code signals intent without producing the underlying compliance. Intent is valuable in regulatory diplomacy. It carries less weight when enforcement begins and the question shifts from whether you signed to whether you disclosed. OpenAI's statement is rich in the former and silent on the latter where its business model is concerned. The benchmark data suggests this is not an exception but the pattern: the Code's voluntary architecture lets providers sort into the chapters that cost them nothing and avoid the ones that do.

Starting Sunday, the European AI Office can request documentation, conduct evaluations, and impose financial penalties for the specific obligation that OpenAI's statement does not address. 2 Whether the office uses that power against its most prominent signatory will determine how every GPAI provider calculates the distance between endorsing a voluntary code and actually complying with one.

References

1.TechTimes, July 31 2026techtimes.com
2.European Commissiondigital-strategy.ec.europa.eu

Cite this story

ProvenBrief (2026). "OpenAI endorsed the EU's AI Code of Practice but skipped the Copyright chapter, and enforcement powers activate tomorrow." ProvenBrief. https://provenbrief.com/story/openai-endorsed-the-eu-s-ai-code-of-practice-but-skipped-the-copyright-chapter-a

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified16 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.