AI Policy Wiki
Dashboard

EU General-Purpose AI Code of Practice (Final Version, 2025)

high confidence · updated 2026-07-13

Source summary of the EU AI Act's voluntary General-Purpose AI Code of Practice — Transparency, Copyright, and Safety & Security chapters.

The EU General-Purpose AI Code of Practice is a voluntary instrument that GPAI model providers can use to demonstrate compliance with Articles 53 and 55 of the EU AI Act. It was published 10 July 2025 by the European Commission's AI Office and prepared by independent experts in a multi-stakeholder process; the Commission and the AI Board endorsed it via adequacy decisions on 1 August 2025. The framework is covered separately at EU General-Purpose AI Code of Practice (Final Version, 2025).

Summary

The Code is organised into three separately-authored chapters:

  1. Transparency — applies to all GPAI model providers. It includes a Model Documentation Form enabling providers to document Article 53 information.
  2. Copyright — applies to all GPAI model providers. It sets out approaches to EU copyright compliance, including handling of Text-and-Data-Mining (TDM) opt-outs.
  3. Safety and Security — applies only to providers of GPAI models with systemic risk (Article 55), addressing systemic risks for advanced and frontier models.

According to the AI Office, signatories gain reduced administrative burden and enhanced legal certainty compared with demonstrating compliance through alternative methods. Implementation is coordinated by the Signatory Taskforce, chaired by the AI Office.

Signatories

More than 27 organisations signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI. The Commission's signatory list, as updated April 23, 2026, names 23 full signatories — Accexible, AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, Lawise, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow, and WRITER — with the caveat that confirmed signatures are added on a continuing basis, and the signature process remains open via a form submitted to the AI Office (Source: digital-strategy.ec.europa.eu).

xAI signed only the Safety and Security chapter, not the Transparency or Copyright chapters; the Commission states that xAI "will have to demonstrate compliance with the AI Act's obligations concerning transparency and copyright via alternative adequate means" (Source: digital-strategy.ec.europa.eu). xAI signed the Seoul Commitments in full but only the Safety and Security chapter of the GPAI Code, a contrast relevant to discussions of AI Race Dynamics. The signatory set overlaps substantially with the Seoul Commitments: Amazon, Anthropic, Google, IBM, Microsoft, Mistral, and OpenAI appear on both.

Signatories have established a Signatory Taskforce, chaired by the AI Office, to facilitate coherent application of the Code; its rules of procedure and member list are set out in a Vademecum (Source: digital-strategy.ec.europa.eu).

Key claims

  • The European Commission and the AI Board confirmed the Code as an adequate voluntary tool for Article 53 and 55 compliance. Providers that sign receive a regulatory presumption of compliance. (high)
  • xAI signed only Safety and Security, declining the Transparency and Copyright chapters. The summary characterises this as a carve-out indicating resistance to copyright and transparency obligations while accepting the safety framing. (high)
  • The Copyright chapter is described as the primary mechanism by which the EU's Text-and-Data-Mining exception (Directive 2019/790) becomes enforceable against GPAI training data, the first major jurisdiction to operationalise it. (high)
  • The Safety and Security chapter applies only to GPAI with systemic risk — the AI Act's tier for models above a compute threshold (default 10^25 FLOPs). The summary states that most current frontier models qualify. (high)
  • The Code is technically voluntary, but absent signing a provider must demonstrate compliance through alternative methods the summary characterises as costlier and less predictable, which the summary frames as functioning as a soft mandate for market access. (high)

The Code is the direct implementation mechanism for EU AI Act (Regulation 2024/1689) Articles 53 and 55, the route through which the Act's GPAI obligations take effect. It cross-references the G7 Hiroshima Code of Conduct as part of the EU's adequacy narrative. The TDM opt-out operationalisation connects to copyright disputes including nyt-v-openai-microsoft and AB 2013 — Training Data Documentation (California).

Commission Guidelines on GPAI providers

The Code operates alongside the Commission's Guidelines on the scope of obligations for providers of general-purpose AI models under the AI Act (last updated 26 March 2026), summarised in EU AI Office — GPAI Provider Guidelines and Enforcement Framework. The Guidelines are the interpretive layer: the Commission's authoritative interpretation of who is a provider, what counts as a significant modification, how open-source exemptions apply, and what documentation the AI Office expects. The Code is the operational layer: the voluntary instrument that, once signed, gives providers a presumption of compliance with the obligations the Guidelines clarify. The two are designed to be read together — the Code addresses how a provider complies, the Guidelines whether they must. Commission enforcement powers, including fines, activate 2 August 2026.

Relationships