# EU AI Act Code of Practice

The EU AI Act Code of Practice is a voluntary framework published on 10 July 2025 to help providers of general-purpose AI models demonstrate compliance with the EU Artificial Intelligence Act, covering transparency, copyright, and safety and security.

The EU AI Act Code of Practice is a voluntary framework published on 10 July 2025 by the European Commission. It is designed to help providers of general-purpose AI models, such as [large language models](https://www.wikiprompt.org/wiki/large-language-model), demonstrate compliance with the obligations set out in the Artificial Intelligence Act (AI Act), a European Union regulation concerning [artificial intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence). The Code does not create new legal duties but operationalizes existing requirements under the Act, focusing on three main chapters: transparency, copyright, and safety and security.

The AI Act itself entered into force on 1 August 2024, with provisions phased in over the following 6 to 36 months. The Code of Practice was developed to address the regulatory gap for general-purpose AI, a category added in 2023 to cover foundation models that can perform a wide range of tasks, including generative systems such as ChatGPT. Participation in the Code is voluntary, but adherence is intended to signal and support compliance with binding legal obligations under the Act.

## Background and Legislative Context

The AI Act was proposed by the European Commission on 21 April 2021 as a comprehensive regulatory framework for AI across all sectors, with exemptions for military, national security, research, and non-professional use. It passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024. The draft was revised during negotiations to address the rapid rise of [generative AI](https://www.wikiprompt.org/wiki/generative-ai) systems, whose general-purpose capabilities did not fit the original risk-based framework.

The Act establishes a common regulatory and legal framework with four risk levels - unacceptable, high, limited, and minimal - plus a separate category for general-purpose AI. It also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

The General-Purpose AI Code of Practice emerged from this legislative process as an implementation tool. It was published on 10 July 2025 following consultations with stakeholders, including AI developers, industry associations, civil society, and academia. The Code is structured around the Act's requirements for providers of general-purpose AI models, which include publishing a summary of training data, adopting a copyright policy, and providing technical documentation to downstream providers and supervisory authorities.

## Transparency Requirements

The transparency chapter of the Code addresses the Act's obligation for providers to inform users about the nature of AI-generated content and interactions. For general-purpose AI models, this includes requirements to disclose that content is AI-generated, particularly for text, audio, or visual outputs that could be mistaken for human creations. This aligns with the Act's limited-risk category, which imposes transparency duties on systems that generate or manipulate images, sound, or video, such as deepfakes.

Open-source models, whose weights and design are made publicly available, face reduced transparency requirements under the Code. They must publish a training data summary and a copyright policy, but they are exempt from some broader disclosure duties. Closed-source models, on the other hand, must meet fuller transparency standards, including detailed documentation of the model's capabilities, limitations, and intended use.

For high-capability models that pass a threshold of 1025 floating-point operations to train, the Code adds extra evaluation obligations. These models are considered to pose systemic risks and must undergo model evaluations and adversarial testing beyond the baseline requirements. The transparency provisions also require providers to maintain records that are accessible to national supervisory authorities and downstream business users.

## Copyright and Training Data

The copyright chapter of the Code operationalizes the Act's requirement for providers to adopt policies that comply with EU copyright law. This includes documenting the sources of training data, ensuring that datasets used to train models do not infringe on existing rights, and providing transparency about what data was used. Providers must publish a summary of the training data, which serves as a practical mechanism for rights holders to identify potential infringements.

The Code encourages providers to use available technical tools and best practices to filter copyrighted material from training datasets. It also emphasizes the need for downstream providers to have sufficient information to assess compliance when using a general-purpose model in their own products. This is particularly relevant because the Act holds providers primarily responsible, but deployers may also have obligations depending on their role.

There is no mandatory registration or enforcement mechanism in the Code itself. Instead, adherence is voluntary, but providers who follow the Code can use it as evidence of good-faith efforts to meet the Act's obligations. The Commission has signaled that participation may be considered favorably during any future enforcement actions, though non-participation does not automatically imply non-compliance.

## Safety and Security Obligations

The safety and security chapter of the Code addresses the Act's risk-management duties for general-purpose AI models. For models designated as posing systemic risk, providers must carry out model evaluations, including tests for bias, security vulnerabilities, and other potential harms. They must also conduct adversarial testing to probe model weaknesses, assess and mitigate risks such as discrimination or unsafe outputs, report serious incidents to authorities, and ensure an adequate level of cybersecurity.

