As of August 2, 2025, any general-purpose AI model newly placed on the EU market has to meet the AI Act's transparency, copyright, and (for the most capable systems) safety obligations under Article 53 — models already on the market before that date get until August 2, 2027 to catch up, according to the European Commission's own summary of the rules. Most large developers are meeting those obligations through a voluntary industry tool called the General-Purpose AI Code of Practice, published July 10, 2025.
The code isn't law. It's a compliance shortcut. Sign it, follow its commitments, and regulators treat that as evidence you've met the Act's requirements — without it, a company has to prove compliance some other, less-defined way, per the Commission's page on the code's contents. That's the trade a couple dozen AI labs made last summer, and it's why the code's three chapters are worth understanding even if you never touch enterprise compliance paperwork yourself.
What is the GPAI Code of Practice, exactly?
It's a document drafted with the AI Office and endorsed by the European Commission and the AI Board as an adequate way to demonstrate compliance with the AI Act's "legal obligations on safety, transparency and copyright of general-purpose AI models," according to the Commission's page on the code's contents. It applies to any model trained to perform a wide range of tasks — the Act's definition of "general-purpose" — rather than to a single narrow product.
Signing is optional. A provider can instead try to demonstrate compliance directly against the Act's text, but the Commission and AI Office built the code specifically to make that unnecessary, offering what the same page calls "reduced administrative burden and greater legal certainty" for signatories.
What do the three chapters actually cover?
The Transparency chapter centers on a Model Documentation Form: a standard template providers fill out so the information the Act requires — about training, capabilities, and limitations — exists in one comparable format across companies, per the Commission's page on the code's contents.
The Copyright chapter asks signatories to adopt a policy for complying with EU copyright law, including how they handle rights holders' opt-out reservations on text and data mining. The Safety and Security chapter is narrower: it lays out state-of-the-art risk-management practices, but it only binds providers of the small set of models the Act classifies as carrying "systemic risk" under Article 55 — the largest, most capable systems, not every GPAI model on the market.
Which AI companies actually signed it, and who didn't?
Over 20 organizations signed at least part of the code, including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI, Aleph Alpha, Cohere, and Black Forest Labs, per the Commission's page on the code's contents. xAI signed only the Safety and Security chapter, not the full document. Meta declined to sign at all, a holdout TechCrunch reported in its August 5, 2025 explainer of the AI Act as the clearest split among major labs — "signing does not equal a full-on endorsement," the outlet noted, since several signatories paired their commitment with public reservations about specific provisions.
Declining to sign doesn't mean walking away from the underlying law. The Act's GPAI obligations still apply to every qualifying model regardless of who signs the code; a non-signatory just has to show compliance a different way, and answers to the AI Office directly if it can't.
What happens to companies that don't comply, signed or not?
The AI Act's penalty structure is tiered by violation type. Breaches of the Act's outright-prohibited AI practices carry fines up to €35 million or 7% of a company's total worldwide annual turnover, whichever is higher; violations specific to GPAI-provider obligations top out lower, at up to €15 million or 3% of turnover, according to TechCrunch's August 2025 explainer of the Act's structure.
Enforcement of the AI Act's rules is a live process rather than a settled one. A Signatory Taskforce that most code signatories have joined held its first meeting on January 30, 2026, and the AI Office has been running compliance assessments and engaging directly with providers since, per the Commission's page on the taskforce. Broader AI Act enforcement authority took effect in August 2026, per the same page — which is why scrutiny of how labs are actually implementing their commitments, rather than just whether they signed, is the phase regulators are in right now.
What does any of this change at your desk?
Not much day to day — the code governs how model makers document and disclose, not what a chat interface looks like. But it's the reason vendor model cards and usage policies have gotten more detailed over the past year, and why some providers now publish clearer statements on what training data they used and how they handle copyright opt-outs. If a tool you rely on links to a "model documentation" or "transparency report" page, that disclosure very likely traces back to this code rather than to the vendor's own initiative.
It's also a reasonable proxy for how seriously a vendor treats EU obligations generally: a company that signed the full code, kept its taskforce seat, and publishes its documentation form is choosing the more scrutinized path over the more opaque one.
What the sources don't settle
Neither the Commission's pages nor TechCrunch's reporting name every individual signatory — the full list sits in a separate taskforce document the Commission links to but that wasn't reviewed for this piece — and none of the sourced material confirms any fine actually issued against a named company under the GPAI provisions as of this writing. Treat "who signed" and "who's been fined" as two separate, unequally documented questions.
FAQ
- Is the Code of Practice legally binding? No. It's voluntary, but signing it is the recognized shortcut to demonstrating compliance with the AI Act's binding GPAI rules, per the European Commission.
- Does refusing to sign mean a company is breaking the law? No. The Act's obligations apply either way; a non-signatory has to demonstrate compliance through other means rather than through the code's presumption.
- When do the GPAI rules apply to a given model? Since August 2, 2025 for models newly placed on the market; providers of models already on the market before that date have until August 2, 2027.
- Does the Safety and Security chapter apply to every AI model? No — only to the subset the Act classifies as carrying systemic risk under Article 55, typically the largest frontier-scale models.
For a related business news perspective, read Is AI actually taking entry-level jobs? Here's what the data says.
For more context, read How to set up a passkey and stop relying on passwords.
