European Union - General-Purpose AI Code of Practice

General-Purpose AI Code of Practice (voluntary Code of Practice for GPAI providers)

European Union

RAI-EU-NA-GACPVXX-2025
Effective: July 10, 2025
In Force(In Force)
GuidelineTransparency and DisclosureRisk ManagementSafety, Testing, and Evaluation
Export PDF

The EU General-Purpose AI Code of Practice (2025) offers voluntary guidelines for AI model providers to comply with the AI Act's transparency, copyright, and safety rules.

Summary

The General-Purpose AI Code of Practice (GPAI CoP) is a pivotal, voluntary instrument developed by the European Commission to facilitate compliance with the EU's AI Act, specifically addressing obligations for providers of general-purpose AI models. Published on July 10, 2025, it offers a 'rebuttable presumption of conformity' with mandatory AI Act obligations, reducing administrative burden and increasing legal certainty. The Code is structured into Transparency, Copyright, and Safety and Security chapters, with the latter tailored for systemic-risk models, ensuring human-centric and trustworthy AI within the EU.

Full article

Read full text ↗

Overview

The General-Purpose AI Code of Practice (GPAI CoP) is a pivotal, voluntary instrument developed by the European Commission to facilitate compliance with the European Union's landmark Artificial Intelligence Act (AI Act), specifically addressing the obligations for providers of general-purpose AI models. Published on July 10, 2025, after extensive multi-stakeholder consultations involving nearly a thousand participants, the Code serves as operational guidance for adhering to Articles 53 and 55 of the AI Act, which became applicable to GPAI models on August 2, 2025. Its primary objective is to foster the uptake of human-centric and trustworthy AI within the EU, while simultaneously ensuring a high level of protection for health, safety, and fundamental rights against potential harmful effects of AI systems. Although adherence to the Code is voluntary, it offers a significant advantage to signatories by providing a 'rebuttable presumption of conformity' with the mandatory AI Act obligations. This mechanism is designed to reduce the administrative burden on AI model providers and offer increased legal certainty, thereby encouraging robust compliance practices across the industry.

The Code is meticulously structured into three distinct chapters: Transparency, Copyright, and Safety and Security. The chapters on Transparency and Copyright are applicable to all providers of general-purpose AI models, outlining measures to ensure adequate documentation, information sharing, and adherence to EU copyright law. The Safety and Security chapter, conversely, is specifically tailored for providers of general-purpose AI models that pose systemic risks, providing comprehensive guidance on risk identification, assessment, mitigation, and continuous monitoring. This tiered approach reflects the risk-based framework of the underlying AI Act, ensuring that regulatory efforts are proportionate to the potential impact of different AI systems. The Code is complemented by Commission guidelines on key concepts related to general-purpose AI models, further clarifying its scope and application.

Definitions

Within the context of the General-Purpose AI Code of Practice and the broader EU AI Act, several key definitions are crucial for understanding the scope and application of the regulations. A 'General-Purpose AI (GPAI) model' refers to an AI model that is capable of performing a wide range of tasks and can be integrated into various downstream AI systems and applications. These models are often foundational, meaning they can be adapted to numerous specific uses across different domains, such as natural language processing, image recognition, and data analysis. The definition of a GPAI model is critical because the Code of Practice specifically targets providers of these models, helping them navigate their unique obligations under the AI Act. The AI Act itself provides a more detailed framework for classifying AI systems based on their risk levels, with GPAI models falling under specific provisions due to their widespread applicability and potential for systemic impact.

A particularly important concept is 'systemic risk,' which applies to GPAI models that are highly capable or widely used and could potentially lead to significant, widespread negative consequences. The AI Act uses criteria such as the cumulative amount of computing power used to train a model (e.g., exceeding 10^25 floating-point operations, or FLOPs) to identify models presumed to have high-impact capabilities and thus pose a systemic risk. The European Commission also retains the authority to classify a model as posing a systemic risk. Providers of GPAI models identified as carrying systemic risks face additional obligations under the AI Act and, consequently, within the Safety and Security chapter of the Code of Practice. These obligations include performing rigorous model evaluations, assessing and mitigating potential systemic risks, tracking and reporting serious incidents, and ensuring the cyber and physical security of their models. These definitions underscore the EU's proactive approach to regulating AI, focusing on the inherent capabilities and potential societal impact of AI technologies.

