EU AI Act General-Purpose AI Codes of Practice Move Toward Final Form
The European AI Office has published updated drafts of the codes of practice that will govern general-purpose AI models under the EU AI Act, with provisions covering transparency, copyright and systemic-risk evaluation.
Illustrative image. Cedar S. Insights uses editorial stock photography; images do not depict specific events described in articles.
The European AI Office has released updated drafts of the codes of practice for general-purpose AI models under the EU AI Act. The codes are intended to provide practical guidance on how providers of GPAI models can comply with the Act's requirements, particularly for models that may pose systemic risk.
The drafts cover four areas: transparency and copyright-related rules, which apply to all GPAI model providers; and safety and security measures, which apply to providers of models designated as posing systemic risk based on training compute thresholds or other criteria.
On transparency, the codes require providers to publish technical documentation, maintain information about training data and make available a summary of content used for training. The copyright provisions require providers to implement policies for complying with EU copyright law, including opt-out mechanisms for rights holders.
For systemic-risk models, the codes describe requirements for adversarial testing, incident reporting, cybersecurity measures and post-market monitoring. Providers must also conduct model evaluations before and after significant updates.
The codes are being developed through a multi-stakeholder process involving model providers, civil society and academic experts. Compliance with an approved code of practice will create a presumption of conformity with the relevant Act requirements, though providers may also demonstrate compliance through other means.
The codes of practice are not yet final. The drafts are subject to further revision before adoption. Organisations building on GPAI models should monitor the process, but the final obligations may differ from the current drafts.
Why It Matters
The GPAI codes of practice will set the practical compliance baseline for frontier model providers operating in the EU. The systemic-risk provisions are particularly significant because they apply to the most capable models and include requirements for adversarial testing and incident reporting that go beyond what most providers currently publish. How the European AI Office interprets and enforces these requirements will shape the regulatory environment for AI development across Europe.
Primary Sources
Our sourcing: Cedar S. Insights provides source-led editorial analysis. Reported company, institutional and regulatory claims are attributed to their original sources unless stated otherwise.
Corrections: If a material factual error is identified, Cedar S. Insights will update the relevant article and preserve the distinction between the corrected statement and supporting evidence.
Topics