The GPAI Code of Practice, Explained: What Foundation Model Providers Actually Signed
Key takeaways
- -The GPAI Code of Practice (published July 2025) is the voluntary route for general-purpose AI model providers to show compliance with their Chapter V obligations. It has three chapters: Transparency and Copyright apply to all GPAI providers; Safety & Security applies only to models with systemic risk (above the 10^25 FLOP threshold).
- -Enforcement of GPAI obligations begins August 2, 2026 — the Commission's AI Office can fine GPAI providers up to €15 million or 3% of global turnover.
- -Even if you don't build foundation models, this matters: the Code shapes the documentation, copyright posture, and provenance signals of the models you build on. Whether your provider signed affects what you can rely on.
There are two "Codes of Practice" floating around the EU AI Act conversation, and people mix them up constantly. One is about marking AI-generated content under Article 50. The other, the subject of this post, is the General-Purpose AI Code of Practice, and it governs the companies that build foundation models. If you build on Claude, GPT, Gemini, Llama, or Mistral, this is the one that shapes what your provider owes you.
Enforcement of the GPAI obligations begins August 2, 2026, so it's worth understanding what the Code actually asks for, even if you never train a model yourself.
What the GPAI Code is
The European AI Office published the final GPAI Code of Practice in July 2025. Like the content-marking code, it's voluntary: signing isn't mandatory, but doing so and following it is the cleanest way for a model provider to demonstrate compliance with its Chapter V obligations under the AI Act, and to earn a presumption of conformity. Most of the major model providers signed on.
The three chapters
The Code is organised into three chapters, and which ones apply depends on the kind of model you provide.
- Transparency. Signatories keep up-to-date documentation for every GPAI model they put on the EU market, following a standardised Model Documentation Form covering licensing, technical specifications, intended use, and the datasets involved. This is what downstream builders rely on to do their own compliance.
- Copyright. Signatories commit to a real copyright policy: only crawling lawfully accessible data, respecting machine-readable opt-out signals (think robots.txt and rights reservations), putting safeguards in place to limit infringing output, and offering a contact point for rightsholder complaints.
- Safety and Security. This chapter applies only to models with systemic risk — very roughly, models trained above the 10^25 FLOP compute threshold, a group of only a handful of companies worldwide. It covers systemic risk assessment and mitigation, adversarial testing, and incident reporting.
Two chapters for everyone, one for the frontier
Who it covers
The Code is aimed at providers of general-purpose AI models — the companies that develop and distribute foundation models. That's a smaller club than the deployers and downstream developers most of our writing is aimed at. But the line can move: if you take an open model and fine-tune or substantially modify it, you can step into provider territory for the resulting model. Our GPAI developers guide covers where that boundary sits.
Why it matters even if you don't build models
Here's the reason this isn't just a frontier-lab story. If you're a deployer building on a foundation model, the GPAI Code shapes the raw materials you depend on:
- The documentation you inherit. The Transparency chapter is why you can get a usable model card and technical details from your provider. That documentation feeds your own Article 26 obligations. A provider who follows the Code is a provider who makes your compliance possible.
- The copyright posture you sit on. If your provider followed the Copyright chapter, the model you're building on has a cleaner training-data story, which reduces the IP risk that flows downstream to you.
- The provenance signals. Transparency and content-marking commitments upstream make your own Article 50 labelling easier to implement honestly.
In short: whether your model provider signed and follows the GPAI Code is a due-diligence question for you, the same way you'd check any critical supplier. It belongs in your AI vendor assessment.
What to do with this
- If you provide a GPAI model: read the Code, decide whether to sign, and get your Model Documentation Form and copyright policy in order. Enforcement starts August 2, 2026.
- If you build on one: check whether your provider is a signatory and ask for their model documentation. It's the input to your own compliance.
- Either way: don't confuse this with the content-marking Code of Practice — they're different documents with different audiences and different deadlines. Our breakdown of the content-marking Code covers that one.
The GPAI Code is voluntary, but it's quietly load-bearing for the whole ecosystem. The obligations it operationalises are what make the models underneath everyone else's products documentable, and from August 2 they come with real enforcement behind them.
Related articles
The deadlines aren't moving. Get updates that matter.
Get EU AI Act updates, enforcement news, and compliance guides delivered to your inbox. No spam — unsubscribe any time.
Check your AI system's risk level for free
Our classifier maps your AI system against the EU AI Act in under 60 seconds. No signup required.
Classify Your AI System