Skip to main content
Category: EU AI Act & GPAI

General-Purpose AI Code of Practice

Also known as: GPAI Code of Practice, Code of Practice for General-Purpose AI, GPAI Code, General-Purpose AI Code of Practice
Simply put

The General-Purpose AI Code of Practice is a document developed to help companies that provide general-purpose AI models meet their legal obligations under the EU AI Act, particularly regarding transparency, copyright, and safety. It is intended as a practical tool that translates certain AI Act rules into guidance that providers can follow. It applies within the European Union context and is one route through which providers may demonstrate compliance rather than a separate body of law itself.

Formal definition

The General-Purpose AI Code of Practice is an instrument associated with the EU AI Act that details how providers of general-purpose AI (GPAI) models can meet relevant obligations concerning transparency, copyright, and safety and security. Per the evidence, it is organised into three chapters—Transparency, Copyright, and Safety and Security—and is presented as a means for industry to comply with AI Act legal obligations, with the underlying GPAI rules reported to have taken effect on 2 August 2025 for new models released from that date. The evidence characterises the Code as a compliance-facilitation mechanism drawn up for and received by the European Commission; it should not be conflated with the AI Act's binding statutory provisions themselves, and its precise legal status, degree of adherence expectation, and scope of application are not fully specified in the evidence provided here.

Why it matters

The General-Purpose AI Code of Practice matters because it functions as a practical bridge between the EU AI Act's obligations for general-purpose AI (GPAI) model providers and the day-to-day steps those providers can take to demonstrate compliance. The GPAI rules under the AI Act are reported to have taken effect on 2 August 2025, meaning new models released from that date fall within scope; the Code offers a structured route—organised around transparency, copyright, and safety and security—for providers navigating those obligations. For organisations building or deploying GPAI models in the EU, the Code shapes how they document their systems, address copyright considerations, and manage safety and security concerns.

Who it's relevant to

Providers of general-purpose AI models
Companies that develop or supply GPAI models for the EU market are the primary audience. The Code offers them a structured means of addressing transparency, copyright, and safety and security obligations, and adherence may serve as one route toward demonstrating compliance with the corresponding AI Act rules. Providers should confirm scope and the current legal status of the Code against authoritative sources, as those details are not fully specified in the evidence here.
AI governance and compliance teams
Governance officers and compliance specialists operating in or serving the EU context can use the Code's three-chapter structure to organise policies, documentation, and internal controls for GPAI models. It is relevant to how they design accountability and oversight processes, while keeping the distinction between the Code as guidance and the AI Act's binding provisions.
Legal and copyright professionals
Because one of the Code's chapters addresses copyright, legal advisers working with GPAI providers may consult it when assessing how transparency and copyright obligations under the AI Act are approached in practice. The evidence does not specify the precise legal weight of the Code, so professionals should treat its status as a matter requiring further verification.
Model risk and safety functions
Teams responsible for identifying, monitoring, and controlling risks from AI models may find the Safety and Security chapter relevant to structuring their practices. This is distinct from, though overlapping with, broader model risk management disciplines; the Code is scoped to EU GPAI obligations rather than serving as a general model risk framework.

Inside GPAI Code of Practice

General-Purpose AI (GPAI) scope
The Code of Practice is oriented toward providers of general-purpose AI models, which are typically understood as models trained on broad data and capable of performing a wide range of distinct tasks. The precise boundary of what qualifies as GPAI, including thresholds tied to systemic-risk characterization, is defined within the EU AI Act framework rather than by the Code itself, and readers should consult the current legislative text for the operative definitions.
Voluntary, guidance-style instrument
The Code of Practice is commonly understood as a mechanism to help providers demonstrate compliance with obligations for general-purpose AI models under the EU AI Act. As a code of practice it is generally a facilitation tool rather than the primary binding legal text; the underlying legal obligations derive from the Act. Its exact legal weight and the conditions under which adherence is recognized should be verified against the current EU framework.
Transparency and documentation elements
Codes of practice of this kind typically address documentation that providers maintain and make available, such as information about a model's capabilities, limitations, and intended uses, to support downstream deployers and relevant authorities. The specific documentation items required are governed by the EU AI Act's provisions for GPAI providers.
Copyright and training-data considerations
Commentary around GPAI obligations often references measures relating to compliance with EU copyright law and to summaries of content used for training. Whether and how such elements appear in a given version of the Code should be confirmed against the published text, as details in this area have been subject to development.
Systemic-risk measures for higher-capability models
Frameworks addressing GPAI commonly distinguish models that may present systemic risk and associate them with additional expectations, such as risk assessment and mitigation. The applicable criteria and any corresponding measures are set by the EU AI Act, and the Code functions to help operationalize them rather than to establish them.

Common questions

Answers to the questions practitioners most commonly ask about GPAI Code of Practice.

