OpenAI、EU AI 法に基づく GPAI コードに安全対策を整合
本文の状態
日本語全文を表示中
詳細モードで約6分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
AI News
OpenAI は EU AI 法に基づく GPAI コードへの準拠方針を明らかにし、既存の安全対策や透明性フレームワークが基準を満たすと主張した。
AI深層分析を開く2026年8月1日 00:13
AI深層分析
キーポイント
EU 規制への準拠姿勢表明
OpenAI は EU の一般目的 AI(GPAI)コードおよび生成コンテンツ透明性コードに貢献し、自社の安全・セキュリティ・透明性作業がこれらの基準と整合していることを示した。
内部フレームワークの活用
同社は 2023 年に導入され 2025 年に更新された「準備度フレームワーク」と、法的要件とのマッピングを示す「フロンティアガバナンスフレームワーク」を用いてリスク管理を行っている。
コンテンツの真正性保証
C2PA 標準に基づくコンテンツ認証と SynthID ウォータマーキングを組み合わせ、画像・音声からテキストへも対象を広げながら生成 AI コンテンツの識別を目指す。
欧州向けサイバーセキュリティ対策の展開
OpenAI は 2026 年 5 月初めに EU サイバーアクションプランを立ち上げ、EU および各国のサイバー機関やインフラ事業者に対して高度なサイバーモデルへのアクセスを提供している。
規制対応の柔軟性と継続的な学習
同社は技術の進展に合わせてルールが柔軟である必要があると主張し、EU AI Act の実施に伴いコンプライアンスアプローチを調整していく方針を示した。
重要な引用
OpenAI points to a stack of existing practices as evidence it already operates near that bar
The stated goal is shared safety research and clearer testing benchmarks across the industry, not just within one company's walls.
None of this solves provenance outright. Metadata gets lost and labels don't always survive a transfer between platforms.
OpenAI believes the answer is its Trusted Access for Cyber programme, designed to give vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse.
編集コメントを表示
編集コメント
OpenAI は規制対応を単なるコンプライアンスとしてではなく、業界全体の安全研究共有の基盤として位置付けている点が注目される。ただし、メタデータの紛失やプラットフォーム間での転送によるラベル消失といった技術的課題は依然として残っており、完全な解決には至っていない。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
EU AI 法に基づく GPAI コードの施行が迫る中、OpenAI は自社の安全性・セキュリティ・透明性への取り組みが同コードとどのように整合しているかを明らかにしました。
同社は EU の一般目的型 AI(GPAI)行動規範および生成 AI コンテンツの透明性に関する行動規範に貢献し、支持しています。これらは多様なステークホルダーによるプロセスを経て策定されたものです。
GPAI コードは、EU で販売または導入される一般目的モデルに対する透明性・安全性・セキュリティの共通基準を定めています。OpenAI は、既存の取り組みがすでにこの基準にほぼ達していることを示す証拠として、モデルのリリース前テスト、主要なローンチに伴うシステムカードの公開、および「レッドチームネットワーク」と呼ばれる外部によるレッドチームングを挙げています。また、同社はモデルの振る舞いをどのように形成するかを記した公開文書「Model Spec」も維持しています。
これらの取り組みを支える内部フレームワークが 2 つあります。「準備性フレームワーク(Preparedness Framework)」は 2023 年に導入され、2025 年に更新されました。これは先進的なシステムから生じる重大なリスクを特定・評価・管理する方法を定めています。これとは別に、「フロンティアガバナンスフレームワーク(Frontier Governance Framework)」が構築されており、OpenAI の安全性・セキュリティの取り組みが GPAI コードを含む法的要件とどのように対応しているかを説明しています。
OpenAI によれば、この 2 つの文書はリスク評価、セーフガード、モデル報告、セキュリティ体制、インシデント対応、および外部専門家の関与方法を一貫して管理するものです。
