GPAI Code: When Voluntary Compliance Shapes Regulatory Compliance
The Code of Good Practice for General-Purpose AI Models, published on July 10, 2025, is voluntary; however, it is by no means peripheral. It translates the requirements of the AI Act into structured measures and provides providers who adhere to it with a pathway to demonstrate compliance. As of February 12, 2026, the organization of signatories around a working group chaired by the European AI Bureau demonstrates how this voluntary approach is becoming a widely followed implementation framework. For business leaders, the issue is therefore not to confuse code with law, but to understand how the two combine in terms of evidence and governance.
Updated September 10, 2026. Regulation (EU) 2026/1744 amending the AI Act was published in the Official Journal on July 24, 2026, and entered into force on July 27. The new deadlines for high-risk systems are now set for December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Full details in our reference article.
The Essentials in 30 Seconds
- The final version of the GPAI Code was made available on July 10, 2025.
- The AI Act requirements applicable to general-purpose model providers have been in effect since August 2, 2025.
- The code includes chapters on transparency, copyright, and safety and security.
- The European AI Bureau invited providers to join and published a list of signatories on August 1, 2025.
- The first inaugural meeting of the signatories’ working group was held on January 30, 2026, chaired by the European AI Bureau.
What Happened
The Commission received the final version of the code on July 10, 2025. It presents it as a voluntary tool, developed by thirteen independent experts with input from more than a thousand stakeholders. Its practical objective is to help the sector apply the rules of the AI Act relating to general-purpose AI models. It therefore does not replace either the regulation or the provider’s legal analysis; rather, it offers a structured approach to meeting the obligations to which the regulation refers.
Three sections form the backbone of the code. The chapter on transparency applies to providers of general-purpose models. In particular, it requires model documentation and the provision of useful information to downstream providers. The chapter on copyright also applies to all relevant providers and sets out a policy for complying with EU law. The chapter on safety and security targets providers of the most advanced models posing a systemic risk; it addresses the management of these risks.
On August 2, 2025, the corresponding obligations under the AI Act took effect. The Commission has indicated that providers who voluntarily sign the code can demonstrate their compliance with the relevant obligations by adhering to it, once the code has been endorsed by the Commission and the Member States. The rationale is important: signing the code does not eliminate the legal obligation; it establishes a compliance pathway that the regulator can follow.
Signatories to a Working Framework
Adherence itself is formalized. The European AI Bureau has provided a signatory form, to be signed by a person with the necessary authority to bind the provider. The list of signatories was published on August 1, 2025. This publication serves a governance purpose: it identifies the companies that have adopted this framework and distinguishes adherence to the code from general commitments regarding responsible AI.
The structure is further developed through the signatories’ working group. The first meeting, held on January 30, 2026, was a constitutive meeting. Its purpose is to discuss the implementation of the code; it is chaired by the European AI Bureau. As of February 12, this does not transform the group into a legislative body. However, it does create a forum where a common operational interpretation, implementation challenges, and documentation practices can be discussed with the authority overseeing the code.
This explains the shift within organizations from “voluntary” to “mandatory.” When a code includes detailed commitments, a public list of signatories, a mechanism for exchange, and monitoring of compliance, the gap between the code’s text and internal practices becomes apparent. The pressure does not stem from a new, standalone obligation; it stems from the need to prove that the chosen path is actually being followed.
What the Code Changes in Evidence
In terms of transparency, the code is concrete. Signatories commit to establishing and maintaining model documentation, providing downstream providers with the necessary information, and supplying the requested information to the European AI Office. The documentation must be retained as evidence, protected against unintentional modifications, and kept for ten years after the model is placed on the market. Additional information requested by a downstream provider must, except in exceptional circumstances, be provided no later than 14 days after the request.
Limitations and Policy Decision
A clear legal distinction must be maintained. The code is described as a guidance document to demonstrate compliance with Articles 53 and 55; adherence to it is not, on its own, conclusive proof of compliance. A non-signatory company may seek to demonstrate its compliance in other ways. A signatory company, on the other hand, must avoid the opposite risk: invoking the code while leaving commitments unaccounted for, without supporting evidence, or without monitoring changes.
The decision to sign must therefore be preceded by a capability analysis. Which models are placed on the EU market? Which commitments in each chapter are applicable? Are training materials, documentation, requests from downstream suppliers, and risk management already governed? The key indicator is not the number of internal policies; it is the ability to produce the requested information in a consistent and up-to-date manner.
What to Do Now
- Define the Role — confirm whether the organization is a supplier of a general-purpose model and for which models.
- Review by chapter — assign transparency, copyright, and safety and security responsibilities to the relevant functions.
- Test the documentation — simulate a request from a downstream supplier and verify the turnaround time, version, and controls.
- Govern Adherence — if signing is being considered, have an authorized person sign it and incorporate the commitments into internal controls.
- Monitor the group of signatories — document exchanges relevant to the interpretation and implementation of the code.
Sources
- GPAI Code of Practice, final version, quantified commitments (ten-year retention period, fourteen-day deadline for downstream suppliers): code-of-practice.ai
- European Commission, final version of the GPAI Code and its three chapters: ec.europa.eu
- European Commission, invitation to join, form, and signing procedures: digital-strategy.ec.europa.eu
- European Parliament, analysis of the code, list published on August 1 and non-binding status: europarl.europa.eu
- European Commission, inaugural meeting of the signatories’ working group: digital-strategy.ec.europa.eu
← AI Act: The European Timeline to Be Prepared by August 2026 (2026-01-15)AI Content: What Labeling Requirements Mean for Businesses (2026-03-05) →