Skip to main content
Choosing Your GPAI Compliance Path: Code or Standards?EU AI Act & GPAI
5 min readFor AI Governance Leaders

Choosing Your GPAI Compliance Path: Code or Standards?

If you're a General-Purpose AI Model provider under the EU AI Act, you're facing a decision: adopt the Code of Practice published in July 2025, wait for harmonized standards (expected August 2027 or later), or demonstrate compliance through alternative means. Each path carries different burdens, timelines, and strategic implications.

Here's how to make that choice.

The Decision You're Facing

Your obligations under Articles 53 and 55 took effect on August 2, 2025. You must comply with transparency, copyright, and, if applicable, systemic risk requirements. The question isn't whether to comply, it's how you'll demonstrate compliance during the gap before European standards arrive.

You have three options:

  • Path A: Adopt the General-Purpose AI Code of Practice now
  • Path B: Wait for harmonized European standards
  • Path C: Demonstrate compliance through alternative documentation and processes

The Commission and EU AI Board have confirmed the Code adequately covers your Article 53 and 55 obligations. That confirmation matters because it reduces regulatory uncertainty around Path A.

Key Factors That Affect Your Choice

Your model's compute threshold determines scope. If you're below 10^25 floating point operations (FLOP), you face transparency and copyright obligations only. Above that threshold, you're a systemic risk provider with additional safety, evaluation, and incident reporting requirements.

Your current documentation maturity matters. If you already maintain comprehensive technical documentation, training data summaries, and copyright policies, Path C becomes more viable. If you're building governance infrastructure from scratch, the Code's structured commitments and measures provide a clearer roadmap.

Your risk tolerance for enforcement scrutiny. The Code isn't legally binding, but providers who don't adopt it must prove compliance "by alternative, possibly more burdensome and time-consuming means." That language from Article 56 signals higher regulatory friction for Path C.

Your timeline for EU market access. If you need to demonstrate compliance quickly to downstream deployers or regulators, waiting until 2027 or later for standards isn't practical.

Path A: Adopt the Code of Practice Now

Choose this path if:

  • You need to demonstrate compliance before August 2027
  • You want regulatory clarity during the standards development period
  • You're willing to commit to structured documentation and retention requirements
  • You value the presumption of compliance that Code adherence provides

What you're committing to:

For transparency (all providers): Maintain up-to-date Model Documentation Forms for every General-Purpose AI Model you distribute in the EU. This includes licensing terms, technical specifications, use cases, training datasets, compute, and energy usage. Store securely for at least ten years. Make available on request to the AI Office and downstream users.

For copyright (all providers): Develop and update a copyright policy with clear internal responsibilities. Ensure web-crawled data is lawfully accessible. Respect machine-readable rights signals like robots.txt. Provide a designated contact point for copyright holder complaints with efficient resolution processes.

For systemic risk (above 10^25 FLOP only): Develop a Safety and Security Framework before model release. Conduct structured risk identification through inventories and scenario analysis. Submit a Safety and Security Model Report prior to release. Track and report serious incidents according to defined severity thresholds and deadlines. Retain detailed records for ten years.

Strategic advantage: The Code was developed through multi-stakeholder engagement involving academic experts, model providers, deployers, and civil society. That collaborative process means the commitments reflect practical implementation realities, not just regulatory theory.

Watch out for: You're committing to measures before knowing what the eventual harmonized standards will require. If standards diverge significantly from the Code, you may need to adjust your processes again in 2027 or beyond.

Path B: Wait for Harmonized Standards

Choose this path if:

  • You can delay EU market distribution until 2027 or later
  • You're confident you can demonstrate interim compliance through alternative means
  • You want to align with international standards (ISO/IEC coordination is prescribed in the AI Act)
  • You're operating in a jurisdiction where standards alignment matters more than early Code adoption

What you're waiting for:

The Commission must issue a standardization request to CEN-CENELEC specifically for GPAI models. That request hasn't been drafted yet. Once issued, the European standardization process typically takes three years, often longer for technical standards and international coordination. The AI Act requires coordination with international standards where possible, which adds time.

Strategic advantage: You'll align with fully harmonized European standards from the start, avoiding potential rework if the Code and standards diverge. You'll also benefit from the consensus-building and technical rigor of the formal standardization process.

Risk exposure: You must still comply with Articles 53 and 55 starting August 2, 2025. Without Code adoption, you'll face scrutiny on how you're demonstrating compliance. Expect more frequent requests for documentation from the AI Office and National Competent Authorities. Expect downstream deployers to demand more detailed evidence of your compliance approach.

Path C: Alternative Compliance Documentation

Choose this path if:

  • You have mature AI governance infrastructure already in place
  • Your documentation and processes exceed Code requirements
  • You're pursuing certification under ISO/IEC 42001 or similar management systems
  • You want flexibility to tailor compliance to your specific risk profile

What you need:

At minimum, you must provide technical documentation to the AI Office and National Competent Authorities on request. You must give downstream providers information on capabilities and limitations. You must maintain training data summaries and copyright compliance policies. If you're above 10^25 FLOP, add state-of-the-art evaluations, risk assessments, incident reporting, and cybersecurity protections.

Strategic advantage: You control the format and depth of your compliance approach. If you're already implementing ISO/IEC 42001 (AI Management Systems) or following NIST AI RMF governance functions, you can map those frameworks to Article 53 and 55 requirements without adopting Code-specific measures.

Burden warning: The AI Act explicitly states this path may be "more burdensome and time-consuming." Without the Code's presumption of adequacy, you'll need to justify your alternative approach repeatedly. Budget for more regulatory engagement, more detailed evidence packages, and potential challenges from National Competent Authorities.

Summary Matrix

Factor Path A: Code Path B: Standards Path C: Alternative
Timeline to demonstrate compliance Immediate 2027+ Immediate but higher burden
Regulatory clarity High Highest (eventually) Low
Documentation burden Structured, defined TBD Self-defined, must justify
Flexibility Moderate Low High
Presumption of adequacy Yes (confirmed by Commission) Yes (when adopted) No
Best for Most providers needing near-term compliance Providers who can delay EU distribution Providers with mature governance already

One final consideration: The Code's adequacy confirmation by the Commission and EU AI Board matters legally. It shifts the burden of proof. With Code adoption, you're presumed compliant unless proven otherwise. Without it, you're proving compliance from scratch every time regulators ask.

For most General-Purpose AI Model providers, Path A offers the clearest route through the interim period. But if you're building for the long term and can absorb near-term regulatory friction, Path C or even Path B might align better with your governance maturity and market timeline.

You Might Also Like