European Union · GPAI

The EU GPAI Code of Practice.

The EU AI Act's General-Purpose AI Code of Practice gives model providers a concrete, regulator-recognized way to show they meet their obligations. It is voluntary — but its three chapters are a credible framework for any organization building, buying or deploying AI in the EU. Here's what it is, and how an audit helps.

At a glance

  • Published 10 July 2025 by the European Commission
  • Three chapters: Transparency, Copyright, Safety & Security
  • GPAI obligations have applied since 2 Aug 2025
  • Voluntary — most major providers signed; Meta declined
What it is

The standard, accurately

The GPAI Code of Practice is a voluntary tool, facilitated by the European AI Office, that lets general-purpose AI model providers demonstrate compliance with their obligations under Articles 53 and 55 of the EU AI Act. It was published on 10 July 2025 and confirmed as an adequate way to show compliance until harmonized European standards arrive.

It has three chapters. Transparency (all GPAI providers) — a standardized Model Documentation Form covering capabilities, limitations, training-data information and compute, including what must reach downstream providers. Copyright (all providers) — a policy to comply with EU copyright law and respect machine-readable rights reservations. Safety & Security — applies only to providers of GPAI models with systemic risk (training compute above 10^25 FLOP, a small group), covering safety frameworks, model evaluations, systemic-risk mitigation, incident reporting and cybersecurity.

It is voluntary and incentivized: signing doesn't change the underlying binding obligations, but gives reduced administrative burden and greater legal certainty. By 2026 roughly two dozen providers had signed (Anthropic, OpenAI, Google, Microsoft, Mistral, IBM, Amazon and others); Meta declined, and xAI signed only the Safety & Security chapter.

On timing: the AI Act entered into force August 2024; prohibited practices applied Feb 2025; GPAI obligations since 2 August 2025; AI Office enforcement powers over GPAI from August 2026. High-risk rules are set to be deferred under the "Digital Omnibus" (Annex III to December 2027) agreed in May 2026 — but that was pending formal adoption as of mid-2026, and does not roll back GPAI or prohibited-practice timing.

What it means for AI buyers

Why this lands on your desk

Most enterprises are deployers, not GPAI providers — and deployers don't sign the Code. But the Act's obligations flow downstream: if you integrate a GPAI model into your own product you can become a downstream provider with your own duties, and you depend on receiving the upstream provider's transparency documentation.

If your use case is high-risk under Annex III (HR, credit, biometrics, critical infrastructure, education), the full high-risk regime applies — now likely deferred to December 2027, pending the omnibus. Transparency duties (labeling synthetic content, disclosing chatbots under Article 50) bite for many ordinary deployments now.

Choosing a model from a Code signatory gives you more assurance the required documentation and copyright/safety practices exist upstream — a real procurement signal.

How iDharma audits map to it

Readiness you can evidence

An audit can't issue legal certification — but it can verify concrete, checkable artifacts that map to the standard.

EU AI Act readiness

Map where you sit in the value chain (provider / deployer / downstream provider) and which obligations and deadlines actually apply to you.

High-risk classification triage

Determine whether a system falls under Annex III / Annex I, factoring the omnibus's clarified carve-outs and deferred timelines.

GPAI documentation review

Verify the upstream model documentation you rely on (the Transparency / Model Documentation Form content) is present, complete and sufficient for your own compliance.

Structured around the three chapters

Run the audit against Transparency, Copyright and Safety & Security — a credible, regulator-recognized frame even for deployers who never sign the Code.

FAQ

Common questions

Do we need to "sign" the GPAI Code of Practice?

No — the Code is signed by general-purpose AI model providers. If you're an enterprise buyer or deployer, you don't sign it. An auditor helps you align with its structure, verify your upstream provider's compliance, and meet your own EU AI Act deployer obligations.

Is the Code legally binding?

No. It is a voluntary tool to demonstrate compliance with the binding EU AI Act. The Act itself is the law; signing the Code earns reduced administrative burden and greater legal certainty.

Have the EU AI Act deadlines been delayed?

GPAI obligations have applied since 2 August 2025 and were not delayed. High-risk rules are set to be deferred (Annex III to December 2027) under the Digital Omnibus agreed in May 2026 — but as of mid-2026 that was agreed, not yet formally adopted, so we present it as "set to be deferred," not settled law.

Can an iDharma audit certify EU AI Act compliance?

No — we don't issue legal certification. We assess readiness against the Code's three chapters and the Act's deployer obligations, and give you documented evidence and a prioritized roadmap.

Informational only, reflecting our understanding of the EU AI Act and GPAI Code of Practice as of 2026; not legal advice. The Digital Omnibus high-risk deferrals were agreed in May 2026 but pending formal adoption — confirm current requirements with qualified counsel.

Turn a moving target into a documented posture

An independent audit gives you evidence you were ready — useful as rules shift and as buyers ask.

Request an AI audit
See our NIST AI RMF alignment