OpenAI は、フロンティア・モデル・フォーラムへの参加や、米国 AI 標準・イノベーションセンター、英国 AI セキュリティ研究所との連携、そして第三者による評価基準への貢献などを通じて、EU の AI 法における GPAI コードに準拠した安全対策を強化しています。同社が掲げる目標は、自社内の取り組みにとどまらず、業界全体で共通の安全性研究を進め、明確なテストベンチマークを確立することです。
生成されるコンテンツの種類が増えるほど、その出所を追跡するのは難しくなります。
トランスパレンシー・コード(透明性コード)へのコミットメントは、AI によって作成または改変されたコンテンツを人々が識別できるよう支援するという、別の課題に焦点を当てています。
OpenAI のアプローチは、相互に補強し合う2 つの仕組みに基づいています。C2PA 標準を採用した「コンテンツ・クレデンシャルズ」は、ファイル自体に文脈情報を直接付与します。また、メタデータが途中段階で削除されてしまった場合のために、「SynthID」による透かし信号も用意されています。
現在、この対策は画像から音声出力へと適用範囲を広げており、OpenAI は基盤となる標準やツールの成熟に伴い、テキストを含むさらに多くのモダリティにも同様の出所追跡措置を拡大する方針です。さらに、自社のモデルの上にアプリケーションを開発する開発者に対し、透明性義務を果たすためのシグナルやガイダンスの提供も進めています。
この仕組みだけで、情報の出所を完全に保証できるわけではありません。メタデータは失われやすく、プラットフォーム間での転送時にラベルが維持されないケースも少なくありません。暗号化や透かし技術といった単一のシグナルだけでは、すべてのリスクを網羅することはできません。OpenAI の対応は、特定の手法で課題を解決できると主張するのではなく、多層的なアプローチを採用し、広範な標準化コミュニティとの連携を継続していくという姿勢です。
適応型ガバナンスの試金石としてのサイバーセキュリティ
防御側が脆弱性を発見・修正するために必要な機能は、攻撃者がそれらを見つけ出すためにも利用され得ます。OpenAI はこの課題に対する解決策として、「Trusted Access for Cyber」プログラムを提唱しています。これは、信頼性の高い防御者に対して高度なサイバー能力へのアクセスを提供する一方、悪用によるリスクを最小限に抑えることを目的としています。
同プログラムには現在、欧州向けの展開部門が設けられています。OpenAI は 2026 年 5 月初旬、「EU サイバーアクションプラン」を発表し、EU および各国のサイバー機関、民間セクターのパートナー、インフラ運営企業と連携して、これらの組織に対し高度なサイバーモデルへのアクセスを提供しています。
この計画の明らかな目的は、欧州全体におけるサイバーレジリエンス(回復力)の強化です。ただし、「最も先進的な」能力が実際に各機関内で測定可能な防御効果をもたらしているかどうかについては、OpenAI 自身の主張に留まっており、プログラムの成果を裏付ける独立した検証データは提示されていません。
同社は今回の取り組みを、欧州委員会のサイバーセキュリティおよび人工知能に関する行動計画と整合するものとして位置付けています。この計画では、AI のリスクを管理すると同時に、防御能力の強化に活用することを求めており、特にサイバーセキュリティ目的のための安全なアクセス体制の整備も含まれています。
OpenAI は、EU AI 法の実施が進むにつれてコンプライアンス対応を継続して調整していく方針を示しています。また、規制当局やルール形成に関わる幅広いコミュニティから学び続けることも明言しました。同社は、技術の進化に合わせて柔軟に対応できる余地のある規則が必要であり、企業や組織がその恩恵を受け続けられるようにすべきだと主張しています。
GPAI コードとトランスパレンシー・コードはいまだ比較的新しい枠組みであり、OpenAI のコンプライアンス文書も完成品というよりは、常に更新され続ける対象です。規制の厳しい欧州市場で OpenAI のモデルをベースに開発を行うチームは、現在のシステムカードやフロンティア・ガバナンス・フレームワークを、自社のデューデリジェンスのための出発点として捉えるべきであり、それを代替するものとして安易に扱うべきではありません。
関連記事:ザッカーバーグ氏がメタの個人向けAIスーパーインテリジェンス戦略の詳細を明かす

本記事は TechForge Media が提供する AI News で配信されています。その他の企業向け技術イベントやウェビナーについては、こちらからご確認ください。
※本記事「OpenAI aligns safety practices with EU AI Act’s GPAI Code」の初出は AI News です。
原文を表示
OpenAI has outlined how it aligns safety, security, and transparency work with the EU AI Act’s GPAI Code as enforcement approaches.