The Code provides practical guidance on how to conduct these assessments, including specific metrics and evaluation methodologies. It also encourages providers to establish internal governance structures that can monitor risks throughout the model's lifecycle. These obligations go beyond mere documentation and require active, ongoing risk management.

For models below the systemic-risk threshold, the safety requirements are lighter. Providers must still ensure basic reliability and safety, but they are not required to conduct the same level of adversarial testing or incident reporting. The Code distinguishes between high-capability models and others, recognizing that different approaches are needed based on potential impact.

The safety framework draws on earlier technical work in [machine learning](https://www.wikiprompt.org/wiki/machine-learning), including methods like [reinforcement learning from AI feedback](https://www.wikiprompt.org/wiki/rlaif) and [model pruning](https://www.wikiprompt.org/wiki/model-pruning), though the Code does not prescribe specific techniques. It focuses on outcomes and processes rather than particular algorithms.

## Relationship to Risk-Based Categories

The Code operates within the AI Act's broader risk classification system. While the Act regulates general-purpose AI separately, its provisions interact with the four risk categories. For example, a general-purpose model deployed as part of a high-risk application - such as in health, education, or recruitment - would be subject to both the general-purpose obligations and the high-risk requirements. This includes conformity assessments and, in some cases, a Fundamental Rights Impact Assessment before deployment.

The general-purpose AI category was added to the Act specifically to address models that do not fit neatly into the traditional risk levels. These models are adaptable to many tasks, making their risk profile context-dependent. The Code helps bridge this gap by providing a single framework for provider obligations, independent of how a model is ultimately deployed.

Minimal-risk applications, such as video games or spam filters, remain largely unregulated under the Act, and the Code does not apply to them. The Act's maximum harmonisation rules prevent Member States from imposing additional national regulations on these systems, though a voluntary code of conduct is suggested for them as well.

## Implementation and Monitoring

The European Commission oversees the implementation of the Code, working in conjunction with national authorities and the European Artificial Intelligence Board. The Board, established by the Act, promotes cooperation among Member States and ensures consistent application of the regulation across the EU. The Code serves as a tool for this coordination, providing a common set of practices that providers can adopt.

Monitoring of the Code is primarily self-regulatory. Providers that commit to the Code report on their compliance through publicly available documentation Description. The Commission has indicated that it will review the Code periodically and may update it as technologies evolve or as lessons are learned from implementation. This adaptive approach is meant to keep pace with developments in [transformer-based architectures](https://www.wikiprompt.org/wiki/transformer) and other AI advances.

Enforcement of the underlying AI Act remains the responsibility of national supervisory authorities and, where applicable, the European Commission. The Code is not a substitute for formal compliance, but it is designed to make compliance more straightforward and transparent. Providers from outside the EU are also encouraged to participate if they offer services or products within the EU market.

## Reception and Impact

The Code of Practice has been generally well-received by the AI industry, though some stakeholders have raised concerns about the burden of documentation and evaluation. Major technology companies, including those involved in [OpenAI](https://www.wikiprompt.org/wiki/openai), [Anthropic](https://www.wikiprompt.org/wiki/anthropic), and [Google DeepMind](https://www.wikiprompt.org/wiki/google-deepmind), have participated in consultations and are expected to align their practices with the Code. Smaller providers and open-source projects may face challenges in meeting the requirements, but the code's reduced transparency obligations for open-source models aim to mitigate this.

Civil society groups have praised the Code for making AI governance more tangible, particularly around copyright and safety. However, some critics argue that its voluntary nature weakens accountability, as there is no penalty for non-participation. The European Parliament has expressed support for the Code as a complement to the Act, while emphasizing the need for strong enforcement of the underlying regulation.

The Code also influences international AI governance discussions. By providing a detailed template for general-purpose AI oversight, it offers a reference point for other jurisdictions developing similar frameworks. Its focus on risk-based, proportionate measures aligns with emerging best practices in AI policy, though the EU's regulatory approach remains distinctive in its comprehensiveness.

As of late 2025, the Code is in its early implementation phase. Its long-term impact will depend on how effectively providers integrate its provisions into development cycles and how robustly authorities oversee compliance with the AI Act. The Code's voluntary nature means that its success hinges on widespread adoption and the credibility of self-reported compliance.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-code-of-practice
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:31.119566+00:00