Governance and Institutional Framework

The governance and institutional framework surrounding the General-Purpose AI Code of Practice is intricately linked to the broader regulatory architecture established by the European Union's AI Act. The European Commission plays a central role in the development and oversight of the Code, having published the final version and confirmed its adequacy as a voluntary tool for demonstrating compliance with the AI Act. This demonstrates the Commission's commitment to providing practical guidance alongside the legally binding provisions of the AI Act. The EU AI Office, a dedicated body within the Commission, is instrumental in coordinating the multi-stakeholder process that led to the Code's creation and continues to work closely with signatories to facilitate its coherent application. The AI Office is also responsible for supporting providers in complying with the AI Act and will eventually enforce its obligations, including those related to GPAI models.

The Code's existence is directly mandated by Article 56 of the AI Act, which empowers the EU AI Office to develop such voluntary rulebooks to guide AI model providers in meeting their legal obligations, particularly those outlined in Articles 53 and 55. This hierarchical relationship ensures that the Code, while voluntary, is a critical component of the overall EU AI governance strategy. The AI Act itself establishes a comprehensive, risk-based regulatory framework for artificial intelligence, with different rules applying based on the level of risk an AI system poses. The Code of Practice, by offering a pathway to demonstrate conformity, integrates seamlessly into this framework, providing a practical bridge between the high-level legal requirements of the Act and the operational realities of AI development and deployment. The involvement of independent experts and a wide array of stakeholders in the drafting process further strengthens the Code's legitimacy and practical utility within the EU's AI governance landscape.

Key Focus Areas

The General-Purpose AI Code of Practice is structured around three critical chapters, each addressing distinct yet interconnected aspects of responsible AI development and deployment: Transparency, Copyright, and Safety and Security. The Transparency chapter is fundamental, aiming to ensure that providers of general-purpose AI models offer sufficient clarity regarding their models' characteristics and functionalities. This includes detailed documentation on technical specifications, training methodologies, data provenance, computational resources utilized, and energy consumption. A user-friendly Model Documentation Form is provided to streamline this process, enabling providers to consolidate necessary information in a single, accessible format. Furthermore, providers are expected to establish effective channels for timely information sharing with downstream users, empowering those users to conduct their own AI Act compliance assessments. This emphasis on transparency is crucial for fostering trust, enabling accountability, and allowing for informed decision-making throughout the AI value chain.

The Copyright chapter offers practical solutions for providers to establish policies that comply with existing EU copyright law, particularly concerning the data used for training AI models. Given the extensive datasets often employed in training general-purpose AI, addressing copyright considerations is paramount to avoid infringement and ensure legal certainty for both AI developers and rights holders. This chapter helps providers navigate the complexities of intellectual property rights in the context of AI development, promoting responsible data practices. The third chapter, Safety and Security, is specifically directed at providers of GPAI models that present systemic risks. It outlines a comprehensive risk management process that must be implemented before significant deployment decisions, such as releasing a new systemic-risk GPAI model or substantially updating an existing one. This includes identifying and assessing systemic risks, evaluating their acceptability, and implementing robust mitigation measures until an acceptable risk level is achieved. The chapter also covers obligations related to tracking and reporting serious incidents, as well as ensuring the cyber and physical security of the models. Together, these three chapters provide a holistic framework for responsible innovation in general-purpose AI, balancing technological advancement with ethical considerations and legal compliance.

