Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU’s General-Purpose AI (GPAI) Code of Practice is a voluntary way for in-scope model providers to demonstrate how they comply with binding obligations in the AI Act. It is not a new law, and it does not automatically apply to every business that uses AI. As of October 2026, the Commission’s enforcement powers for these GPAI rules are in application, making it important for providers to determine whether they are in scope and which duties apply to their models.

What is the General-Purpose AI Code of Practice?

The Code is a voluntary compliance tool for providers of general-purpose AI models under the EU AI Act. The European Commission received its final version on 10 July 2025. Drafted by 13 independent experts after a multi-stakeholder process, it is organized into three chapters: Transparency, Copyright, and Safety and Security. The Commission’s announcement of the final Code said it was designed to help industry comply with GPAI rules applying from 2 August 2025.

The Commission and AI Board have confirmed the Code as an adequate voluntary tool for demonstrating compliance with relevant obligations. A provider that signs can use the relevant chapters to show how it meets those duties; the Commission identifies reduced administrative burden and increased legal certainty as possible benefits. Signing does not make the statutory obligations optional, nor does the Code replace the AI Act.

The Commission’s Q&A, last updated 20 July 2026, says more than 1,400 people took part in the process, with over 1,600 written submissions and feedback from 40 workshops. Those are figures from the later Q&A; the Commission’s July 2025 announcement separately reported more than 1,000 stakeholders.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who does the Code apply to?

The relevant audience is providers of GPAI models placed on the EU market—not every organization that buys or uses an AI tool. A company may be a downstream provider of an AI system without being the provider of the underlying GPAI model. The legal role depends on the facts, including whether an organization develops, places a model on the market, or modifies it in a way that may make it a provider.

The Commission’s July 2025 guidelines describe a GPAI model using a compute criterion of more than 1023 floating-point operations, together with the capability to generate language (text or audio), text-to-image, or text-to-video. This is a scope guide, not a shortcut for deciding a particular company’s legal status: the definitions of model, provider, and placing on the market matter too. See the Commission’s guidelines for providers of general-purpose AI models.

Some free and open-source models may qualify for exemptions from certain obligations if they meet specified transparency conditions. Open-source status alone does not exempt a model from every GPAI duty.

What obligations does the Code help providers demonstrate?

The Code maps to different obligations according to the provider’s model and risk classification. Transparency and Copyright address Article 53 duties for GPAI model providers generally. Safety and Security is relevant to providers of models classified as posing systemic risk, which face additional Article 55 requirements.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Code chapter Who it is for What it covers
Transparency GPAI model providers subject to Article 53 A Model Documentation Form to organize information for transparency and documentation duties.
Copyright GPAI model providers subject to Article 53 Practical measures for putting in place a policy to comply with EU copyright law.
Safety and Security Providers of GPAI models classified as systemic-risk models Practices for assessing and managing systemic risks from the most advanced models.

Core Article 53 duties include preparing technical documentation, giving information to downstream providers, maintaining a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of training content. The systemic-risk category adds duties that include model evaluation, risk mitigation, serious-incident reporting, and cybersecurity measures. The Commission’s GPAI Code policy page and Code Q&A describe the chapters and related duties.

How is systemic risk determined?

Systemic risk is a narrower classification than GPAI status. The Commission’s Q&A says the Act currently presumes that models trained with cumulative compute greater than 1025 floating-point operations have high-impact capabilities. That compute level is not the whole classification test: the assessment also concerns high-impact capabilities and the model’s impact on the EU market.

Providers of models classified as systemic risk must notify the AI Office without delay and meet the additional evaluation, mitigation, incident-reporting, and security duties. Do not treat a compute figure on its own as a complete legal determination.

What are the key dates for GPAI providers?

These dates concern GPAI obligations and models placed on the EU market. They are not general application dates for every AI Act provision or every kind of AI system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date What it means for GPAI providers
2 August 2025 Provider obligations began to apply for GPAI models newly placed on the EU market.
2 August 2026 The Commission’s GPAI enforcement powers began to apply.
2 August 2027 Deadline for relevant obligations for GPAI models that were already on the market before 2 August 2025.

The dates and transition rules are set out in the Commission’s provider guidelines explainer. Providers should check current official guidance and applicable law before relying on a transition rule.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should an affected provider decide what to do?

  1. Establish the organization’s role. Use the Commission’s provider and scope guidance to assess whether the organization provides a GPAI model, acts only downstream, or has both roles. Review model modifications as well as initial development and market placement.
  2. Map the model’s Article 53 duties. Identify the required technical documentation, downstream-provider information, copyright policy, and published training-content summary. Assess any free or open-source exemption against its actual conditions rather than assuming one applies.
  3. Assess systemic-risk classification separately. If the model is classified as systemic risk, account for notification to the AI Office and the additional evaluation, mitigation, serious-incident reporting, and cybersecurity duties.
  4. Choose a compliance demonstration route. Decide whether to sign and implement the relevant Code chapters or use another adequate way to demonstrate compliance. The Code is voluntary; the underlying applicable duties are not.
  5. Check the current signing procedure. The Commission’s Code page lists the form and signature process. Confirm the current procedure and signatory information there, since administration can change.
  6. Apply the correct transition date. Distinguish a model newly placed on the EU market from one already there before 2 August 2025, and verify whether the 2027 transition applies to the model at issue.

Is this the same as the EU’s 2026 AI transparency Code?

No. The GPAI Code published in July 2025 concerns model-provider duties, including documentation, copyright policy, and training-data transparency. A separate Article 50 Code of Practice on transparency of AI-generated content, published in 2026, addresses marking and labelling AI-generated or manipulated content at the AI-system level. The Commission describes the codes as complementary: they concern different obligations and audiences. A provider may need to consider both depending on its role and activities.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.