OpenAI and the EU AI Act
US-based AI lab behind the GPT model family, ChatGPT and the OpenAI API, one of the most widely deployed LLM providers.
What the Act means when you deploy OpenAI
OpenAI is a provider of general-purpose AI models, so the Act's GPAI provider obligations (technical documentation, information for downstream providers, copyright policy) sit with OpenAI — not with you. As a deployer you still own your side: transparency towards affected people where required, human oversight, and classifying your own use case, which may be high-risk regardless of the model behind it.
Questions to send OpenAI
Copy these into your supplier questionnaire. Answers in writing beat answers on a call — your Article 26 file needs evidence, not recollection.
- Q1
Can you provide the model documentation and information for downstream providers that the AI Act expects from GPAI providers, for the specific models we use?
- Q2
Is our API input and output used for training by default, and how do we opt out contractually?
- Q3
Do you offer EU data residency for our workload, and under which legal transfer mechanism is data processed outside the EU?
- Q4
Which DPA, security certifications and sub-processor list apply to our tier, and where are they published?
Documents to request for your file
- Instructions for use / product documentation for the exact service and version you deploy
- Model documentation and information for downstream providers, per model in use
- Data processing agreement, sub-processor list and processing locations
- Security documentation: certifications, retention defaults and access controls
- Written statement on whether your inputs and outputs are used for training, and how to opt out
- Licence terms for the exact version you deploy, including commercial-use conditions
Which of these you can actually obtain depends on your contract and tier — treat the list as a checklist to work through with the vendor, not as an entitlement.
Articles to have on the table
- Art. 53GPAI provider duties (the vendor's, not yours)
OpenAI is described here as a provider of general-purpose AI models. Technical documentation, information for downstream providers, a copyright policy and a training-content summary are obligations of the model provider — request the resulting artefacts for your own file.
- Art. 26Deployer obligations
If you use this vendor's technology professionally in a high-risk context, you must follow the instructions for use, assign competent human oversight, keep logs and monitor operation.
- Art. 25When you become the provider
Putting your own name on the system, changing its intended purpose or substantially modifying it moves you from deployer to provider — with Article 16 obligations attached.
- Art. 50Transparency towards people
Where people interact with an AI system, or where content is AI-generated or manipulated, disclosure and — in defined cases — machine-readable marking are required. This duty sits with you, not the vendor.
Most buyers of AI land in the deployer role. Read the full deployer obligations under Article 26 — or the overview of all operator roles if you are not sure which one you hold.
Go to the source
Verify everything on this page with OpenAI directly. Public pages change; profiles do not update themselves.
Important: what this page is not
This profile is based on publicly available information about OpenAI and describes only who they are and what they offer. It makes no assessment of OpenAI’s compliance, contains no rating or certification claim, and is not endorsed by or affiliated with OpenAI.
EU AI Act obligations depend on how you deploy this vendor's technology and on your role (provider, deployer, importer, distributor). Verify every fact and commitment directly with the vendor before relying on it — this profile is a starting point, not legal advice.
Nothing here is legal advice. Confirm the facts with the vendor and your own counsel before you rely on them.
Other vendors in Foundation models
Run the free 2-minute checker — deterministic classification, no sign-up.