Implementation Framework

The implementation framework for the General-Purpose AI Code of Practice is designed to be a practical and supportive mechanism for providers of general-purpose AI models in navigating the complex landscape of the EU AI Act. While adherence to the Code is entirely voluntary, it offers a significant incentive: a 'rebuttable presumption of conformity' with the mandatory obligations set out in Articles 53 and 55 of the AI Act. This means that if a provider can demonstrate that they are following the measures outlined in the Code, EU regulators will generally assume they are meeting the corresponding legal requirements of the AI Act. This 'safe harbor' provision is crucial for reducing the administrative burden on companies and providing greater legal certainty, especially as AI technology and regulations continue to evolve.

To benefit from this presumption of conformity, providers of general-purpose AI models are encouraged to voluntarily sign the Code of Practice. The process involves completing a Signatory Form and submitting it to the EU AI Office. The Code is intended to serve as a roadmap for compliance, and while it does not create new legally binding obligations, it provides concrete guidance on how to meet existing ones. The EU AI Office, in collaboration with a Signatory Taskforce, will work closely with signatories to facilitate a coherent application of the Code. This collaborative approach aims to support providers in achieving full compliance, recognizing good-faith efforts even if all commitments are not immediately implemented upon signing. However, it is important to note that while the Code is voluntary, compliance with the underlying AI Act is mandatory, and deviations from the Code may invite increased scrutiny from the EU AI Office.

Monitoring and Evaluation

The monitoring and evaluation of the General-Purpose AI Code of Practice are integral to its effectiveness and adaptability within the rapidly evolving AI landscape. The EU AI Office plays a central role in this process, working in close collaboration with the signatories of the Code through a dedicated Signatory Taskforce. This ongoing engagement ensures a coherent application of the Code's provisions and allows for continuous feedback and refinement. The AI Office's involvement is crucial for assessing how providers are demonstrating compliance with their obligations under the AI Act by adhering to the Code. This collaborative oversight mechanism helps to identify any gaps between the Code's recommendations and current AI documentation and practices, facilitating a proactive approach to compliance.

The Code of Practice is not intended to be a static document; rather, it is anticipated to be updated continuously by the EU AI Office. This dynamic approach is essential to keep pace with technological advancements in AI and emerging best practices. Such updates may involve refining existing measures, introducing new guidance, or adapting to new challenges posed by general-purpose AI models. The continuous monitoring and evaluation process also involves ensuring that the Code remains an adequate voluntary tool for providers to demonstrate compliance with the AI Act, thereby maintaining its utility and relevance. By fostering an environment of ongoing dialogue and adaptation, the EU aims to ensure that the Code of Practice remains a robust and effective instrument for promoting trustworthy and responsible AI development in the European Union.

Penalties, Liability, and Appeals

It is crucial to understand that the General-Purpose AI Code of Practice itself does not directly impose penalties, establish liability, or outline appeal mechanisms. As a voluntary tool, its primary function is to guide providers of general-purpose AI models in demonstrating compliance with the legally binding obligations set forth in the European Union's AI Act. Therefore, any penalties, liability provisions, or appeal processes are derived from the underlying AI Act, which is the comprehensive legal framework for artificial intelligence in the EU. Non-compliance with the mandatory requirements of the AI Act can lead to significant consequences, including substantial fines. For instance, the AI Act establishes a risk-based approach, with different levels of non-compliance potentially triggering varying degrees of penalties, particularly for high-risk AI systems and prohibited AI practices.

While adherence to the Code offers a 'rebuttable presumption of conformity' with the AI Act, thereby reducing the likelihood of regulatory scrutiny and potential penalties, it does not absolve providers of their ultimate legal responsibilities under the Act. If a provider fails to meet the mandatory obligations of the AI Act, even if they have attempted to follow the Code, they could still face enforcement actions by the EU AI Office and relevant national regulators. The AI Act includes provisions for reporting serious incidents and outlines the governance rules for high-risk AI systems, which indirectly relate to liability. Furthermore, the AI Act provides for the establishment of AI regulatory sandboxes to facilitate testing and innovation, which can also influence how compliance and potential non-compliance are assessed. Ultimately, while the Code offers a valuable pathway to compliance, the ultimate legal authority for penalties, liability, and appeals rests with the AI Act and the judicial systems of the EU Member States, with the Court of Justice of the European Union providing the binding interpretation of the Act.

