EU AI ACT · GPAI CODE OF PRACTICE · VOLUNTARY

You don’t sign this Code yourself. You still depend on it.

Signed by the labs that train the models. Your compliance leans on it anyway.


A reviewer with dark hair pinned back, in a charcoal blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
A signature is an undertaking. Evidence is a record
Transparency Copyright Safety & Security Model Documentation Form 10^25 FLOP

Our promise

“Nobody certifies this. We can evidence you.”

Every finding is written against the duty it answers — the Act’s where it reaches you, the Code’s where it does not. The fee is fixed at $25,000, and nothing is charged until you approve it.

Request this readiness assessment
The case file

The Code of Practice, in three chapters

The Code

Published on 10 July 2025 and facilitated by the European AI Office: a voluntary way for the labs that train general-purpose models to show how they meet Articles 53 and 55. It changes none of their duties, buys lighter paperwork and legal certainty, and most of them signed.

The Gap

You are not offered it. Deployers cannot sign, gain nothing by asking, and are dependent on it anyway: your own compliance leans on documentation the Code says a provider should hand down to you. Whether it reached you is a question about your file, not about their signature.

The Office

Our review is the independent read. We settle your role for each system, test the upstream documentation against what should have come with it, triage which systems are high-risk, and hand you the position and the gap list, every finding mapped to the duty that it answers.

The three chapters

Three chapters. Two bind every provider.

The third was written for frontier models only, and probably not for yours.

Every GPAI provider № 01
  • Transparency - the standardised Model Documentation Form
  • Capabilities, limitations, training-data information, compute
  • Including what must reach downstream providers - you
  • Copyright - an EU copyright policy, and opt-outs respected
Articles 53 & 55 · iDharma · Presented for assay
Systemic-risk models only № 02
  • Safety & Security - above 10^25 FLOP of training compute
  • Safety frameworks, evaluations, systemic-risk mitigation
  • Serious-incident reporting to the AI Office, and cybersecurity
  • A small group of frontier models — check before you ask for it
Article 55 · iDharma · Not most models
Know your role

Three positions. You are one of them.

The signatory

The lab that trained the model

A general-purpose AI model provider is who the Code is for, and who signs it. Signing undertakes to the AI Office how it will meet Articles 53 and 55: the documentation it maintains, the copyright policy it keeps, and the safety work behind a systemic-risk model. Two dozen have signed.

You

The deployer, who cannot sign it

You are almost certainly here. Deployers are not offered the Code and gain nothing by asking for it. What you have instead is your own set of Act duties - human oversight, informing the people it is used on, logging, intended purpose - and a hard dependency on documentation from upstream.

The catch

When you become a provider of it

Put your own name on a model, change what it is for, or modify it substantially, and the Act makes you its provider - and if what you now provide is itself general-purpose, the Article 53 documentation duty becomes yours. Fine-tuning a bought-in model into your product is how that happens by accident.

What most teams assume

“Our model provider signed the Code, so we’re covered.”

What the Act says

They signed for their duties. Yours never moved.

It is the most common finding we write up.

  • Who it is for
  • AI product teams
  • SaaS & platform vendors
  • Procurement & vendor risk
  • Legal & compliance
  • Banking, insurance and HR tech
Signatories & standing
A thick dark-bound instrument lying open on a desk under a low warm light, a red ribbon marker laid across the page block and a fountain pen resting beside it, the visible page carrying dense clauses and a small charted table.
01 By 2026 roughly two dozen providers had signed — Anthropic, OpenAI, Google and Microsoft among them. An undertaking about their documentation, not about your use of it.
02

Meta declined. A non-signatory still carries the Act’s obligations; what it does not carry is the Code’s agreed way of showing them.

03

xAI signed one chapter. Safety & Security only — which says nothing about the transparency documentation you would be relying on.

04

The AI Office gains its enforcement powers over general-purpose models from August 2026. Adherence is assessed there, not by an auditor.

Two vendors, two answers. Which chapters reach you turns on whose model you run and whether they signed. Ask per vendor, not per company.

The 60-second check

Three questions. Then you’ll know your position.

No email, no signup. A position, not a determination.

