The General-Purpose AI Code of Practice is a draft regulatory document published by the European Commission in 2025, intended to operationalize the obligations placed on providers of general-purpose artificial intelligence (GPAI) models under the EU AI Act. The code translates high-level legislative requirements into concrete, actionable measures for companies developing and deploying foundation models, including large language models and other generative AI systems. It represents a key step in the EU's effort to establish a global standard for AI governance, balancing innovation with fundamental rights protections.
The code was developed through a multi-stakeholder process involving industry representatives, civil society organizations, academia, and independent experts. It addresses four primary pillars: transparency and copyright compliance, risk identification and assessment, internal risk management, and systemic risk evaluation and mitigation. The draft was published for public consultation, with a final version expected after incorporating feedback from stakeholders and the European AI Office.
Background and Legal Basis
The EU AI Act, formally adopted in 2024, introduced a risk-based regulatory framework for AI systems. GPAI models, defined as those trained on large-scale data and capable of performing a wide range of tasks, are subject to specific obligations under Articles 51-56 of the Act. These include providing technical documentation, publishing summaries of training data, and implementing policies to respect EU copyright law. For models with systemic risk - those with high computational capacity or significant impact - additional requirements apply, such as adversarial testing and incident reporting.
The Code of Practice is not a standalone legal instrument but a guidance document that the European Commission intends to use as a benchmark for compliance. Providers who adhere to the code are presumed to be in conformity with the AI Act's GPAI provisions. This "soft law" approach aims to provide clarity and flexibility while the Commission develops harmonized standards through European standardization organizations.
Development Process
In November 2024, the European AI Office launched a consultation process to draft the code. Four working groups were established, each focusing on a specific pillar. The groups included representatives from major technology companies such as OpenAI, Anthropic, Google DeepMind, and Amazon Web Services, as well as European startups, civil society groups like Access Now, and academic institutions including MIT CSAIL and Stanford AI Lab. The process was chaired by independent experts, including computer scientist Michael I. Jordan and legal scholar Marietje Schaake.
The working groups met virtually and in person over several months, producing iterative drafts. The first complete draft was published on 14 April 2025, followed by a six-week public comment period. Over 500 submissions were received from 40 countries, reflecting the global interest in EU AI regulation. The final version is scheduled for adoption in late 2025, with a transition period for providers to align their practices.
Pillar One: Transparency and Copyright
The first pillar requires GPAI providers to maintain detailed technical documentation, including model architecture, training data sources, and computational resources used. Providers must publish a sufficiently detailed summary of training content, as mandated by Article 53(1)(a) of the AI Act. The code specifies that this summary should include information about data categories, languages, and the provenance of datasets, while respecting trade secrets.
Copyright compliance is a central concern. The code obliges providers to implement state-of-the-art measures to identify and respect rights reservations expressed by copyright holders, such as the use of machine-readable opt-out protocols. It also requires providers to document their policies for complying with the EU Directive on Copyright in the Digital Single Market, particularly regarding text and data mining exceptions. The draft suggests that providers should maintain records of any copyright-related complaints and their resolutions.
Pillar Two: Risk Identification and Assessment
The second pillar focuses on internal processes for identifying and assessing risks associated with GPAI models. Providers must establish a risk management system that covers the entire model lifecycle, from data collection and training to deployment and post-market monitoring. The code recommends a structured approach based on existing frameworks like the NIST AI Risk Management Framework, adapted to the EU context.
Specific risk categories include bias and discrimination, privacy violations, safety failures, and potential misuse for disinformation or cyberattacks. Providers are expected to conduct red-teaming exercises and adversarial testing, particularly for models with high capability. The code also requires documentation of risk assessment methodologies, including metrics used to measure bias (e.g., demographic parity) and robustness (e.g., performance under distribution shift).
Pillar Three: Internal Risk Management
The third pillar details governance and operational measures. Providers must appoint a responsible person or team for AI compliance, with clear lines of accountability. The code recommends establishing an internal review board that includes diverse perspectives, including ethicists and legal experts, to oversee risk decisions. Training programs for staff on AI safety and ethics are also mandated.
Technical measures include implementing Model Pruning and other optimization techniques to reduce unintended behaviors, as well as maintaining version control and audit trails for model updates. Providers must also establish incident response protocols, including procedures for reporting serious incidents to the European AI Office within 15 days. The code emphasizes the importance of Data Augmentation and Curriculum Learning as methods to improve model robustness and reduce known failure modes.
Pillar Four: Systemic Risk Evaluation and Mitigation
For models deemed to have systemic risk - defined as those requiring more than 10^25 floating-point operations per training run - the code imposes additional obligations. Providers must conduct comprehensive evaluations using standardized benchmarks and stress tests, including assessments of cyber-offensive capabilities, chemical or biological weapon knowledge, and autonomous replication potential. The draft references methodologies from BAIR (Berkeley AI Research) and University of Oxford on frontier AI risk assessment.
Mitigation measures include implementing Reinforcement Learning from AI Feedback (RLAIF) (reinforcement learning from AI feedback) and Gradient Clipping to stabilize training, as well as deploying Top-K Sampling and Temperature Scaling to control generation behavior. Providers must also commit to sharing safety findings with the European AI Office and, where appropriate, with other providers. The code encourages participation in joint safety research initiatives, such as those led by Anthropic and Google DeepMind.
Industry Response and Criticisms
The draft code has received mixed reactions. Large technology firms generally welcomed the clarity it provides but expressed concerns about compliance costs and the potential for over-regulation. OpenAI and Anthropic publicly committed to meeting the code's requirements, while Google Cloud and Microsoft Azure noted the need for international alignment to avoid fragmentation. European startups, such as AI21 Labs and Mistral AI, argued that the code's emphasis on documentation could disadvantage smaller players with limited resources.
Civil society organizations praised the focus on transparency and copyright but criticized the lack of binding enforcement mechanisms. Some academics, including Melanie Mitchell and Aleksander Madry, questioned the feasibility of the proposed risk assessments, noting that current evaluation methods are insufficient for predicting emergent capabilities. The OpenPanel, an independent advisory body, recommended stronger provisions for public disclosure of training data and more rigorous third-party audits.
Next Steps and Implementation Timeline
The European Commission plans to finalize the code by December 2025, incorporating feedback from the consultation. Once adopted, the code will become effective on 2 August 2026, coinciding with the AI Act's general application date for GPAI obligations. Providers will have a six-month transition period to align their practices, with the European AI Office conducting compliance checks starting in early 2027.
The code is expected to influence AI governance beyond the EU, as other jurisdictions, including Canada and Japan, have expressed interest in adopting similar frameworks. The Artificial intelligence community will closely monitor its implementation, particularly regarding how systemic risk thresholds are applied and whether the code successfully balances innovation with public safety. As of mid-2025, the final text remains subject to change, and stakeholders continue to engage in the rulemaking process.