Relationship to Other Instruments

The General-Purpose AI Code of Practice operates within a broader ecosystem of EU policy and regulatory instruments aimed at fostering trustworthy and human-centric artificial intelligence. Its most direct and fundamental relationship is with the EU AI Act (Regulation (EU) 2024/1689), which serves as the overarching legal framework for AI in the European Union. The Code is specifically designed to help providers of general-purpose AI models comply with the mandatory obligations stipulated in Articles 53 and 55 of the AI Act, particularly concerning transparency, copyright, and systemic risk management. It acts as a practical implementation tool, translating the high-level legal requirements of the Act into actionable guidance for industry stakeholders. Without the AI Act, the Code would lack its foundational legal basis and purpose, highlighting their symbiotic relationship.

Beyond the AI Act, the Code of Practice is also situated within the context of other significant EU AI strategies and initiatives. These include the 'AI Continent Action Plan,' launched in April 2025, which aims to position Europe as a global leader in AI by focusing on developing trustworthy AI technologies, enhancing competitiveness, and safeguarding democratic values. The Action Plan outlines measures to build AI infrastructure, increase access to data, strengthen AI skills, and facilitate the implementation of the AI Act. Complementing this is the 'Apply AI Strategy,' launched in October 2025, which focuses on accelerating the adoption and integration of AI across key industrial and public sectors within the EU, with a particular emphasis on supporting small and medium-sized enterprises (SMEs). The Apply AI Strategy encourages an 'AI first' policy and promotes a 'buy European' approach for AI solutions. The Code of Practice, by promoting compliance with the AI Act, indirectly supports the objectives of these broader strategies by ensuring that the AI deployed and developed within the EU adheres to high standards of safety, transparency, and ethical conduct, thereby contributing to the overall vision of an 'AI Continent.'

International Alignment

The European Union's General-Purpose AI Code of Practice, in conjunction with the foundational EU AI Act, is poised to have a significant impact on international AI governance and standards. The EU AI Act itself is recognized as the world's first comprehensive legal framework on artificial intelligence, setting a precedent for other jurisdictions grappling with AI regulation. Consequently, the Code of Practice, by providing detailed guidance for compliance with this pioneering legislation, contributes to shaping global best practices for the responsible development and deployment of general-purpose AI models. Its emphasis on transparency, copyright, and safety and security for GPAI models can serve as a benchmark for international discussions and regulatory initiatives.

The EU's approach to AI regulation, characterized by its risk-based framework and focus on human-centric and trustworthy AI, is already influencing legislative efforts in other countries. The Code of Practice, by offering a clear pathway for compliance, further solidifies the EU's leadership in this domain. While the Code is a voluntary instrument for EU-based providers, its principles and recommended practices may be adopted or adapted by companies operating internationally that seek to align with leading regulatory standards or prepare for similar regulations in other markets. The EU's commitment to fostering trustworthy AI through instruments like the Code of Practice underscores a broader ambition to ensure that AI development globally prioritizes ethical considerations, fundamental rights, and societal well-being. This proactive stance contributes to a global dialogue on AI governance, encouraging international alignment on crucial aspects of AI safety and accountability.

Implementation Timeline

MilestoneDateNotes
EU AI Act entered into force2024-08-01The overarching legal framework for AI in the EU.
Prohibited AI practices and AI literacy obligations applicable2025-02-02First set of AI Act provisions came into effect.
EU AI Continent Action Plan unveiled2025-04-09Outlines EU strategy to boost AI development and adoption.
General-Purpose AI Code of Practice published2025-07-10Voluntary tool to help comply with AI Act GPAI obligations.
GPAI obligations under AI Act applicable2025-08-02Rules for general-purpose AI systems in the AI Act became applicable.
Apply AI Strategy launched2025-10-09Aims to accelerate AI adoption across strategic sectors.
AI Act governance rules and GPAI obligations enforceable by AI Office (for new models)2026-08-02One year after GPAI obligations became applicable.
AI Act fully applicable2026-08-02Full applicability of the EU AI Act.
AI Act rules for high-risk AI systems embedded in regulated products applicable2027-08-02Extended transition period for specific high-risk systems.

