Archive context: an implementation instrument
This is a retrospective archive analysis, not a new announcement. The EU’s General-Purpose AI, or GPAI, Code of Practice was published on 10 July 2025. It was presented as a voluntary tool, prepared by independent experts through a multi-stakeholder process, to help industry comply with obligations for providers of general-purpose AI models. [2]
Its timing explains its importance. AI Act obligations for GPAI-model providers applied from 2 August 2025. [3, 4] The Code therefore sat between legislation and execution. It translated high-level requirements into a route for demonstrating compliance: documentation had to be maintained, copyright commitments had to become working policies, and advanced-model risk controls had to connect to evaluation, incident handling and cybersecurity.
The essential distinction is straightforward. The AI Act created the binding legal baseline. The Code was a voluntary means of showing how relevant obligations could be met. The Commission’s Q&A explicitly said that the Code did not impose obligations beyond the Act. [3, 4] It was neither a replacement for the Act nor a separate legal regime.
“Voluntary” consequently needs careful reading. A provider could choose whether to sign and use this route. That choice did not make applicable statutory duties optional. Official material says providers may demonstrate compliance through the assessed Code or through alternative adequate means. The practical consequence is evidential, rather than deregulatory: non-signatories still needed a credible way to substantiate compliance with the underlying duties.
What the final Code covered
The final document had three separately authored chapters: Transparency, Copyright, and Safety and Security. [2] This structure reflected a regulatory distinction between obligations applying to GPAI providers generally and extra duties applying to providers of models with systemic risk.
Transparency and Copyright addressed all providers of GPAI models. The underlying framework required technical documentation for authorities and downstream providers, a policy to comply with Union copyright law, and a public summary of training content. [3] The Code’s function was practical: it offered measures and an organised compliance approach. It did not convert every implementation choice into a legal safe harbour.
That is especially relevant along the AI value chain. A downstream organisation integrating a foundation model needs usable information, not simply a statement that a provider follows a code. The Commission’s materials describe documentation intended to help downstream providers understand capabilities and limitations and fulfil their own obligations. In operational terms, transparency includes technical handover: intended tasks, specifications, integration conditions, limits and relevant information about training and testing must be available in a form that supports decisions.
The Copyright chapter concerns another implementation challenge. A policy can establish governance for identifying and respecting rights reservations, but policy existence is not identical to proof that every training-data decision is lawful. The source material establishes the requirement for a policy and a training-content summary; it does not settle every question of provenance, licensing or legal liability. Buyers and providers should preserve that boundary between documented process and legal conclusion.
Why Safety and Security had narrower scope
Safety and Security was relevant only to the limited number of providers of the most advanced models subject to systemic-risk obligations. [2] It was not merely an intensified transparency chapter. It represented a distinct risk-management layer for models considered capable of large-scale harm or equivalent market impact.
For systemic-risk GPAI models, Commission material identifies assessment and mitigation of systemic risks, model evaluation, serious-incident tracking and reporting, and adequate cybersecurity for the model and its physical infrastructure. [3] Those elements link technical testing with organisational accountability. Evaluation without an incident pathway is incomplete operationally; so is protecting model assets while neglecting the infrastructure on which they depend. That is a practical interpretation of the listed duties, not a claim that any particular provider’s controls succeed.
The Commission’s interpretative materials also use training-compute indicators. They describe an indicative GPAI criterion above 10^23 FLOP for specified generative capabilities, while 10^25 FLOP is the threshold at which the Act presumes high-impact capabilities relevant to systemic-risk status. These are regulatory indicators, not universal measures of harm. The material also says models below an indicator can still qualify where they display sufficient generality, and a provider meeting the systemic-risk threshold may present arguments for Commission assessment.
The sensible operational conclusion is restrained: compute can trigger governance attention early in a development programme, but it cannot replace evidence about capabilities, reach, scalability, misuse routes or actual effects. Thresholds help determine scrutiny; they do not provide a complete theory of risk.
Voluntary adherence is not a safe harbour
The Code’s stated institutional value was predictability. The Commission and AI Board confirmed it as an adequate voluntary tool, and official materials say signatories can demonstrate compliance by adhering to it, with reduced administrative burden and greater legal certainty compared with other methods. This is an official account of the intended compliance route. It is not independent evidence that a signatory’s model is safe, appropriate for every use, or compliant in every circumstance.
For procurers and downstream providers, that difference matters. A signature may be relevant evidence, but it should not end due diligence. It does not by itself show that documentation is current, that stated limits fit a deployment, that evaluations cover the intended context, or that incident and cybersecurity processes function effectively. Those are questions to test with current artefacts and accountable contacts.
The same reasoning applies to providers that did not sign. They were not automatically outside the regime. Their task was to establish that alternative means adequately addressed applicable duties. The Code could thus influence market expectations beyond its signatories without eliminating alternative compliance demonstrations.
Open-source status also requires precision. Commission material describes conditional documentation exemptions for qualifying free and open-source releases, but says the exception does not apply to GPAI models with systemic risk. It also states that copyright-policy and training-summary obligations remain applicable. “Open” was therefore not a blanket waiver.
A contested compromise, not a settled verdict
Official sources describe broad participation and an adequate compliance instrument. The Ada Lovelace Institute offered a different kind of evidence: an independent policy assessment. It welcomed the preservation of public-transparency and external-assessment mechanisms, but argued that the final version narrowed the range of risks and left providers considerable latitude regarding external risk assessments and risk acceptance. [6]
These accounts should not be collapsed into one conclusion. Commission materials explain the framework, its legal context and intended operation. The Institute statement critiques the adequacy of safeguards and process. Neither source capture supplies an independent outcome evaluation of the Code’s effects in deployment.
The continuing governance question is whether a provider-facing demonstration framework creates sufficient independent challenge when much of the technical information remains with providers. The Code was designed for periodic review, and official material says the AI Office will review it at least every two years. Review is a mechanism, not proof of results. Its value depends on evidence, participation and whether revisions address implementation experience.
Practical implication: request evidence, not status
For organisations buying or integrating GPAI, ask whether the provider adheres to the Code—but do not stop there. Request current model documentation, declared limitations, integration requirements, applicable training-content disclosures, copyright-policy information, evaluation material relevant to the proposed use, incident contacts and clearly assigned security responsibilities. Map each item to the deployment, affected people and the organisation’s own duties.
For model providers, make compliance artefacts operational. Maintain versioned lifecycle documentation. Connect development planning to escalation where systemic-risk indicators may be relevant. Retain evaluation and adversarial-testing records. Link incident reporting to security operations. State clearly whether Code adherence or alternative adequate means is being used to demonstrate compliance.
The 2025 Code mattered because it made a route from broad EU GPAI duties to operational evidence more legible. Its voluntary character made the route elective. It did not make the binding legal baseline elective.