GPAI Code of Practice and systemic risk

What is the GPAI Code of Practice?

The General-Purpose AI Code of Practice is a voluntary document that a provider of a general-purpose AI model can sign to show how it meets its duties under the EU AI Act. The Commission published it on 10 July 2025, written by thirteen independent experts with input from over a thousand stakeholders, and on 1 August 2025 the Commission and the AI Board confirmed it as an adequate tool for demonstrating compliance.

The word voluntary cuts in one direction only. Signing is optional. What sits underneath is not. Articles 53 and 55 bind every provider of a general-purpose model whether or not they sign anything, and Article 55(2) says a provider who does not rely on an approved code has to demonstrate alternative adequate means of compliance for the Commission to assess.

It works like a sector agreement next to a safety law. The law says the workplace has to be safe. The agreement says here is the checklist our sector settled on, and an inspector who sees you following it asks fewer questions. Skip it and the workplace still has to be safe. You just have to make the argument yourself. The code says the same about itself: adherence is not conclusive evidence of compliance. What a signature buys, in the Commission's wording, is a lower administrative burden and more legal certainty.

The three chapters, and who each one binds

Transparency applies to every provider and covers the documentation duties in Article 53(1)(a) and (b). Its practical output is the Model Documentation Form, one form holding what Annex XI asks for: the tasks the model performs, the architecture and parameter count, the input and output modalities, the licence, the type and provenance of the training data, the compute used and the energy consumed. Each item is marked with who it is meant for, either downstream providers or the AI Office and national authorities. Models under a genuine free and open-source licence sit outside this chapter unless they carry systemic risk.

Copyright also applies to every provider and covers Article 53(1)(c). It asks for a written copyright policy in a single document, plus four practical commitments that give the policy weight. Do not circumvent paywalls or other access restrictions while crawling. Do not crawl sites that EU or EEA courts and authorities have named as persistent commercial infringers. Read and follow robots.txt as specified in IETF RFC 9309, and identify other machine-readable ways rightsholders reserve their rights under Article 4(3) of the copyright directive. Put safeguards in the model so it does not reproduce protected training content in an infringing way. Signatories also name a contact point for rightsholders and run a complaints mechanism. This chapter is where the web-crawling argument ended up.

Safety and Security applies only to the small group of providers in the systemic-risk tier, in practice the labs building frontier models, and it is by far the longest of the three: ten commitments over more than forty pages, covering risk identification, model evaluations, mitigations, incident reporting and who inside the company carries the responsibility.

What makes a model a systemic-risk model

Article 51 gives two routes, and the number attached to the first is misquoted constantly.

The first is capability. A model is presumed to have high-impact capabilities when the cumulative training compute is greater than 10^25 floating-point operations. That is a presumption, not a definition, and the Commission can move it by delegated act as hardware and algorithms improve.

The second is designation. The Commission can decide on its own initiative, or after a qualified alert from the scientific panel, that a model has equivalent capabilities or impact, using the criteria in Annex XIII. Reach is one of them: a model available to at least 10,000 registered business users in the EU is presumed to have a high impact on the internal market.

Article 52 sets the procedure. A provider crossing the threshold notifies the Commission within two weeks, and may argue with substantiated reasons that its model presents no systemic risk anyway. If the Commission rejects that, the model is designated, and a reassessment can be requested no earlier than six months later. The Commission keeps a public list of these models.

The misquoting comes from a second number. The Commission's guidelines of 18 July 2025 use a different figure, 10^23 floating-point operations, as an indicative sign that a model counts as general-purpose at all. The two are a hundred times apart and answer different questions: 10^23 asks whether the GPAI rules reach you, 10^25 asks whether the heavy tier does. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved several AI Act deadlines in July 2026 and left both numbers alone.

A general-purpose model versus one with systemic risk, before release

Take one dimension: what the provider has to do before the model goes on the market.

A plain general-purpose model. Write the technical documentation, prepare the information companies building on the model will need, have a copyright policy, and publish a summary of the training content on the Commission's template, which the entry on the AI supply chain and AIBOM covers in detail. All of it is paperwork about a model that is already finished. None of it can stop a release.

