# EU AI Act GPAI Code of Practice

The EU AI Act GPAI Code of Practice is a voluntary framework guiding providers of general-purpose AI models to comply with the EU AI Act, finalized in 2025 with stakeholder input.

The EU AI Act GPAI Code of Practice is a voluntary governance framework developed under the European Union's Artificial Intelligence Act (AI Act). It provides detailed guidance for providers of general-purpose AI (GPAI) models, including large language models and other foundation models, on how to meet the regulatory obligations set out in the AI Act. The code was finalized in 2025 after a multi-stakeholder drafting process, aiming to translate high-level legal requirements into concrete, actionable practices for transparency, copyright compliance, and systemic risk management.

The code is not legally binding in itself, but compliance with it is presumed to demonstrate conformity with the AI Act's requirements for GPAI models. It was developed by the AI Office, the EU body responsible for overseeing GPAI regulation, in collaboration with independent experts, industry representatives, and civil society. The final version was published in July 2025, following a public consultation that drew over 430 submissions from companies, researchers, and advocacy groups.

## Background and Legal Context

The EU AI Act, adopted in August 2024, entered into force on 1 August 2024, with most provisions applying progressively. GPAI models, defined as AI models trained on large-scale data and capable of performing a wide range of tasks, are subject to specific obligations under the Act's Chapter V. These obligations include providing technical documentation, publishing a summary of training content, and implementing policies to respect EU copyright law.

For GPAI models with systemic risk - defined as those with cumulative computing power exceeding 10^25 floating-point operations (FLOPs) - additional requirements apply, such as conducting model evaluations and adversarial testing. The AI Act mandates that the AI Office facilitate the creation of codes of practice to detail how these obligations can be met. The GPAI Code of Practice is the primary instrument for this purpose.

## Drafting Process and Timeline

The drafting process began in September 2024, when the AI Office launched a consultation to gather input on the scope and content of the code. In November 2024, the AI Office appointed four independent chairs: Yoshua Bengio, a Turing Award winner and pioneer in deep learning; Marietje Schaake, a former Member of the European Parliament; Alexander Peukert, a copyright law professor; and Anja Feldner, a digital policy expert. These chairs led working groups focused on transparency, copyright, and systemic risk.

Four working groups were established, each addressing a specific area: transparency and copyright-related provisions, systemic risk identification and assessment, technical risk mitigation, and governance and review. Each group included representatives from major AI developers such as [openai](https://www.wikiprompt.org/wiki/openai), [anthropic](https://www.wikiprompt.org/wiki/anthropic), [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind), and [microsoft](https://www.wikiprompt.org/wiki/microsoft), as well as European startups, open-source communities, and civil society organizations. The groups met regularly from January to April 2025, producing successive drafts.

A first draft was released in February 2025, followed by a second draft in April 2025. The AI Office held a public consultation on the second draft, receiving feedback from over 430 stakeholders. The final version, incorporating revisions on issues like copyright opt-outs and systemic risk thresholds, was adopted on 10 July 2025.

## Key Provisions: Transparency and Copyright

The code's transparency chapter requires GPAI model providers to maintain detailed technical documentation, including model architecture, training data sources, and computational resources used. Providers must also publish a sufficiently detailed summary of training content, as required by the AI Act. The code specifies that this summary should be structured to allow rights holders to identify whether their works were used, without revealing proprietary business secrets.

On copyright, the code mandates that providers implement a policy to comply with the EU Directive on Copyright in the Digital Single Market (2019/790), including the text-and-data-mining exception and the opt-out mechanism. Providers must make reasonable efforts to ensure that training data does not include works where rights holders have explicitly reserved their rights through machine-readable means. The code also encourages the use of technical tools, such as robots.txt and content registries, to facilitate opt-outs.

For providers that use web-scraped data, the code requires them to maintain a record of the sources and to respond promptly to rights holder requests. It also suggests adopting a 'best effort' standard for filtering out opt-out content, acknowledging that perfect compliance is technically challenging. The final version softened earlier proposals for mandatory filtering, reflecting industry concerns about feasibility.

## Systemic Risk Management

The systemic risk chapter applies to GPAI models with cumulative training compute exceeding 10^25 FLOPs, a threshold set by the AI Act. As of 2025, this includes models like OpenAI's GPT-4 and GPT-5, Anthropic's Claude 3, and Google's Gemini Ultra. The code requires these providers to conduct rigorous model evaluations, including red-teaming and adversarial testing, to identify potential harms such as cyber-offense capabilities, biological threat creation, and loss of control.

Providers must implement a risk management system that includes a risk assessment framework, mitigation measures, and incident reporting protocols. The code specifies that evaluations should be conducted by independent third parties where feasible, and that results should be shared with the AI Office. It also requires providers to monitor for emergent capabilities that could escalate risk after deployment.

