European Union

The GPAI Code of Practice: What Signatories Actually Commit To

Signing the GPAI Code of Practice isn't a pledge — it's a specific set of measures around documentation, copyright, and safety reporting, with a legal presumption of conformity attached. Here's what each chapter actually requires.

Voluntary instrument, in effect since July 2025Effective July 10, 2025
Legal and compliance staff reviewing the commitments in the EU's GPAI Code of Practice
Photo: Anastassia Anufrieva via Unsplash

Most coverage of the GPAI Code of Practice treats it as a headline event — "OpenAI and Anthropic signed a pledge," "Meta refused to sign." That framing makes it sound symbolic, like a statement of intent a company can walk back with a press release. It isn't one. The Code is a structured set of specific, checkable measures a signatory commits to carrying out, tied directly to Articles 53 and 55 of the EU AI Act, and signing it creates real operational work, not a headline. This page goes through what a signatory is actually agreeing to do, chapter by chapter — not that the Code exists, but what's inside it.

Why the Code exists: Article 56 and the presumption of conformity

Article 56 lets the AI Office facilitate voluntary codes of practice that general-purpose AI providers can rely on to demonstrate compliance with Articles 53 and 55, until the EU publishes formal harmonised standards covering the same ground. The European Commission published the actual Code — the General-Purpose AI Code of Practice — on July 10, 2025, after a multi-stakeholder drafting process led by independent experts.

The mechanism that makes this worth a company's attention isn't goodwill; it's the legal effect. Adhering to the Code creates a presumption of conformity with the corresponding Chapter V obligations — functionally similar to how harmonised technical standards work elsewhere in EU product-safety law. A signatory that follows the Code's measures gets to point to that adherence as evidence of compliance. A provider that declines still has to comply with Articles 53 and 55 regardless — the underlying legal duties don't disappear — but has to demonstrate that compliance to the AI Office directly, case by case, which is a heavier lift during any actual inquiry than pointing to a documented, recognized set of measures.

Chapter 1 — Transparency: the Model Documentation Form

The Transparency chapter applies to every provider of a general-purpose AI model, systemic-risk or not. Its core commitment is completing a standardized Model Documentation Form before placing the model on the market — covering training data sources, intended use cases, licensing information, and evaluation results, operationalizing the Article 53(1) documentation duty rather than leaving providers to interpret it from scratch.

Three things about the commitment matter beyond just filling out the form once. It has to stay current: signatories commit to updating the documentation to reflect material changes to the model, not treating it as a one-time filing. It has a long retention floor: the completed form has to be preserved for a minimum of 10 years after the model's initial release. And it has to be reachable: signatories commit to publishing contact details so the AI Office and downstream integrators — companies building products on top of the model — can actually request access to it, rather than the documentation existing only internally.

The Copyright chapter also applies to every signatory, and it's the most specific — and least accurately summarized — part of the Code. It's built around a provider's Article 53(1)(c) duty to maintain a policy that respects EU copyright law, in particular the text-and-data-mining opt-out rights that Article 4(3) of the DSM Directive (Directive (EU) 2019/790) gives rights holders.

Concretely, signatories commit to identifying and complying with machine-readable rights reservations when crawling the web for training data — respecting robots.txt and any successor protocol used to express an opt-out — and to excluding sources that an EU or EEA court or authority has found to be persistently and repeatedly infringing copyright at commercial scale. There's also a narrower, easy-to-miss commitment aimed specifically at providers that operate both a general-purpose AI model and a web search engine: honoring a website's crawling opt-out can't be allowed to degrade that site's ranking in the provider's own search results. Without that carve-out, a site owner opting a crawler out of AI training could end up penalized in unrelated search visibility — the Code treats that as a form of retaliation and rules it out.

Chapter 3 — Safety and Security: only for systemic-risk models

The third chapter has a scope boundary the first two don't: it only binds signatories whose models are classified as posing systemic risk — the tier defined by Article 51's presumption that a model crossing 10^25 floating-point operations of cumulative training compute has "high-impact capabilities." A provider whose model sits under that threshold, and isn't otherwise designated by the Commission, never has Safety and Security obligations under the Code, no matter how many other chapters it signs.

For a systemic-risk signatory, the commitment is a Safety and Security Framework — tailored to the specific model's risk profile, finalized before the model goes to market, and notified to the AI Office rather than kept purely internal. Alongside it sits a serious-incident-reporting commitment: tracking incidents from both internal testing and external sources, including reports routed in from downstream deployers and users; notifying the AI Office and affected parties without undue delay on a clock that tightens with severity; and preserving incident logs for a minimum of 5 years. This is the chapter that turns the Code from a documentation exercise into something closer to an ongoing safety-monitoring obligation, and it's the one most providers never encounter, because most general-purpose AI models never cross the compute threshold that triggers it.

A worked example: two providers, two different sets of commitments

Take a hypothetical company, Lumen Systems, that releases a 20-billion-parameter model called LumenChat, trained on roughly 3×10^24 FLOPs — comfortably under the 10^25 systemic-risk threshold. If Lumen signs the full Code, its actual commitments are Chapters 1 and 2 only: complete and maintain the Model Documentation Form, publish request contact details, and run its web-crawling and copyright practices under the Chapter 2 opt-out and infringing-source rules. Chapter 3 never applies to LumenChat, because it was never classified as systemic risk.