A model with systemic risk. Everything above, plus notification to the Commission within two weeks of crossing the threshold. A provider following the code then adds a Safety and Security Framework, confirmed and notified to the AI Office before the model ships, a full round of risk identification, analysis and estimation, model evaluations including documented adversarial testing, safety and security mitigations, and a Safety and Security Model Report to the AI Office before the model goes on the market.

Commitment 4 is the real difference in one line. The provider has to decide whether the remaining systemic risk is acceptable against criteria written down in advance, and if it is not, it does not proceed. The gap continues afterwards. The code puts clocks on serious incidents: two days for a serious and irreversible disruption of critical infrastructure, five days for a serious cybersecurity breach including exfiltration of model weights, ten days for the death of a person, and fifteen days for serious harm to health, an infringement of fundamental rights, or serious harm to property or the environment. Then an update every four weeks while it is unresolved, and a final report within sixty days of resolution. A provider outside the tier has no equivalent duty.

Who signed, and the dates that matter

On 4 September 2026 the Commission's list holds 21 signatories to all three chapters, including Amazon, Anthropic, Google, Microsoft and OpenAI alongside European companies such as Mistral AI, Aleph Alpha and Almawave. Two names are worth knowing separately. xAI signed only the Safety and Security chapter, so it has to show transparency and copyright compliance by alternative adequate means. Meta did not sign at all. Signing is per chapter and a signatory can withdraw at any time.

Three dates carry the timeline. The general-purpose AI obligations have applied since 2 August 2025. The Commission's enforcement powers over model providers, and the penalty regime with them, came into force on 2 August 2026. Providers of models already on the market before 2 August 2025 have until 2 August 2027 to comply.

What you can get out of a signatory's documentation

None of this is your obligation. Its value to you is that it tells you what should exist in a model provider's paperwork, which gives you something concrete to ask for.

Take a Ghent company of thirty people building a document-checking tool on a hosted model and selling it to insurers. An insurer's procurement team asks what the model was trained on, whether anyone evaluated it, and what happens when it goes wrong. Three answers exist, each from a different place.

  • The training content summary is public. Article 53(1)(d) makes it mandatory, on a template the Commission published in July 2025. It names the large public datasets and the main domains crawled, and it is a link you can paste straight into a procurement answer.

  • The Model Documentation is not public, it is requestable. Measure 1.2 of the Transparency chapter commits a signatory to publishing contact details on its website for exactly this, to giving downstream providers the parts of the form marked for them, and to answering within 14 days barring exceptional circumstances. The Ghent company builds a system on the model, so it is a downstream provider, which is the role that can ask. A company that only uses a chatbot in a browser is a deployer and has no such claim.

  • For a systemic-risk model, part of the safety work is published. Measure 10.2 commits signatories to publishing summarised versions of their Framework and Model Reports where that is needed to assess or mitigate systemic risk, with high-level descriptions of the risk assessment results and the mitigations in place. Commercially sensitive detail comes out, and what remains is more than most vendors volunteer.

The procurement answer becomes a public training summary, a documentation pack the provider sent within two weeks of being asked, and the provider's published safety framework. Without the code, none of the three would have a name or a place to ask.

What to watch out for with the code of practice

A signature is not a certificate. When a vendor answers a compliance question with the line that its model provider signed the code, that is where the answer starts, not where it ends.

Ask which chapters. The xAI case shows why the question is not pedantic. Signing is per chapter, and the chapter that matters to you may be the one left out.

This is not the code about AI-generated content. A separate Code of Practice on Transparency of AI-generated Content sits under Article 50, with its own signatory list. The two get mixed up constantly.

A copyright policy is not a copyright licence. The chapter states that adherence does not constitute compliance with EU copyright law, and that interpreting that law is for national courts and ultimately the Court of Justice. Whether a specific model was trained lawfully on a specific archive is a court question, and a signature does not answer it.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
gpai code of practice gpai systemic risk ai act article 55 frontier model provider and deployer digital omnibus ai office model documentation ai governance compliance