Rupert Marais serves as a primary authority on the intersection of advanced technology and digital defense, specializing in the nuances of endpoint security and comprehensive cybersecurity strategies. With years of experience navigating the complexities of network management, he provides a critical lens through which we can examine the evolving landscape of artificial intelligence. In this conversation, we explore how major industry players are attempting to bridge the gap between rapid technological innovation and the stringent regulatory demands of the European Union. Marais offers deep insights into the internal frameworks and collaborative efforts required to maintain safety and transparency in an era where AI capabilities are advancing faster than ever before.
OpenAI has been vocal about its alignment with the EU AI Act’s General-Purpose AI Code of Practice, but how does an organization of this scale actually integrate such rigid legal requirements into its fast-moving development cycle?
The integration of these legal requirements is less about reacting to a checklist and more about embedding a structural philosophy into the very fabric of the development process. OpenAI utilizes two foundational internal frameworks—the Preparedness Framework and the Frontier Governance Framework—to ensure that every step of development is scrutinized. The Preparedness Framework, which was originally established in 2023 and received a significant update in 2025, serves as the rigorous baseline for identifying and managing high-level risks from advanced systems. By mapping these internal safety and security protocols directly onto the GPAI Code, the company creates a bridge between technical execution and legal compliance. It feels like a high-stakes balancing act where the “Model Spec” document acts as a public-facing manual for model behavior, ensuring that the team is not just building powerful tools, but building them with a clear, documented moral and legal compass.
When we look at the practical side of safety, such as pre-release testing and red-teaming, how do these external collaborations change the way a model is shaped before it ever reaches the public?
The shift toward a more open, collaborative safety culture is perhaps the most significant change in how these models are matured today. By utilizing the Red Teaming Network, the organization pulls in external experts who intentionally try to break the system or find hidden vulnerabilities, creating a sensory-rich environment of “stress testing” that an internal team simply cannot replicate alone. This isn’t just a corporate exercise; it involves deep-seated participation in the Frontier Model Forum and active collaboration with the US Center for AI Standards and Innovation and the UK AI Security Institute. These partnerships ensure that the testing benchmarks are not just proprietary secrets but are part of a broader, shared safety research initiative. When a model finally launches alongside its detailed system card, it is the result of thousands of hours of external scrutiny designed to ensure that the “shared bar” for safety and security is actually met.
The concept of AI provenance is becoming increasingly difficult as we move into multi-modal systems involving audio and video; what mechanisms are being used to ensure users can still trust what they see and hear?
Provenance is currently one of the most technical and frustrating hurdles in the industry because metadata is notoriously fragile and can be easily stripped away during platform transfers. To combat this, a layered approach is used that combines Content Credentials, based on the C2PA standard, with more resilient methods like SynthID watermarking. SynthID acts as a vital fallback signal, a hidden digital fingerprint that remains even if the more visible metadata is lost in transition. We are seeing this coverage expand from simple image labels into audio outputs, with a concerted effort to move toward text provenance as the underlying tooling matures. It is an acknowledgment that no single cryptographic signal is a silver bullet, but by layering these technologies, developers can provide a much higher degree of transparency for the end-user.
In early May 2026, the EU Cyber Action Plan was launched to help defenders use AI more effectively, but how do we manage the reality that these same capabilities could easily be used by attackers?
This is the classic “double-edged sword” of cybersecurity, where the very tools that allow a defender to spot a vulnerability are the same ones that could allow a malicious actor to exploit it first. The response to this dilemma has been the creation of the Trusted Access for Cyber program, which is specifically designed to provide vetted defenders with access to advanced capabilities while keeping them out of the hands of bad actors. This program’s European deployment involves working directly with national cyber agencies, private sector partners, and infrastructure operators to bolster the continent’s overall resilience. While the measurable defensive gains are still being evaluated, the intent is to align with the European Commission’s Action Plan on Cybersecurity and AI by providing secure, controlled access arrangements. It feels like a tactical deployment of high-grade digital armor, given only to those who have proven they are on the front lines of defense.
What is your forecast for the future of AI governance as these models and regulations continue to evolve in tandem?
My forecast is that AI governance will move away from being a static set of rules and toward a “living” ecosystem where compliance is a moving target rather than a finished product. We will see a shift where internal frameworks like the Frontier Governance Framework become industry-standard starting points for any organization building on top of large-scale models. As implementation of the EU AI Act continues, the relationship between regulators and tech companies will become more symbiotic, necessitating a flexibility that allows rules to adapt as quickly as the technology itself. Ultimately, businesses in regulated markets will have to treat these initial transparency codes and system cards as the minimum requirement, realizing that true due diligence requires constant, proactive engagement with the evolving safety landscape.