The company has contributed to and endorsed the EU’s General-Purpose AI (GPAI) Code of Practice and the Code of Practice on Transparency of AI-Generated Content. Both emerged from multi-stakeholder processes.
The GPAI Code sets a shared bar for transparency, safety, and security across general-purpose models sold or deployed in the EU. OpenAI points to a stack of existing practices as evidence it already operates near that bar: pre-release testing of models, published system cards accompanying major launches, and outside red-teaming through what it calls its Red Teaming Network. The company also maintains a public Model Spec document describing how it shapes model behaviour.
Two internal frameworks sit underneath that work. The Preparedness Framework has been in place since 2023 and was updated in 2025; it sets out how OpenAI identifies, evaluates and manages serious risks from advanced systems. A separate Frontier Governance Framework builds on it, explaining how the company’s safety and security practices map onto legal requirements including the GPAI Code specifically.
Together, OpenAI says, those two documents govern risk assessment, safeguards, model reporting, security posture, incident response, and how external experts get pulled into the process.
OpenAI cites its participation in the Frontier Model Forum alongside collaborations with the US Center for AI Standards and Innovation and the UK AI Security Institute, plus contributions to third-party evaluation standards more broadly. The stated goal is shared safety research and clearer testing benchmarks across the industry, not just within one company’s walls.
Provenance gets harder as modalities multiply
The Transparency Code commitments centre on a different problem: helping people tell when content was made or altered by AI.
OpenAI’s approach rests on two mechanisms that are meant to reinforce each other. Content Credentials, built on the C2PA standard, attach context directly to a file. SynthID watermarking provides a fallback signal for cases where that metadata gets stripped out somewhere along the way.
Coverage is expanding from images into audio outputs, and OpenAI says it’s working toward extending provenance measures across further modalities, including text, as the underlying standards and tooling mature. The company is also building signals and guidance aimed at developers who need to meet their own transparency obligations when building on top of its models.
None of this solves provenance outright. Metadata gets lost and labels don’t always survive a transfer between platforms. No single signal, whether cryptographic or watermark-based, catches everything on its own. OpenAI’s response is a layered approach paired with continued work across the wider standards community rather than a claim that any one mechanism closes the gap.
Cybersecurity as the test case for adaptive governance
Capabilities that help defenders spot and patch vulnerabilities are the same capabilities that could help an attacker find them first. OpenAI believes the answer is its Trusted Access for Cyber programme, designed to give vetted defenders access to more advanced cyber capabilities while limiting exposure for misuse.
That programme now has a European deployment arm. OpenAI states it launched its EU Cyber Action Plan in early May 2026, working with EU and national cyber agencies, private sector partners, and infrastructure operators to give them access to its more advanced cyber models.
The stated aim of the plan is to strengthen cyber resilience across the continent. Whether “most advanced” translates into measurable defensive gains inside these agencies is a claim from OpenAI itself; the source material offers no independent verification of outcomes from the programme.
The company positions this work as consistent with the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, which calls for coordinated handling of AI’s risks alongside its use in strengthening defensive capability, including secure access arrangements for cybersecurity purposes specifically.
OpenAI says it will keep adjusting its compliance approach as EU AI Act implementation continues, and that it expects to keep learning from regulators and the wider community involved in shaping the rules. The company argues that rules need enough flexibility to adapt as the technology moves, so that businesses and organisations can keep benefiting from it.
The GPAI Code and the Transparency Code are still relatively new instruments, and OpenAI’s compliance documentation is a moving target rather than a finished product. Teams building on OpenAI’s models in regulated European markets should treat the current system cards and Frontier Governance Framework as a starting point for their own due diligence, not a substitute for it.
See also: Zuckerberg details Meta’s personal AI superintelligence strategy

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post OpenAI aligns safety practices with EU AI Act’s GPAI Code appeared first on AI News.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み