A voluntary framework, three chapters, and a practical route for general-purpose AI providers to demonstrate Chapter V compliance.
Educational content, not legal advice. AI regulation is fast-moving and jurisdiction-specific. Verify every obligation and deadline against the primary legal text and consult qualified counsel before making compliance decisions. Accurate as of the research date shown in the metadata below.What the Code of Practice is
The General-Purpose AI (GPAI) Code of Practice is a voluntary compliance tool published on 10 July 2025. It was developed through a multi-stakeholder process facilitated by the European Commission's AI Office and chaired by independent experts, with input from GPAI providers, industry, academia and civil society. The Code is designed to help providers of general-purpose AI models demonstrate compliance with their obligations under Chapter V of the AI Act (Articles 53 and 55), which have applied since 2 August 2025.
Signing is not mandatory. A provider can comply with Chapter V by other means. But the Code is the Commission's preferred route: adherence gives providers a clearer, lower-friction path to demonstrating conformity, and the AI Office has indicated it will focus its attention on providers that do not sign.
The three chapters
The Code is structured into three chapters. The first two apply to all in-scope GPAI providers; the third applies only to models that carry systemic risk.
1. Transparency
Establishes how signatories meet the documentation duties in Article 53(1)(a)-(b) and Annexes XI and XII. Its centrepiece is a standardised Model Documentation Form: signatories keep up-to-date documentation about the model and make relevant information available to the AI Office and to downstream providers who integrate the model, so that critical information flows through the value chain.
2. Copyright
Signatories commit to putting in place a copyright policy that complies with EU law. That includes respecting reservations of rights expressed under the text-and-data-mining exception of the Copyright in the Digital Single Market Directive (for example, machine-readable opt-outs such as robots.txt), taking reasonable measures not to train on pirated sources, and providing a point of contact for rightsholders.
3. Safety and Security
Applies only to GPAI models with systemic risk. Under Article 51, a model is presumed to pose systemic risk when it has high-impact capabilities, with cumulative training compute above 10^25 floating-point operations used as the indicative threshold. This chapter carries the bulk of the commitments: adopting a Safety and Security Framework, conducting state-of-the-art model evaluations and adversarial testing, assessing and mitigating systemic risks, reporting serious incidents to the AI Office, and ensuring adequate cybersecurity of the model and its weights.
Who has signed
A broad set of major model providers signed, including OpenAI, Anthropic, Microsoft, Amazon, IBM, Google and the European providers Mistral AI and Aleph Alpha. The picture is not uniform:
- Most signatories adhere to all three chapters.
- xAI signed only the Safety and Security chapter, declining the Transparency and Copyright chapters.
- Meta publicly declined to sign the Code, opting to demonstrate Chapter V compliance by other means.
The AI Office maintains a signatory list and continues to invite providers to adhere. Signing is an ongoing commitment, not a one-off certification.
How a provider actually uses the Code
- Determine scope. Are you a provider of a GPAI model placed on the EU market? Fine-tuning or substantially modifying a model can make you a provider for that modified model.
- Assess systemic risk. Estimate cumulative training compute and capability level against the Article 51 criteria to know whether the Safety and Security chapter applies to you.
- Adopt the transparency documentation. Complete and maintain the Model Documentation Form and set up the channel to share information with the AI Office and downstream providers.
- Stand up a copyright policy. Implement opt-out honouring, provenance controls on training sources, and a rightsholder contact point.
- For systemic-risk models, build the Safety and Security Framework: evaluations, red-teaming, incident reporting workflows, and model/weight security.
- Sign, then keep it current. Signing signals intent to comply; the substantive work is continuous.
Downstream integrators benefit too. Because the Transparency chapter forces standardised model documentation upstream, teams building on a GPAI model should ask their vendor for the Model Documentation Form. It is often the fastest way to get the technical information you need for your own high-risk or transparency obligations.What is at stake if you get it wrong
Chapter V obligations are enforceable. The AI Office supervises GPAI providers directly, and under Article 101 the Commission can impose fines on GPAI providers of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher, for infringements. Non-signatories are not exempt from the underlying obligations; they simply carry a heavier burden of showing, on their own terms, that they meet them. For most providers, the Code is the path of least resistance to the same destination.
The Code is also a template for what regulators expect of frontier model governance more broadly. Even organisations outside its formal scope increasingly use its structure, evaluations, incident reporting, and model documentation, as a reference for internal AI governance.