Sources and References

SourceType
AI Act | Shaping Europe's digital future - European UnionGovernment
General-Purpose AI Code of Practice now available - European CommissionGovernment
The General-Purpose AI Code of Practice | Shaping Europe's digital futureGovernment
AI Continent Action Plan | Shaping Europe's digital futureGovernment
Apply AI Strategy | Shaping Europe's digital futureGovernment

Requirements for a company

What an organisation has to do under European Union - General-Purpose AI Code of Practice, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

9
  • Complete the Model Documentation Form with detailed model information.Providers of general-purpose AI models.
  • Establish clear channels for timely information sharing with downstream users.Providers of general-purpose AI models.
  • Implement a robust policy to ensure compliance with EU copyright law.Providers of general-purpose AI models.
  • Identify potential systemic risks for systemic-risk GPAI models.Providers of systemic-risk general-purpose AI models.
  • Assess and mitigate identified systemic risks until acceptable levels are achieved.Providers of systemic-risk general-purpose AI models.
  • Track and report serious incidents related to systemic-risk GPAI models.Providers of systemic-risk general-purpose AI models.
  • +3 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Consider signing the Code of Practice to gain presumption of conformity.Providers of general-purpose AI models.

Should not do

0

Nothing in this category.

Who must do what

The obligations under European Union - General-Purpose AI Code of Practice, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of general-purpose AI models.Complete the Model Documentation Form with detailed model information.
Complete the Model Documentation Form detailing AI model architecture, training data, computational resources, and energy consumption.
Before deployment or significant updateTransparency chapterImportant
2Providers of general-purpose AI models.Establish clear channels for timely information sharing with downstream users.
establish effective channels for timely information sharing with downstream users
ContinuouslyTransparency chapterImportant
3Providers of general-purpose AI models.Implement a robust policy to ensure compliance with EU copyright law.
establish policies that comply with existing EU copyright law, particularly concerning the data used for training AI models.
Before training or placing on marketCopyright chapterImportant
4Providers of systemic-risk general-purpose AI models.Identify potential systemic risks for systemic-risk GPAI models.
identifying and assessing systemic risks, evaluating their acceptability
Before major deployment or updatesSafety and Security chapterImportant
5Providers of systemic-risk general-purpose AI models.Assess and mitigate identified systemic risks until acceptable levels are achieved.
implementing robust mitigation measures until an acceptable risk level is achieved.
Before major deployment or updatesSafety and Security chapterImportant
6Providers of systemic-risk general-purpose AI models.Track and report serious incidents related to systemic-risk GPAI models.
tracking and reporting serious incidents
Upon occurrenceSafety and Security chapterImportant
7Providers of systemic-risk general-purpose AI models.Ensure robust cyber and physical security measures for systemic-risk GPAI models.
ensuring the cyber and physical security of their models.
ContinuouslySafety and Security chapterImportant
8Providers of systemic-risk general-purpose AI models.Implement a continuous risk management and governance process for systemic-risk models.
comprehensive risk management process that must be implemented before significant deployment decisions
ContinuouslySafety and Security chapterImportant
9Providers of general-purpose AI models.Balance transparency with intellectual property protection, allowing necessary redactions.
Balance transparency with intellectual property protection, permitting redactions where strictly necessary, subject to regulator inspection.
Before deployment or significant updateTransparency DocumentationImportant
10Providers of general-purpose AI models.Consider signing the Code of Practice to gain presumption of conformity.
providers of general-purpose AI models are encouraged to voluntarily sign the Code of Practice.
Implementation FrameworkRecommended

© Regulations.AI using Gemini 2.5 Flash · updated on 05-May-2026