0 of 3

What you did -

Training one is not the only way in. Fine-tuning a bought-in model, or changing what it is for, can move you up the chain without anybody deciding to.

Whose name -

The name on it is a test, not a brand decision. Putting your own on a model you did not train is one of the routes the Act uses to make you its provider.

The file -

A model card is not a Model Documentation Form. The Transparency chapter names what should reach a downstream provider, and a public page rarely covers it.

The calendar

Four moments, and two have already passed.

The general-purpose obligations are live and were never deferred. Only the high-risk regime is moving, and it is agreed rather than adopted.

  1. Prohibited

    Since Feb 2025

    The unacceptable-risk bans have applied since February 2025, and the omnibus does not touch them.

  2. GPAI live

    Since 2 Aug 2025

    The general-purpose AI obligations came into application, and were not deferred with anything else.

  3. Enforcement

    From Aug 2026

    The AI Office gains its enforcement powers over general-purpose AI models from August 2026.

  4. High-risk

    Set for Dec 2027

    Annex III high-risk is set to be deferred here under the Digital Omnibus - agreed, not yet adopted.

The trap

Teams read “the AI Act has been delayed” and stand down. It has not: the general-purpose obligations have applied since August 2025 and the prohibitions since February 2025. What is moving is Annex III high-risk, and as of mid-2026 that was agreed rather than formally adopted.

Chapter by chapter

What the Code asks, what we ship

12 things the Code asks of a provider, and what an engagement hands you for each one. Paired, so every claim on this page can be checked against the row beside it.

Which role you hold Provider, deployer, downstream provider - or two at once
A written determination of your role for each system, so a signatory's undertaking is never mistaken for yours.
Whether you became a provider Your name on it, a new purpose, or a substantial change
An assessment of whether what you did makes you the provider - and which duties follow if it does.
Model documentation Transparency chapter - the standardised Model Documentation Form
The form you were handed read against the fields it is supposed to carry, with the thin ones named.
Capabilities and limitations Transparency chapter - what the model can and cannot do
Whether what the provider states about the model actually covers the way you are using it.
Training-data information Transparency chapter - the summary a provider must publish
The published summary checked against your own use, and the questions it leaves you exposed on.
What must reach you Transparency chapter - the downstream-provider disclosure
A list of what the Code says should have come down the chain to you, and what actually did.
Copyright policy Copyright chapter - a policy to comply with EU copyright law
Whether your provider holds one, what it says, and what your own contract does with the residue.
Rights reservations Copyright chapter - machine-readable opt-outs respected
The upstream commitment recorded, and your own exposure where your outputs are published.
Safety framework Safety & Security - systemic-risk models only
Whether the model you buy is in that group at all, and what its provider has committed to.
Model evaluations Safety & Security - evaluated before and after release
The evaluation evidence you can actually obtain, and the gap between that and what you assumed.
Incident reporting Safety & Security - serious incidents reported to the AI Office
Your own route for noticing and escalating an incident, which the upstream duty does not give you.
Cybersecurity Safety & Security - the model and its weights, upstream
The line between what the provider secures and what you do, drawn before an incident draws it.
The engagement

Somebody else’s file, independently read

From model builders to everyday deployers.

  1. Place

    Where you sit in the value chain: provider, deployer, or both at once.

  2. Read the file

    The upstream documentation you rely on, tested against what you owe.

  3. Sign off and file

    You see the draft first. Then the position, the gaps and the record - dated.

Request your assessment
An auditor in a black trouser suit and cream blouse, with dark hair in a low bun, standing against a warm pale wall and pointing into the open space alongside.
Somebody has to read it line by line.
Struck in your favour

Why buyers bring the Code to iDharma

Genuinely independent

We build, resell and operate no AI systems of our own, and take no fee tied to what we find.

We read what was signed

A signature is an undertaking. We check what was actually handed down against what it promised.

Your side of the chain

Written for a deployer, because that is who you are - not reworded provider guidance.

We do not certify, and say so

There is no certificate against this Code. Anyone offering you one is selling something else.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Position report

The whole assessment in one document: your role settled for every system you build or deploy, the Act duties that follow from each role, the upstream documentation you rely on read against what it is supposed to contain, every gap mapped to the chapter or article it belongs to, and the findings written in plain language rather than in the Act's.

