Is OpenAI Ready for EU AI Regulations With GPT-5?

Compliance of OpenAI’s GPT-5 with EU AI Regulations

As the development of artificial intelligence continues to advance, the legal frameworks governing such technologies are becoming increasingly stringent. One significant piece of legislation is the EU AI Act, which establishes requirements for developers of general purpose AI models (GPAIs), including OpenAI’s latest model, GPT-5.

Training Data Disclosure Requirements

Under the EU AI Act, developers are mandated to publish summaries of the data used for training their models. This includes providing a list of the most relevant domain names crawled for data collection and any publicly available datasets utilized.

In July 2025, the AI Office of the EU released a template outlining these necessary disclosures. Notably, models released before August 2, 2025 have until 2027 to comply, while those introduced after this date are expected to adhere immediately.

OpenAI launched GPT-5 on August 7, 2025, just five days after the EU’s compliance deadline. However, as of now, OpenAI has not provided the required summary of GPT-5’s training data, raising questions about compliance.

Lack of Transparency

Attempts to obtain information regarding GPT-5’s compliance with the EU Act have been unsuccessful. OpenAI has not responded to inquiries about the model’s adherence to the training data disclosure requirements. Notably, CEO of LatticeFlow, Petar Tsankov, highlighted that OpenAI has yet to publish a training-data summary or a copyright policy for GPT-5.

Despite this lack of disclosure, OpenAI has signed the EU’s code of practice for GPAI developers, which encourages publishing a copyright policy. Nevertheless, there is no indication that such a policy has been made available for ChatGPT.

Systemic Risk Considerations

Tsankov also indicated that GPT-5 likely exceeds the threshold to be classified as a systemic risk model under the AI Act. This classification would require OpenAI to conduct comprehensive evaluations of the model and address potential systemic risks. However, there is currently no public evidence demonstrating that these evaluations have been undertaken.

It is essential to note that while the AI Act mandates evaluations for systemic risk models, there is no legal obligation for OpenAI to publicly disclose these assessments.

Regulatory Ambiguity

The European Commission has stated that whether GPT-5 complies with training data disclosures will depend on its classification as a new model under the AI Act. The AI Office is still analyzing this based on various non-public technical details.

OpenAI promotes GPT-5 as a new model, with Sam Altman comparing its significance to the Manhattan Project, the historic initiative responsible for developing the atomic bomb during WWII.

If the EU’s AI Office determines that GPT-5 is indeed a new model, OpenAI may find itself in a complex situation. Although immediate compliance may not be enforced until August 2026, the pressure for adherence to the Act’s rules is mounting.

As Tsankov aptly describes, the situation is akin to a speed limit sign that is already in place yet lacks active enforcement: exceeding the limit constitutes a violation, but consequences will not arise until enforcement begins.

As the landscape of AI continues to evolve, the implications of compliance with regulations such as the EU AI Act will be critical for developers like OpenAI.

More Insights

Revolutionizing Drone Regulations: The EU AI Act Explained

The EU AI Act represents a significant regulatory framework that aims to address the challenges posed by artificial intelligence technologies in various sectors, including the burgeoning field of...

Revolutionizing Drone Regulations: The EU AI Act Explained

The EU AI Act represents a significant regulatory framework that aims to address the challenges posed by artificial intelligence technologies in various sectors, including the burgeoning field of...

Embracing Responsible AI to Mitigate Legal Risks

Businesses must prioritize responsible AI as a frontline defense against legal, financial, and reputational risks, particularly in understanding data lineage. Ignoring these responsibilities could...

AI Governance: Addressing the Shadow IT Challenge

AI tools are rapidly transforming workplace operations, but much of their adoption is happening without proper oversight, leading to the rise of shadow AI as a security concern. Organizations need to...

EU Delays AI Act Implementation to 2027 Amid Industry Pressure

The EU plans to delay the enforcement of high-risk duties in the AI Act until late 2027, allowing companies more time to comply with the regulations. However, this move has drawn criticism from rights...

White House Challenges GAIN AI Act Amid Nvidia Export Controversy

The White House is pushing back against the bipartisan GAIN AI Act, which aims to prioritize U.S. companies in acquiring advanced AI chips. This resistance reflects a strategic decision to maintain...

Experts Warn of EU AI Act’s Impact on Medtech Innovation

Experts at the 2025 European Digital Technology and Software conference expressed concerns that the EU AI Act could hinder the launch of new medtech products in the European market. They emphasized...

Ethical AI: Transforming Compliance into Innovation

Enterprises are racing to innovate with artificial intelligence, often without the proper compliance measures in place. By embedding privacy and ethics into the development lifecycle, organizations...

AI Hiring Compliance Risks Uncovered

Artificial intelligence is reshaping recruitment, with the percentage of HR leaders using generative AI increasing from 19% to 61% between 2023 and 2025. However, this efficiency comes with legal...