Is signing the GPAI Code of Practice legally mandatory for providers of general-purpose AI models?
No. As commonly described, the GPAI Code of Practice is a voluntary instrument rather than binding law in itself. It is intended to function as a tool that providers can use to demonstrate compliance with obligations that apply to general-purpose AI models under the EU AI Act. Providers may choose not to adhere to the Code and instead demonstrate compliance by other adequate means, though doing so may attract closer scrutiny. The distinction between a voluntary code and the underlying legal obligations it helps evidence is one that professionals should keep clear.
Does adhering to the GPAI Code of Practice mean a provider has satisfied all of its EU AI Act obligations?
Not necessarily. Adherence to the Code is typically framed as a way to demonstrate compliance with specific obligations applicable to general-purpose AI models, not as a blanket discharge of every obligation under the EU AI Act. Other requirements — for example those attaching to high-risk AI systems, or duties borne by deployers rather than model providers — sit outside the scope of a code focused on general-purpose models. Treating adherence as full legal compliance conflates a narrowly scoped instrument with the broader regulatory framework.
How does adherence to the GPAI Code of Practice interact with an organization's existing AI governance structures?
Adherence generally involves mapping the Code's expectations to internal accountability structures, policies, and oversight processes. Because the Code addresses obligations at the level of the general-purpose model provider, organizations typically assign ownership for its commitments within their governance framework — clarifying who is accountable for documentation, transparency measures, and any risk-related expectations. This is a governance activity concerned with structures and accountability, and it is distinct from, though it may draw on, the technical model risk management processes used to identify and control model-specific risks.
What kinds of documentation are typically associated with demonstrating adherence to the Code?
The Code is commonly associated with expectations around technical documentation and transparency information about a general-purpose AI model, which providers may need to make available to downstream deployers and, where applicable, to regulators. The precise contents and format expected can evolve, so organizations should confirm current expectations rather than rely on a fixed checklist. Because the specific documentation elements are subject to change, this entry does not enumerate mandatory fields; providers should verify the operative requirements applicable to their situation.
Who within an organization is usually responsible for operationalizing the Code's commitments?
Responsibility is typically distributed across governance and risk functions. Compliance and legal specialists often own interpretation of how the Code maps to the underlying obligations, while first-line teams building or supplying the model may own the substantive documentation and technical measures. Second-line functions may provide oversight and challenge. The allocation depends on an organization's own operating model, and the Code does not by itself prescribe a single organizational design; roles should be assigned according to established lines-of-defense arrangements.
How should an organization monitor whether its adherence to the Code remains current?
Because the Code is an evolving instrument and its relationship to the underlying legal framework may develop over time, organizations typically treat monitoring as an ongoing activity rather than a one-time exercise. This can include tracking updates to the Code and to associated regulatory expectations, and periodically reassessing whether existing measures still support a claim of adherence. Adherence should be understood as a measure that supports demonstrating compliance rather than one that eliminates regulatory or model-related risk, and readers should confirm the current status of the Code before relying on it.

Common misconceptions

The GPAI Code of Practice is itself binding law that all AI providers must follow.
As commonly characterized, the Code is a facilitation instrument that helps providers demonstrate compliance; the binding obligations sit in the EU AI Act. Its status is oriented to the EU jurisdiction and to general-purpose AI models specifically, not to all AI systems or all providers globally. Confirm the current legal treatment against the published Act and Code.
Following the GPAI Code of Practice satisfies an organization's full AI governance and model risk management obligations.
The Code addresses a specific EU obligation set for GPAI providers. It does not substitute for broader AI governance structures (organizational accountability and oversight) or for model risk management practices (identification, measurement, monitoring, and control of model risk), which are distinct disciplines that may be shaped by other frameworks and, in regulated sectors, by separate supervisory expectations.
Adhering to the Code eliminates the risks associated with general-purpose AI models.
Adherence is a measure that can help manage and reduce risk and support demonstrating compliance; it does not eliminate risk. Residual risk typically remains and requires ongoing monitoring and control regardless of code adherence.

Best practices

Treat the Code as a compliance-support tool for the EU AI Act's GPAI obligations, and trace each element back to the operative legal text rather than relying on the Code in isolation.
Verify scope before acting: confirm whether your model qualifies as general-purpose AI, and whether it may fall within any systemic-risk characterization, using the current EU AI Act definitions rather than assumptions.
Maintain and keep current the documentation on model capabilities, limitations, and intended uses that supports downstream deployers and relevant authorities, and version-control it as the model changes.
Do not treat Code adherence as a replacement for organizational AI governance or for model risk management; maintain distinct accountability structures and risk identification, monitoring, and control processes.
Confirm the present status and text of the Code and its associated obligations directly against published EU sources, since details, including copyright and training-data elements, have been subject to development.
Continue monitoring for residual risk after adopting any Code-aligned measures, since such measures reduce rather than eliminate risk.