Written and maintained by CASRAI Editorial Board
Last updated
The General-Purpose AI (GPAI) Code of Practice is a voluntary compliance instrument for providers of general-purpose AI models under the EU AI Act. It is not the AI Act itself, and it is not mandatory — but for the providers who sign it, it is the main practical route to demonstrating compliance with the Act’s GPAI obligations. This guide covers what the Code actually contains, how the compliance mechanism behind it works, and which major AI labs have signed it.
If you’re looking for how the EU AI Act as a whole compares to other frameworks, see EU AI Act vs California SB 53 or EU AI Act vs NIST AI RMF vs ISO 42001. This page is narrower: it’s about the Code of Practice as its own artifact, not the underlying statute.
What the Code of Practice is
The EU AI Act (Regulation (EU) 2024/1689) sets obligations for providers of general-purpose AI models directly in the statute itself — primarily Articles 53 (transparency and copyright) and 55 (systemic-risk models). But the Act doesn’t spell out exactly how a provider should satisfy those obligations in practice. Article 56 lets the EU AI Office facilitate the drawing-up of Codes of Practice to fill that gap, and the GPAI Code of Practice is the result for general-purpose AI models specifically.
It was drafted by independent experts chaired at the AI Office’s invitation, with input from close to 1,000 participants across industry, academia, civil society, and EU member states, organized into four thematic working groups. The Commission received the final text on 10 July 2025, and the Commission and the European AI Board approved it through an adequacy assessment on 1 August 2025 — one day before the AI Act’s GPAI provisions themselves became applicable, on 2 August 2025.
Why a voluntary code carries real weight
The Code is explicitly optional to sign. But Article 53(4) of the AI Act creates the incentive: a GPAI provider that adheres to an approved code of practice is presumed to comply with the corresponding obligations in Articles 53 and 55, for as long as the code covers those obligations. A provider that doesn’t adhere to the Code (or to a harmonised standard, once one exists) has to demonstrate compliance by other means, subject to the Commission’s assessment — a heavier, more open-ended burden than pointing to a Commission-endorsed code.
That’s the mechanism worth understanding: signing isn’t a legal requirement, but it’s the lowest-friction path to the same legal outcome. The AI Office has also indicated it will not treat early-stage gaps in implementation by signatories as automatic violations, giving signatories room to phase in compliance rather than facing immediate enforcement.
What the Code actually requires: three chapters
The Code is organized into three separately authored chapters, and not every provider owes commitments under all three.
1. Transparency
Applies to every signatory. It operationalizes the Article 53 transparency obligation with a standardized Model Documentation Form: providers record what the model is, its intended and known uses, training data at a summary level, and other technical details, then retain that documentation and make it available to the AI Office and, where relevant, to downstream providers who integrate the model.
2. Copyright
Also applies to every signatory. It sets out how a provider’s copyright policy (also required by Article 53) should work in practice: lawful data-sourcing and crawling, respecting machine-readable rights reservations such as robots.txt, technical safeguards against a model reproducing infringing content, and a complaint mechanism for rightsholders.
3. Safety and Security
Applies only to providers of models classified as carrying systemic risk under Article 55 — in practice, a small number of the most capable, highest-compute models. This chapter is the most substantial: it commits signatories to a risk-management framework covering how they identify and analyze systemic risks across a model’s lifecycle, what mitigations and safety/security practices they apply, and how they report serious incidents, with more detailed internal documentation than the Transparency chapter requires.
A provider without a systemic-risk model can sign just the Transparency and Copyright chapters; a provider that does train systemic-risk models is expected to sign all three to get the presumption-of-conformity benefit for Article 55 as well as Article 53.
Who has signed
Signatories are published by the European Commission and change over time as more providers join; treat any list, including this one, as a snapshot rather than a permanent roster. As of this writing, signatories include major general-purpose model providers Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI, alongside other technology and AI companies such as Cohere, Aleph Alpha, and ServiceNow, among roughly two dozen total signatories spanning both large providers and smaller specialist firms.
The most notable holdout is Meta, which has publicly declined to sign, along with major Chinese model developers such as Alibaba, Baidu, and DeepSeek. Signatories that do sign don’t just make one commitment and move on: on 30 January 2026 the signatories held the first meeting of a standing Signatory Taskforce to govern how the Code’s commitments are interpreted and updated going forward.
How this differs from the EU AI Act itself
It’s easy to conflate “the EU AI Act” with “the GPAI Code of Practice,” but they’re different kinds of thing. The AI Act is binding EU law that applies to GPAI providers regardless of whether they sign anything. The Code of Practice is a non-binding, Commission-endorsed document that gives providers a concrete way to satisfy specific Act obligations (Articles 53 and 55) and earn a presumption of conformity for doing so. A provider can be fully subject to the AI Act’s GPAI rules while choosing not to sign the Code — it just then has to show compliance some other way. For how the AI Act’s GPAI rules sit alongside other frameworks and other jurisdictions’ AI laws, see EU AI Act vs California SB 53 and EU AI Act vs NIST AI RMF vs ISO 42001.
Why this matters beyond the providers who sign it
Organizations that procure or integrate general-purpose AI models increasingly need to track which upstream providers are covered by which compliance instruments, since that shapes what documentation and assurances are available downstream. CASRAI’s NIKOLAI element dictionary defines the vocabulary organizations use to describe and exchange this kind of AI-governance metadata consistently, including elements relevant to frontier-model provenance and compliance status.
FAQ
Is the GPAI Code of Practice mandatory?
No. Signing it is voluntary. The EU AI Act’s GPAI obligations themselves are mandatory for covered providers regardless of whether they sign the Code; the Code is one route — the one with the least legal uncertainty — to demonstrating compliance with those obligations.
What happens if a provider doesn’t sign?
It doesn’t exempt the provider from the AI Act. Under Article 53(4), a non-signatory has to demonstrate compliance with the Act’s GPAI obligations through other adequate means, subject to Commission assessment, rather than relying on the Code’s presumption of conformity.
Do all signatories commit to all three chapters?
Not necessarily. The Safety and Security chapter only applies to providers whose models are classified as carrying systemic risk under Article 55. Providers without a systemic-risk model can sign the Transparency and Copyright chapters alone.
When did the Code take effect?
The Commission received the final text on 10 July 2025, and the Commission and the European AI Board approved it via an adequacy assessment on 1 August 2025 — the day before the AI Act’s own GPAI provisions became applicable, on 2 August 2025. AI Office enforcement of GPAI obligations carries a grace period running to 2 August 2026.
Has Meta signed the Code of Practice?
No. Meta is the most prominent general-purpose AI provider to have publicly declined to sign, alongside major Chinese model developers.







