Loading the catalogue…
Loading the catalogue…
OpenAI is a US-incorporated organisation (Delaware, HQ San Francisco) fully subject to US CLOUD Act and FISA jurisdiction, and it also runs its own first-party inference API — so both training and serving legs of any Stav-routed request carry US jurisdiction exposure. It holds substantial security certifications (SOC 2 Type 2, ISO 27001/27017/27018/27701, ISO 42001) and has established an Irish entity for EU GDPR lead-authority purposes, but its regulatory history includes a since-annulled Italian GDPR fine and open questions from EU regulators about GPT-5's AI Act training-data transparency obligations.
OpenAI is a US-incorporated (Delaware) entity with US HQ and operates its own first-party US-jurisdiction inference API (data_residency=global), fully exposing EU customer data and prompts to CLOUD Act and FISA 702 compulsion risk when using OpenAI's hosted models.
Italy's Garante fined OpenAI €15M in Dec 2024 for GDPR violations including lack of legal basis for training data processing, transparency failures, and late breach notification of a March 2023 incident; while a Rome court annulled the fine in March 2026 on a jurisdictional (one-stop-shop) technicality, the underlying merits of the violations were not overturned.
GPT-5 (released August 2025) reportedly lacked a published Article 53 training-data summary and copyright policy at launch, despite OpenAI being a GPAI Code of Practice signatory; European Commission assessment of compliance status was ongoing as of the most recent reporting found.
OpenAI's October 2025 conversion to a Public Benefit Corporation (from capped-profit nonprofit control) removed prior profit caps and was contested by cofounder Elon Musk and several nonprofit advocacy groups concerned about mission drift; OpenAI also served subpoenas to advocacy groups opposing the restructuring, which one critic characterized as intimidation.
Frequent senior leadership turnover: former CTO departed 2024, a board member resigned Nov 2025, and an April 2026 medical leave triggered a leadership reshuffle; there is currently no company-wide CTO.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
OpenAI's flagship closed-weight reasoning model with a 1.05M-token context window and mandatory reasoning on every request.
OpenAI's fast, cost-efficient GPT-5.6 tier for high-volume chat, classification, and lightweight agentic tasks with a 1.05M-token context window.
OpenAI maintains SOC 2 Type 2, ISO/IEC 27001:2022, 27017, 27018, 27701:2019, ISO/IEC 42001:2023 (AI management system), and PCI-DSS certifications, plus a public Bug Bounty program via Bugcrowd.
OpenAI was the first US company to sign the EU's General-Purpose AI Code of Practice in July 2025 and has since supported the Commission's Code of Practice on Transparency of AI-Generated Content.
OpenAI released gpt-oss-120b and gpt-oss-20b as genuinely open-weight models under Apache 2.0, with published model cards and Preparedness Framework safety evaluations.
Established OpenAI Ireland Limited as its EEA establishment and can execute GDPR-supporting Data Processing Addenda (DPAs) with enterprise customers.
OpenAI completed a structured recapitalization in October 2025 following nearly a year of engagement with the California and Delaware Attorneys General, resulting in continued nonprofit oversight (OpenAI Foundation) of the for-profit PBC.
Published safeguards & certifications
OpenAI's flagship GPT-5.6 reasoning model for agentic coding, cybersecurity, and long-horizon analysis, with a 1.05M-token context window.