Skip to content

The GPAI Code of Practice as a Compliance Route

9 min read · updated August 11, 2026

The General-Purpose AI Code of Practice is voluntary, and it is still the most consequential document in the GPAI regime, because Articles 53(4) and 55(2) attach a presumption of conformity to adhering to it. Knowing exactly what that presumption does and does not do is the whole of this page.

What adherence actually buys

Article 56 of Regulation (EU) 2024/1689 tasks the AI Office with encouraging and facilitating the drawing up of codes of practice at Union level, taking account of international approaches. The legal effect is not in Article 56 itself but in the two articles it serves. Article 53(4) provides that providers of general-purpose AI models may rely on codes of practice to demonstrate compliance with the Article 53(1) obligations until a harmonised standard is published, and Article 55(2) does the same for the systemic-risk obligations. Both say that providers who adhere to approved codes of practice benefit from a presumption of conformity to the extent the code covers the obligation.

Three limits on that presumption are worth stating plainly, because they are where the value of the page is:

  • It is rebuttable. A presumption of conformity shifts the starting position in an assessment; it does not immunise. If the Commission finds that a signatory is not in fact doing what the code says, the presumption does not save it.
  • It is bounded by coverage. The presumption runs only to the extent the code covers the obligation in question. Obligations or aspects the code does not address are demonstrated the ordinary way.
  • It is time-limited by design. Both articles frame the code as the route until a harmonised standard is published. The code is scaffolding for the period before standardisation, not a permanent parallel regime.
This describes the legal mechanism, not whether adherence is the right decision for a particular organisation — that turns on model classification, existing governance and commercial factors. Not legal advice; take advice on your own facts.

Status and dates

The dates matter and they are easy to garble. Regulation (EU) 2024/1689 entered into force on 1 August 2024. The GPAI obligations in Chapter V applied from 2 August 2025 under Article 113. The Commission published the final General-Purpose AI Code of Practice in July 2025, shortly before that application date, following a multi-stakeholder drafting process run by the AI Office; the Commission maintains the text and the signatory list on its digital strategy site. Article 111(3) gives providers of models placed on the market before 2 August 2025 until 2 August 2027 to comply.

The signatory list is not static. Several major model providers signed; at least one declined publicly, and others signed with stated reservations about particular chapters. Any page that names the current signatories will be wrong within a quarter, which is why this one does not — check the Commission's published list rather than a secondary summary.

Status stated as at the time of writing. The AI Act was amended by Regulation (EU) 2026/1744, the digital omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026; its postponements concern the high-risk timetable rather than Chapter V, so the GPAI dates above are stated as they were adopted. They were not checked against the amending text. Verify the current position with the AI Office and the consolidated EUR-Lex text before relying on it.

The three chapters

The code is structured so that a provider only takes on the parts that match its obligations, which is a design detail with legal consequence: a provider without a systemic-risk model does not sign up to the safety chapter, and its presumption is correspondingly narrower.

  • Transparency. Serves Article 53(1)(a) and (b). It is built around a model documentation form — a structured set of fields covering the model, its training process, its intended uses and its energy consumption — that a signatory keeps up to date and supplies to the AI Office on request and to downstream providers as relevant. See the Article 53 technical documentation page.
  • Copyright. Serves Article 53(1)(c). Commitments around crawler conduct, respecting Article 4(3) CDSM reservations, avoiding known piracy sources, and providing a complaints route for rightsholders. See the copyright policy page.
  • Safety and security. Serves Article 55, and only signatories with systemic-risk models take it on. It is the longest chapter: a safety and security framework, risk identification and acceptance criteria, evaluation including adversarial testing, model reports to the AI Office, incident reporting, and security controls around model weights.

Not signing: the alternative route

Not signing is a lawful choice, and the Act says so twice. Article 53(4) provides that providers not adhering to an approved code of practice shall demonstrate alternative adequate means of compliance for the Commission's assessment, and Article 55(3) says the same for systemic-risk obligations. The obligation is identical either way; what changes is the evidential posture.

In practice the alternative route means constructing the evidence yourself: your own documentation schema rather than the model documentation form, your own copyright policy without a benchmark to point at, your own evaluation protocol and your own argument that it reflects the state of the art. That is more defensible than it sounds for an organisation with a mature safety function and mostly worse for one without, because the Commission assesses adequacy and you carry the burden of the argument rather than starting from a presumption.

It is not settled how demanding “alternative adequate means” will prove in practice. No assessment of a non-signatory had produced a published Commission position at the time of writing, and until one does, anyone telling you how much harder the alternative route is, is guessing.

What happens when standards arrive

The code's role is transitional. When harmonised standards under Article 40 are published in the Official Journal, conformity with them gives its own presumption, and the code's “until a harmonised standard is published” framing bites. The relevant work sits with CEN-CENELEC JTC 21 under the Commission's standardisation request, and it had not produced published harmonised standards covering the GPAI obligations at the time of writing. The general mechanism is on the AI standards page.

The practical planning point is that a provider building compliance purely as “we signed the code” is building on a foundation with a known end date. Building it as capabilities — documentation that is maintained, a copyright control that runs, evaluations that are recorded — survives the transition, because those are the same artefacts a harmonised standard will ask for.