Now suppose Lumen trains a successor, LumenChat-2, and cumulative training compute this time comes in at 1.2×10^25 FLOPs — past the threshold. Lumen's Code commitments change the moment that classification attaches. Chapters 1 and 2 still apply, unchanged. But Lumen now also owes Chapter 3 in full: a Safety and Security Framework specific to LumenChat-2, notified to the AI Office before launch, plus the serious-incident-tracking and reporting commitments with their five-year log retention. Nothing about signing the Code once locks a provider into a fixed set of commitments forever — what a signatory actually owes tracks what its models are classified as, model by model, release by release.

Who actually signed — and who didn't

The signatory list reads like most of the frontier AI industry: Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, and Mistral AI all signed the full three-chapter Code within weeks of its July 2025 publication, along with a range of smaller and specialized AI companies. That breadth is itself informative — for most providers, the compliance benefit of the presumption of conformity outweighed the operational cost of the commitments above.

Meta is the most notable holdout. The company publicly declined to sign in July 2025, with its Chief Global Affairs Officer stating that the Code "introduces a number of legal uncertainties for model developers, as well as measures which go far beyond the scope of the AI Act." That makes Meta the clearest example of a major lab choosing to demonstrate Article 53/55 compliance independently rather than through the Code.

xAI shows the middle path: it signed only the Safety and Security chapter, leaving the Transparency and Copyright chapters unsigned. That means xAI still has to demonstrate its Article 53 documentation and copyright compliance through its own means — the Code's presumption of conformity only covers the chapter it actually signed. Partial adherence like this is a legitimate, structured option under the Code, not a loophole.

What not signing actually costs a provider

Declining the Code, in whole or in part, doesn't put a provider outside the law — Articles 53 and 55 apply to every in-scope general-purpose AI model regardless of whether its provider ever signs anything. What changes is the burden of proof. A non-signatory has to independently demonstrate to the AI Office that it meets the underlying obligations, without the shortcut of pointing to documented, recognized Code measures — a materially harder position to be in if the AI Office opens an inquiry, and one that forfeits the legal-certainty benefit the presumption of conformity is specifically designed to provide. For what's actually at stake if that self-demonstrated compliance turns out to fall short, see our breakdown of the EU AI Act's tiered penalty structure, which the EU AI Office enforces directly against general-purpose AI model providers.

Frequently asked questions

Is the GPAI Code of Practice legally required?
No — it's voluntary under Article 56 of the EU AI Act. A provider can comply with Articles 53 and 55 without signing, but then has to demonstrate that compliance directly to the AI Office rather than relying on the Code's presumption of conformity, which signatories get automatically for the obligations the Code covers.
Does signing the Code cover all of a provider's EU AI Act obligations?
No. The first two chapters, Transparency and Copyright, cover the Article 53 baseline that applies to every general-purpose AI provider. The third chapter, Safety and Security, only applies to providers whose models are classified as posing systemic risk under Article 51. A non-systemic-risk provider signing the Code is only ever committing to the first two chapters.
Can a company sign only part of the Code?
Yes. xAI, for example, signed only the Safety and Security chapter, which means it still has to demonstrate its Article 53 transparency and copyright compliance through other means rather than through the Code's presumption of conformity for those two chapters specifically. Partial signing is a real, available option, not an all-or-nothing choice.
What exactly does the Transparency chapter's Model Documentation Form require?
Signatories commit to completing a standardized form covering the model's training data sources, intended use cases, licensing information, and evaluation results before placing it on the market, keeping the form current as the model changes, retaining it for a minimum of 10 years after the model's release, and publishing contact details so the AI Office and downstream integrators can request access.
Why did Meta decline to sign the GPAI Code of Practice?
Meta said the Code introduces legal uncertainties for model developers and includes measures it considers to go beyond the scope of the AI Act's actual text. It was the most notable holdout among major labs — OpenAI, Google, Anthropic, Microsoft, Amazon, and Mistral AI all signed the full Code within weeks of its July 2025 publication.

Sources & references

  1. Official source
  2. European Commission — General-Purpose AI Code of Practice
  3. Regulation (EU) 2024/1689, Articles 53, 55, 56 (full text, EUR-Lex)
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Engineers and compliance staff reviewing technical documentation for a general-purpose AI model
Photo: selcuk sarikoz via Unsplash
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Governome Editorial Team · 9 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read
Compliance team calculating potential EU AI Act fine exposure across the tiered penalty structure
Photo: Vitaly Gariev via Unsplash
EU AI Act fines aren't a single €35 million number. Article 99 defines three separate tiers by violation type, Article 101 sets a fourth track for general-purpose AI model providers enforced directly by the Commission, and Article 100 even reaches EU institutions themselves. Here's the full structure, including the SME inversion rule that changes real exposure by orders of magnitude.
Governome Editorial Team · 7 min read
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
Governome Editorial Team · 2 min read