GPAI Code of Practice
The GPAI Code of Practice is the European Union's voluntary, versioned soft-law instrument for helping providers of general-purpose AI models demonstrate compliance with specified AI Act obligations. Its separately authored chapters cover transparency, copyright, and safety and security. Signing is optional, and the Code is not the AI Act itself; providers that do not rely on it must demonstrate compliance through other adequate means.
Origin and context
The Commission published the first Code on 10 July 2025 after a multi-stakeholder drafting process led by independent experts. The Commission and AI Board endorsed it as an adequate voluntary tool. The transparency and copyright chapters address Article 53 obligations for GPAI-model providers, while the safety and security chapter is relevant to providers of GPAI models with systemic risk under Article 55. European Parliament research describes the Code as central to implementing the Act and as contested policy terrain.
Why it matters
The Code converts broad legal duties into more concrete commitments, documentation practices, and risk-management measures. For signatories, adherence can reduce administrative burden and increase legal certainty. For evaluators, procurement teams, and civil society, the chapters provide a public reference point. Because it remains voluntary and versioned, a signature is not proof of complete compliance, and the live scope, implementation guidance, and provider status must be checked at the time of an assessment.
Example
A GPAI provider may sign the applicable chapters, map each commitment to internal controls and evidence, and use those materials to demonstrate compliance. A provider of a model classified as presenting systemic risk would additionally address the safety and security chapter. A non-signatory still remains subject to applicable AI Act obligations and needs an alternative adequate compliance route; a procurement team should therefore ask for evidence, not only a signatory label.
How it differs
EU AI Act
The EU AI Act contains binding legal obligations. The GPAI Code is a voluntary compliance instrument recognized within that regime. It can help demonstrate compliance but does not replace the Act, change which provider is in scope, or remove supervisory powers.
GPAI / systemic risk
GPAI with systemic risk is an EU legal model classification. The Code is an implementation instrument: two chapters can serve all covered GPAI providers, while its safety and security chapter specifically addresses the smaller systemic-risk group. The classification and the Code should remain separate records.
Maturity and evidence
Maturity is rated 5 because the Code is an official, published instrument integrated into implementation of binding EU AI Act duties, with confirmed institutional assessment and an active signatory process. The rating does not make the Code mandatory or immutable. Its voluntary status, chapters, versions, and continuously updated signatory list must remain explicit.
Limits and open questions
Soft-law detail can support consistency but also age as guidance, model practices, and legal interpretation develop. Public signature does not by itself establish whether each commitment is implemented effectively. The Commission page last updated on 31 July 2026 displayed 21 full-Code signatories and a safety-and-security-only signature from xAI, while warning that the list is continuously updated. Users should date-stamp checks and inspect chapter-level scope and evidence.
Related terms
References
- The General-Purpose AI Code of PracticeEuropean Commission · 2025-07-10 · class A
- The European Union's AI code of practiceEuropean Parliamentary Research Service · 2025-08-27 · class B
Last updated: 2026-09-04
This term is also covered in the Skills Atlas as eu ai act compliance skill.
This term is also covered in the Skills Atlas as ai auditability skill.
This term is also covered in the Skills Atlas as ai risk management skill.