Glossary · EU AI Regulation GPAI Code of Practice (General-Purpose AI (GPAI) Code of Practice under the EU AI Act)
Voluntary Code of Practice for providers of general-purpose AI models, published by the EU AI Office in 2025 under the AI Act. Establishes operational expectations for transparency, copyright compliance, safety, security, and AI governance. Signatories include OpenAI, Anthropic, Google, Mistral, Aleph Alpha. Foundational reference for GPAI compliance through 2027.
## What the GPAI Code of Practice actually is
The GPAI Code of Practice is the voluntary operational framework for providers of general-purpose AI (GPAI) models — large foundation models trained on broad data and adaptable to multiple downstream tasks. Published by the EU [AI Office](/en/glossary/ai-office/) in 2025 under the [AI Act](/en/glossary/eu-ai-act/), the Code translates the AI Act's GPAI obligations into concrete operational expectations.
The Code is voluntary — but adherence creates **presumption of compliance** with the AI Act's GPAI provisions. For foundation-model providers serving the EU market, signing and adhering to the Code is the practical path to demonstrating regulatory compliance.
## What the Code covers
The Code is structured into chapters addressing distinct GPAI obligation areas:
### 1. Transparency
Signatories commit to providing:
- **Model documentation**: capabilities, limitations, intended use cases, training methodology
- **Training-data summaries**: nature and scope of training data without requiring proprietary disclosure
- **Technical specifications**: parameter counts, architecture overview, training compute
- **Use-restriction guidance**: what the model should and shouldn't be used for
- **Update and versioning practices**: how model versions are tracked and communicated
### 2. Copyright compliance
A major focus of the Code addresses the copyright tension in AI training:
- **Rights-reservation handling**: respecting opt-out signals from copyright holders (robots.txt, TDM exemption signals)
- **Training-data provenance**: documentation of training-data sources and licensing
- **Designated point of contact**: for copyright holders to raise concerns
- **Complaint mechanism**: structured process for addressing copyright-related issues
### 3. Safety and security (for systemic-risk GPAI models)
For GPAI models meeting "systemic risk" thresholds, additional safety and security commitments apply:
- **Model evaluations**: red-teaming, adversarial testing, capability evaluations
- **Risk assessment**: structured identification of misuse and emergent-capability risks
- **Risk mitigation**: technical measures and operational safeguards
- **Incident reporting**: notification to AI Office of significant safety incidents
- **Cybersecurity**: protection of model weights, inference infrastructure, training pipelines
### 4. AI governance
Signatories establish internal AI governance practices:
- **Designated responsible parties** for Code adherence
- **Internal risk-management frameworks** aligned with the Code's commitments
- **External engagement** with researchers, civil society, downstream deployers
- **Continuous improvement** as AI capabilities evolve
## Who has signed
Major foundation-model providers signed at Code publication:
- **OpenAI**
- **Anthropic**
- **Google** (DeepMind, including Gemini)
- **Mistral AI** (French foundation-model leader)
- **Aleph Alpha** (German foundation-model provider)
- **Meta** (with specific carve-outs around open-weight commitments)
- **Microsoft** (in coordination with OpenAI partnership)
- **Amazon** (Bedrock-coordinated commitments)
- Other significant foundation-model providers
A small number of major providers have declined to sign — notable both for what the non-signature signals and for the political pressure that follows.
## Why the Code matters
### 1. Presumption-of-compliance mechanism
Code adherence creates legal presumption of AI Act GPAI compliance. For foundation-model providers serving EU markets, this dramatically reduces regulatory uncertainty — adherence becomes the default route to demonstrating compliance.
### 2. Operational standard-setting
The Code translates relatively abstract AI Act provisions into concrete operational expectations. This standard-setting effect propagates beyond direct signatories — non-signatory providers face implicit market pressure to match Code-equivalent practices.
### 3. Copyright operational framework
The copyright provisions of the Code provide the first comprehensive operational framework for AI training in relation to EU copyright law. The rights-reservation handling, designated points of contact, and complaint mechanism create infrastructure that had been notably absent.
### 4. Systemic-risk safety framework
For systemic-risk GPAI models, the Code's safety and security provisions establish the most concrete operational expectations to date for advanced AI safety practices. This influences global AI safety discourse beyond EU jurisdiction.
### 5. EU positioning advantage
European foundation-model providers (Mistral, Aleph Alpha) treat Code participation as competitive advantage — they can credibly claim Code-aligned practices native to EU regulatory context, contrasting with US providers operating under different baseline assumptions.
## The Code's three-year horizon
The Code is intended for the AI Act's transitional GPAI compliance period (2024-2027). After the formal harmonised standards become available (expected 2027-2028), the Code may evolve into harmonised technical standards or remain as voluntary practice alongside formal requirements.
For now, the Code is the operational reference for AI Act GPAI compliance for the rest of the decade.
## How the Code interacts with other AI regulation
### With the AI Act itself
The Code operationalises AI Act GPAI provisions but does not replace them. The AI Act's direct provisions on GPAI remain binding; the Code provides the practical compliance pathway.
### With the AI Pact
The voluntary [AI Pact](/en/glossary/ai-pact/) is broader — covering AI providers and deployers across the AI value chain. The GPAI Code of Practice is specifically focused on foundation-model providers. Signing the AI Pact and signing the GPAI Code of Practice are separate but related commitments.
### With AI Office enforcement
Code adherence is monitored by the AI Office. Violations of voluntary Code commitments could trigger formal AI Act enforcement actions for the underlying mandatory provisions. The Code is voluntary in structure but creates enforceable expectations in substance.
### With AI Liability Directive (if adopted)
The [AI Liability Directive](/en/glossary/ai-liability-directive/), if adopted, would interact with GPAI Code compliance as evidence of duty-of-care fulfilment. Code adherence becomes legal-defence-relevant.
## How the Code affects AI development
### For foundation-model providers serving EU
Code signature is effectively expected. Non-signature is a market-signal that creates customer and regulatory friction. The compliance investment required (model documentation, copyright systems, safety practices, governance) is substantial but proportionate.
### For downstream AI deployers
Deployers integrating GPAI models can rely on Code-compliant providers' documentation for their own AI Act compliance work. This dramatically simplifies downstream-deployer compliance.
### For European AI startups
European foundation-model providers (Mistral, Aleph Alpha) use Code participation as differentiation. For European AI startups building on top of GPAI models, choosing Code-compliant providers simplifies own-compliance.
### For US-headquartered AI providers
Code participation is the practical path to EU market access for foundation-model providers. The required operational investments (transparency, copyright systems, safety practices) are substantial but enable continued European customer access.
## Practical implications
- **For AI providers serving EU markets**: Code signature is increasingly procurement-relevant and effectively expected for serious EU customer engagement
- **For AI deployers**: choose Code-compliant providers to simplify downstream compliance work
- **For European AI startups**: Code participation creates competitive differentiation
- **For policy and compliance teams**: Code is the operational reference for AI Act GPAI compliance through 2027
- **For procurement teams**: include GPAI Code-signature status in AI vendor evaluation
- **For copyright holders**: the Code's rights-reservation handling and complaint mechanism provide concrete recourse
The GPAI Code of Practice is the most operationally significant single instrument under the AI Act for the rest of the decade. Its adoption pace and enforcement experience are setting global norms for foundation-model governance.
Was this helpful?
Thanks for your feedback!