AI Policy Wiki
Dashboard

EU General-Purpose AI Code of Practice (2025)

high confidence · updated 2026-08-06

Voluntary implementation tool for providers of general-purpose AI models under the EU AI Act Articles 53 and 55 — Transparency, Copyright, and Safety & Security chapters.

The General-Purpose AI Code of Practice (Final Version) is a voluntary implementation tool for providers of general-purpose AI (GPAI) models placed on the EU market. It operationalizes the obligations the EU AI Act imposes on GPAI providers under Article 53 (all GPAI models) and on providers of GPAI models with systemic risk under Article 55. Signatories gain a regulatory presumption of compliance and reduced administrative burden relative to demonstrating Article 53/55 compliance through alternative methods.

Full title: General-Purpose AI Code of Practice (Final Version) Enacting body: European Commission AI Office, via independent expert working groups in a multi-stakeholder process Legal status: Voluntary; confirmed an "adequate voluntary tool" for demonstrating compliance with EU AI Act Articles 53 and 55 Scope: Providers of general-purpose AI models placed on the EU market; Chapter 3 applies only to GPAI models with systemic risk

Status and timeline

The Code was published 10 July 2025 and endorsed 1 August 2025 by the European Commission and the AI Board through adequacy decisions. Both bodies' endorsement established it formally as an "adequate voluntary tool," a term of art in the EU AI Act's regulatory architecture.

The underlying Chapter V obligations on GPAI model providers applied from 2 August 2025, but the Commission's supervision and enforcement powers over those providers did not take effect until 2 August 2026 (Source: artificialintelligenceact.eu). Until that date, the Code's presumption-of-compliance mechanism operated without the backstop of actual penalties; after it, signing functions as a regulatory shield against enforcement. See EU AI Office — GPAI Provider Guidelines and Enforcement Framework for the implementation-reality picture, including the gap in which 8 of 27 member states had not designated competent authorities as of March 2026.

Enforcement from 2 August 2026

The Commission announced on 31 July 2026 that from 2 August 2026 the AI Office, together with national authorities, would begin enforcing the AI Act (Source: digital-strategy.ec.europa.eu). The AI Office holds enforcement powers over GPAI models specifically: it can request technical documentation, evaluate models, require corrective measures, and issue fines for non-compliance (Source: digital-strategy.ec.europa.eu).

The Commission has exclusive competence to supervise and enforce Chapter V obligations under Article 88; Article 89(1) tasks the AI Office with monitoring GPAI model providers' compliance and, where relevant, their adherence to the approved codes of practice — the provision that gives the Code its supervisory role. Articles 91 to 93 confer the non-fining powers (to request documentation and information, to conduct evaluations, and to request measures concerning compliance, risk mitigation, market restriction, recall, and withdrawal), and Article 101 confers the power to impose fines. Failing to comply with an Article 91 documentation request or an Article 92 model-access request is itself a finable infringement (Source: artificialintelligenceact.eu). Article 101 penalties reach up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Source: medialaws.eu).

Alongside enforcement, the Commission opened three reporting channels: an AI Act complaints tool, an AI Act whistleblower tool, and a dedicated complaints channel for downstream providers using general-purpose AI models (Source: digital-strategy.ec.europa.eu).

New transparency rules applied from the same date, requiring certain AI systems to disclose to users that they are interacting with AI rather than a human, requiring deepfakes to be labelled, and requiring AI-generated or altered content to carry machine-readable marks. These are operationalised by a separate instrument, the Code of Practice on Transparency of AI-generated Content, for which the Commission published a first list of more than 180 signatory organisations (Source: digital-strategy.ec.europa.eu).

Scope and definitions

The Code covers providers of general-purpose AI models placed on the EU market. Article 53 obligations apply to all GPAI providers; Article 55 obligations apply to providers of GPAI models with systemic risk, defined by default as models trained above the 10^25 FLOPs compute threshold. Chapter 3 of the Code is limited to providers in this Article 55 category.

Key provisions

The Code is organized into three chapters.

Chapter 1 (Transparency) applies to all GPAI model providers and implements the model, training, and data documentation obligations of Article 53. It includes a Model Documentation Form allowing providers to record the information Article 53 requires.

Chapter 2 (Copyright) also applies to all GPAI model providers. It sets out practical approaches for EU copyright compliance, notably Text-and-Data-Mining (TDM) opt-out handling under Directive 2019/790, operationalizing the EU's TDM opt-out against training data for the first time.

Chapter 3 (Safety and Security) applies only to providers of GPAI models with systemic risk under Article 55. It addresses systemic risks for advanced and frontier models, covering state-of-the-art risk assessment, mitigation, model weight security, incident reporting, and red-teaming. It overlaps functionally with the Anthropic RSP and OpenAI Preparedness Framework.

Obligations by actor and signatories

Interested providers submit a Signatory Form to the AI Office. The Signatory Taskforce, chaired by the AI Office, facilitates implementation coherence. More than 27 organizations have signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI as full signatories. xAI signed only Chapter 3 (Safety and Security), declining the Transparency and Copyright chapters.

The Code is technically voluntary, but functions as a soft mandate: absent signing, providers must demonstrate Article 53/55 compliance through costlier and less predictable alternatives. Commentators describe this as voluntary in form but functionally required for efficient EU market access. xAI's decision to sign only Chapter 3 has been read as accepting the safety framing while rejecting the transparency and copyright obligations.

Companion Commission guidelines

The Code is paired with the Commission's Guidelines on the scope of obligations for providers of general-purpose AI models under the AI Act (last updated 26 March 2026), the interpretive instrument that defines who is a GPAI provider, what qualifies as a significant modification, and how open-source exemptions apply. Together they form a two-layer GPAI compliance structure.

LayerInstrumentFunction
InterpretiveCommission Guidelines (Mar 2026, living document)Defines scope — whether a party is a provider and what it owes
OperationalGPAI Code of Practice (Jul 2025, voluntary)Defines method — how to demonstrate compliance

Relation to other frameworks

The Code is the implementation layer for the EU AI Act: the AI Act sets the binding obligations, and the Code provides an approved means of demonstrating compliance.

Chapter 3 is functionally similar to Outcomes 1–3 of the Seoul Commitments, with substantial signatory overlap (Amazon, Anthropic, Google, Microsoft, OpenAI, Mistral). The Seoul Commitments are globally voluntary, whereas the GPAI Code is gated to EU-market access. The Code explicitly cross-references the G7 Hiroshima Code as part of its adequacy argument; the Hiroshima Code covers broader terrain (11 Actions) while the GPAI Code is narrower but operationally binding. Relative to the Anthropic RSP and OpenAI Preparedness Framework, Chapter 3 sets a floor, with company-specific Responsible Scaling Policies operating above it through their own capability thresholds and deployment triggers.

Contested points

The operationalization of the TDM opt-out is contested: rights-holders argue opt-out enforcement is insufficient, while AI providers argue opt-out handling is over-burdensome. The Copyright chapter has been described as likely to face legal challenge.

The systemic-risk threshold is compute-based. The 10^25 FLOPs threshold captures current frontier models but may require periodic revision as compute efficiency improves; see Distillation and DeepSeek-R1 on the efficiency frontier.

Relationships