Skip to main content
v2026.11,858 entries · CC-BY 4.0

The EU AI Act GPAI Code of Practice: What It Is and Who Signed It

What the EU AI Act’s GPAI Code of Practice actually requires — its three chapters, its presumption-of-conformity mechanism under Article 53(4), and which major AI labs have signed it.

Written and maintained by CASRAI Editorial Board

Last updated

The General-Purpose AI (GPAI) Code of Practice is a voluntary compliance instrument for providers of general-purpose AI models under the EU AI Act. It is not the AI Act itself, and it is not mandatory — but for the providers who sign it, it is the main practical route to demonstrating compliance with the Act’s GPAI obligations. This guide covers what the Code actually contains, how the compliance mechanism behind it works, and which major AI labs have signed it.

If you’re looking for how the EU AI Act as a whole compares to other frameworks, see EU AI Act vs California SB 53 or EU AI Act vs NIST AI RMF vs ISO 42001. This page is narrower: it’s about the Code of Practice as its own artifact, not the underlying statute.

What the Code of Practice is

The EU AI Act (Regulation (EU) 2024/1689) sets obligations for providers of general-purpose AI models directly in the statute itself — primarily Articles 53 (transparency and copyright) and 55 (systemic-risk models). But the Act doesn’t spell out exactly how a provider should satisfy those obligations in practice. Article 56 lets the EU AI Office facilitate the drawing-up of Codes of Practice to fill that gap, and the GPAI Code of Practice is the result for general-purpose AI models specifically.

It was drafted by independent experts chaired at the AI Office’s invitation, with input from close to 1,000 participants across industry, academia, civil society, and EU member states, organized into four thematic working groups. The Commission received the final text on 10 July 2025, and the Commission and the European AI Board approved it through an adequacy assessment on 1 August 2025 — one day before the AI Act’s GPAI provisions themselves became applicable, on 2 August 2025.

Why a voluntary code carries real weight

The Code is explicitly optional to sign. But Article 53(4) of the AI Act creates the incentive: a GPAI provider that adheres to an approved code of practice is presumed to comply with the corresponding obligations in Articles 53 and 55, for as long as the code covers those obligations. A provider that doesn’t adhere to the Code (or to a harmonised standard, once one exists) has to demonstrate compliance by other means, subject to the Commission’s assessment — a heavier, more open-ended burden than pointing to a Commission-endorsed code.

That’s the mechanism worth understanding: signing isn’t a legal requirement, but it’s the lowest-friction path to the same legal outcome. The AI Office has also indicated it will not treat early-stage gaps in implementation by signatories as automatic violations, giving signatories room to phase in compliance rather than facing immediate enforcement.

What the Code actually requires: three chapters

The Code is organized into three separately authored chapters, and not every provider owes commitments under all three.

1. Transparency

Applies to every signatory. It operationalizes the Article 53 transparency obligation with a standardized Model Documentation Form: providers record what the model is, its intended and known uses, training data at a summary level, and other technical details, then retain that documentation and make it available to the AI Office and, where relevant, to downstream providers who integrate the model.

2. Copyright

Also applies to every signatory. It sets out how a provider’s copyright policy (also required by Article 53) should work in practice: lawful data-sourcing and crawling, respecting machine-readable rights reservations such as robots.txt, technical safeguards against a model reproducing infringing content, and a complaint mechanism for rightsholders.

3. Safety and Security

Applies only to providers of models classified as carrying systemic risk under Article 55 — in practice, a small number of the most capable, highest-compute models. This chapter is the most substantial: it commits signatories to a risk-management framework covering how they identify and analyze systemic risks across a model’s lifecycle, what mitigations and safety/security practices they apply, and how they report serious incidents, with more detailed internal documentation than the Transparency chapter requires.

A provider without a systemic-risk model can sign just the Transparency and Copyright chapters; a provider that does train systemic-risk models is expected to sign all three to get the presumption-of-conformity benefit for Article 55 as well as Article 53.

Who has signed

Signatories are published by the European Commission and change over time as more providers join; treat any list, including this one, as a snapshot rather than a permanent roster. As of this writing, signatories include major general-purpose model providers Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI, alongside other technology and AI companies such as Cohere, Aleph Alpha, and ServiceNow, among roughly two dozen total signatories spanning both large providers and smaller specialist firms.

The most notable holdout is Meta, which has publicly declined to sign, along with major Chinese model developers such as Alibaba, Baidu, and DeepSeek. Signatories that do sign don’t just make one commitment and move on: on 30 January 2026 the signatories held the first meeting of a standing Signatory Taskforce to govern how the Code’s commitments are interpreted and updated going forward.

How this differs from the EU AI Act itself

It’s easy to conflate “the EU AI Act” with “the GPAI Code of Practice,” but they’re different kinds of thing. The AI Act is binding EU law that applies to GPAI providers regardless of whether they sign anything. The Code of Practice is a non-binding, Commission-endorsed document that gives providers a concrete way to satisfy specific Act obligations (Articles 53 and 55) and earn a presumption of conformity for doing so. A provider can be fully subject to the AI Act’s GPAI rules while choosing not to sign the Code — it just then has to show compliance some other way. For how the AI Act’s GPAI rules sit alongside other frameworks and other jurisdictions’ AI laws, see EU AI Act vs California SB 53 and EU AI Act vs NIST AI RMF vs ISO 42001.

Why this matters beyond the providers who sign it

Organizations that procure or integrate general-purpose AI models increasingly need to track which upstream providers are covered by which compliance instruments, since that shapes what documentation and assurances are available downstream. CASRAI’s NIKOLAI element dictionary defines the vocabulary organizations use to describe and exchange this kind of AI-governance metadata consistently, including elements relevant to frontier-model provenance and compliance status.

FAQ

Is the GPAI Code of Practice mandatory?

No. Signing it is voluntary. The EU AI Act’s GPAI obligations themselves are mandatory for covered providers regardless of whether they sign the Code; the Code is one route — the one with the least legal uncertainty — to demonstrating compliance with those obligations.

What happens if a provider doesn’t sign?

It doesn’t exempt the provider from the AI Act. Under Article 53(4), a non-signatory has to demonstrate compliance with the Act’s GPAI obligations through other adequate means, subject to Commission assessment, rather than relying on the Code’s presumption of conformity.

Do all signatories commit to all three chapters?

Not necessarily. The Safety and Security chapter only applies to providers whose models are classified as carrying systemic risk under Article 55. Providers without a systemic-risk model can sign the Transparency and Copyright chapters alone.

When did the Code take effect?

The Commission received the final text on 10 July 2025, and the Commission and the European AI Board approved it via an adequacy assessment on 1 August 2025 — the day before the AI Act’s own GPAI provisions became applicable, on 2 August 2025. AI Office enforcement of GPAI obligations carries a grace period running to 2 August 2026.

Has Meta signed the Code of Practice?

No. Meta is the most prominent general-purpose AI provider to have publicly declined to sign, alongside major Chinese model developers.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The EU AI Act GPAI Code of Practice: What It Is and Who Signed It

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →