The General-Purpose AI Code of Practice presents a choice: adopt its framework entirely or create your own compliance path under the EU AI Act. Both options come with costs and risks. Here's what practitioners are debating.
The Question at Hand
Starting August 2, 2025, every General-Purpose AI Model distributed in the EU must comply with Article 53 of the EU AI Act. The Code of Practice offers a structured guide covering transparency, copyright, and safety obligations. However, it's voluntary. You can demonstrate compliance through alternative methods that align with your organization's governance structure.
Which path makes sense? The decision isn't straightforward, forcing governance teams to balance standardization with flexibility, both of which have their own costs.
The Case for Adopting the Code
Those in favor of adoption highlight regulatory clarity. The Code translates legal requirements into concrete measures. You'll know what documentation the AI Office expects, what copyright safeguards meet Article 53(1)(c), and how to structure your Safety and Security Framework before releasing a model.
The Model Documentation Form alone reduces ambiguity. Instead of interpreting Annex XI requirements yourself, you follow a standardized template covering licensing, technical specifications, dataset details, and compute usage. You maintain this documentation for ten years, provide it to downstream users within 14 days, and deliver it to the AI Office on request. Clear expectations, clear timelines.
The copyright chapter offers similar specificity. You're not guessing which web crawling practices comply with Directive (EU) 2019/790. The Code requires honoring robots.txt files, excluding websites flagged by EU authorities for copyright infringement, and maintaining a contact point for rights holder complaints. These are testable controls.
For models with systemic risk, the safety commitments provide a compliance blueprint that aligns with your AI Management System under ISO/IEC 42001. You'll implement risk tiering frameworks, conduct adversarial simulations, establish phased access controls, and submit Safety and Security Model Reports before release. The Code's Appendix 3 even specifies evaluation methodologies, reducing the interpretive burden on your assurance team.
There's also a grace period argument. Enforcement actions don't begin until August 2, 2026, giving Code signatories a full year to work with the AI Office on implementation questions. For models released before August 2, 2025, you have until August 2, 2027, to achieve compliance. That's breathing room you won't get if you're defending a bespoke approach under regulatory scrutiny.
The Case for Alternative Compliance Paths
The counterargument focuses on organizational fit and strategic flexibility. Your existing model risk framework may already exceed Code requirements in some areas while approaching others differently. Forcing alignment with the Code could mean retrofitting governance structures that already work.
Consider serious incident reporting. The Code mandates reporting within two days for incidents affecting critical infrastructure, with records retained for five years. If your organization operates under SR 11-7 or has implemented NIST AI RMF with mature incident response processes, you might already have faster escalation paths and longer retention periods. Adopting the Code doesn't eliminate your existing obligations. It adds a parallel compliance layer.
Documentation presents a similar tension. The Model Documentation Form requires specific elements covering training methodology, dataset curation, and energy usage. But if you're already producing Model Cards aligned with your AI RMF Profile and maintaining Technical Documentation under Annex IV for high-risk downstream applications, you're creating multiple documentation artifacts that serve overlapping purposes. That's not efficiency. That's documentation debt.
The copyright chapter's web crawling requirements assume a particular technical architecture. If you don't crawl the web for training data, or if you source data through licensed partnerships with clear rights reservations, you're implementing controls for risks you don't face. Meanwhile, the Code doesn't address your actual copyright challenges around synthetic data generation or fine-tuning on proprietary corpora.
There's also the open-source exemption. If you're distributing free, open-source models without systemic risk, the transparency commitments don't apply to you. Signing the Code anyway creates unnecessary compliance overhead.
Finally, the Code will evolve. Appendix 1 references "other considerations" for systemic risk assessment that aren't fully specified. Your alternative approach might prove more adaptable as regulatory interpretation develops through case law and AI Office guidance.
Where Practitioners Actually Land
Most organizations aren't choosing one path exclusively. They're adopting Code measures where they fill gaps and maintaining existing controls where they're more mature.
A typical pattern: use the Model Documentation Form as a baseline template, but extend it with additional elements your validation team requires for model approval. Implement the copyright crawling restrictions, but integrate them into your broader data governance program under GDPR and your Data Protection Impact Assessment process. Build your Safety and Security Framework around the Code's risk categories, but calibrate risk tiers to your organization's risk appetite and materiality thresholds.
The real decision isn't binary. It's about which elements of the Code strengthen your governance posture and which create friction without reducing risk.
Our Take
Sign the Code if you're building General-Purpose AI Models from scratch without established governance infrastructure. The framework will accelerate your time to compliance and reduce interpretation risk during the enforcement grace period.
Don't sign if you've already implemented an AI Management System under ISO/IEC 42001 with mature controls covering model validation, Post-Market Monitoring, and stakeholder engagement. Instead, conduct a gap analysis mapping your existing controls to Code measures. Adopt specific elements where they add rigor, document your alternative approach for each requirement, and prepare to demonstrate equivalence to the AI Office.
The worst outcome isn't choosing the wrong path. It's treating the Code as either mandatory or irrelevant. It's neither. It's a compliance tool that works best when you use it selectively, with clear rationale for where you diverge.
Your documentation strategy for that rationale matters as much as the controls themselves. When the AI Office requests information after August 2, 2026, you'll need to show not just what you did, but why your approach satisfies Article 53 obligations. That's true whether you signed the Code or not.