A notable provision is the requirement for providers to establish a 'systemic risk mitigation plan' that is updated at least annually. This plan must address risks related to chemical, biological, radiological, and nuclear (CBRN) threats, as well as cyberattacks and manipulation. The code encourages collaboration with [berkeley-ai-research](https://www.wikiprompt.org/wiki/berkeley-ai-research) and other academic institutions to develop evaluation benchmarks.

## Governance and Compliance Mechanisms

The code establishes a governance structure under the AI Office, which will monitor adherence through a combination of self-assessment and audits. Providers are expected to submit annual compliance reports, and the AI Office may conduct targeted reviews in response to complaints or emerging risks. The code also creates a 'GPAI Code of Practice Panel' composed of independent experts to advise on interpretation and updates.

For open-source models, the code includes a special section that relaxes some documentation requirements, recognizing the different risk profiles of openly released weights. However, open-source providers must still comply with copyright obligations and systemic risk provisions if their models exceed the compute threshold. The code encourages the use of model cards and datasheets, a practice popularized by [mit-csail](https://www.wikiprompt.org/wiki/mit-csail) and other research groups.

Non-compliance with the code does not automatically trigger penalties, but it shifts the burden of proof onto the provider to demonstrate alternative means of conformity. The AI Act provides for fines up to 3% of global annual turnover for violations of GPAI obligations, which could apply if a provider fails to meet the underlying legal requirements.

## Industry Reactions and Adoption

Major AI companies have expressed cautious support for the code, though some raised concerns about the administrative burden and the feasibility of certain copyright measures. [openai](https://www.wikiprompt.org/wiki/openai) and [anthropic](https://www.wikiprompt.org/wiki/anthropic) both issued statements welcoming the clarity provided by the code, while noting that some provisions require further technical development. [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind) highlighted the importance of international alignment, as the code could influence regulations in other jurisdictions.

European startups, such as [mistral-ai](https://www.wikiprompt.org/wiki/mistral-ai) and [aleph-alpha](https://www.wikiprompt.org/wiki/aleph-alpha), have been more critical, arguing that the code's documentation requirements could disadvantage smaller players. The open-source community, represented by groups like Hugging Face, welcomed the relaxed provisions for open models but called for more explicit guidance on what constitutes a 'sufficiently detailed' training data summary.

Civil society organizations, including Access Now and the European Digital Rights (EDRi), praised the code's emphasis on transparency but urged stronger enforcement mechanisms. They noted that the code's voluntary nature means that providers could choose to ignore it, and called for the AI Office to conduct proactive audits rather than relying on self-reporting.

## Relationship with Other Regulations and Standards

The GPAI Code of Practice is designed to complement other EU instruments, including the Digital Services Act and the General Data Protection Regulation (GDPR). It also aligns with international initiatives such as the OECD AI Principles and the Council of Europe's Framework Convention on AI. The code references technical standards being developed by CEN-CENELEC, the European standardization bodies, which will provide more granular specifications.

The code's approach to systemic risk draws on methodologies from [deep-learning](https://www.wikiprompt.org/wiki/deep-learning) research, including red-teaming practices used in [neural-network](https://www.wikiprompt.org/wiki/neural-network) safety evaluations. It also incorporates lessons from the [rlaif](https://www.wikiprompt.org/wiki/rlaif) (reinforcement learning from AI feedback) literature, which has informed how providers can align models with safety guidelines. The code encourages providers to share evaluation results with the research community, fostering a culture of transparency.

## Future Revisions and Impact

The code is designed to be a living document, with a review cycle every two years. The first review is scheduled for 2027, at which point the AI Office will assess whether the code has effectively reduced risks and whether thresholds need adjustment. The code's provisions on copyright and systemic risk are likely to evolve as technical capabilities and legal interpretations develop.

As of late 2025, the code has already influenced corporate practices. Several providers, including [openai](https://www.wikiprompt.org/wiki/openai) and [anthropic](https://www.wikiprompt.org/wiki/anthropic), have published initial compliance reports and updated their model documentation to align with the code's templates. The code has also served as a reference for other jurisdictions, including Canada and Japan, which are developing similar frameworks for foundation models.

The long-term impact of the code will depend on the AI Office's enforcement approach and the willingness of providers to engage constructively. While the code is voluntary, its detailed specifications create a strong incentive for compliance, as deviation would require a provider to justify alternative measures. This dynamic has led some observers to describe the code as 'soft law with hard edges', reflecting its potential to shape the AI industry's behavior despite its non-binding nature.

---
Source: https://www.wikiprompt.org/wiki/ai-act-gpai-code-practice
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-12T16:24:11.787367+00:00