Workbook

AI system register

Every system, the model behind it, your role, its tier and its owner, in a workbook your own team can keep current after we hand it over.

Ranked

Documentation gap list

What the Transparency chapter says should have reached you, what actually did, and which of the shortfalls you can do something about.

Templates

Vendor question set

The questions to put to a model provider, in their own vocabulary, so an answer can be checked rather than filed as reassurance.

HTML + PDF

Article 50 notice pack

Chatbot and synthetic-media disclosures, marked up ready to drop into the places your users actually meet them, because those duties are live.

Memo

Scope memo

Which systems were in scope, which were not, and why each call was made - the written record behind your own AI inventory.

Memo

Signatory reliance memo

What your provider's signature actually discharges, which of your duties it leaves entirely open, and what changes if they withdraw it.

Format & fee

Real numbers, upfront.

Scope
Set by the Act, not by us
Frame
The Code’s three chapters
Re-read
Annually, or on a model change - $21,000 against your known baseline

The Act fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request your assessment
EU AI Act · Readiness assessment $25,000 flat
  • Your role, determined per system
  • Upstream documentation read and gap-listed
  • High-risk classification triage
  • Article 50 notice text, ready to post
Readiness you can evidence

Four things an assessment can actually produce

Nobody can certify you against this Code — there is no body and no certificate. These four are checkable, and they are what we hand you.

Your place,
determined

Where you sit in the value chain - provider, deployer or downstream provider - and which obligations and which dates reach you rather than the ones in the headlines.

The tier,
triaged

Whether a system falls under Annex III or Annex I, against the omnibus's clarified carve-outs and its deferred timeline - and saying where the answer is arguable.

The file,
read

The upstream model documentation you rely on, checked for whether it is present, complete and sufficient for your compliance, not just the provider's.

The frame,
borrowed

The engagement run against Transparency, Copyright and Safety & Security - a regulator-recognised frame, credible even for a deployer who never signs it.

Four cards, and not one of them is a certificate.

FAQ

Plain answers

Who signs it, what it binds, and what we can evidence.

Request your assessment
Do we need to "sign" the GPAI Code of Practice?

No. The Code is signed by general-purpose AI model providers. If you buy or deploy those models you do not sign it - and cannot. What you can do is align to its structure and check that your provider held up their end.

Is the Code legally binding?

No. The EU AI Act is the law; the Code is a voluntary tool for showing compliance with it. Signing does not change a provider's underlying obligations - it buys reduced administrative burden and more legal certainty.

Our model provider signed. Are we covered?

For their duties, not yours. A signature is an undertaking about the provider's documentation and policies - it says nothing about your oversight, your logging, or your disclosures, and none of those transfer.

Have the EU AI Act deadlines been delayed?

Not the ones on this page. GPAI obligations have applied since 2 August 2025 and were not deferred. High-risk is SET to be deferred to December 2027 under the Digital Omnibus - agreed May 2026, and pending formal adoption.

Can an iDharma assessment certify EU AI Act compliance?

No, and nobody can certify you against the Code either - there is no accredited body and no certificate. What we issue is an independent readiness assessment: your position, your gaps, and a prioritised roadmap, with evidence behind each finding.

Get started

Turn a moving target into a documented position

An independent read gives you evidence you were ready - useful as the rules shift, and as buyers ask.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which AI systems you build or use, and what each decides
  2. Which model sits behind each one, and whose it is
  3. Any documentation the provider gave you
  4. Whether you fine-tuned, rebranded or repurposed it
  5. Your target readiness date, if you have one

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Regulation (EU) 2024/1689 - the AI Act
  • GPAI Code of Practice, 10 July 2025
GPAI applies
2 August 2025
Enforced from
August 2026

What it means

  • Informational only, and it reflects our understanding of the Act and the Code as of 2026 — not legal advice, and no professional relationship arises from reading it.
  • Where a scope question is arguable, our reports say so rather than the convenient thing.

Scope & limitation

  • Signatory status changes. It is checked at the engagement, not taken from here.
  • The omnibus deferrals were agreed May 2026, pending adoption — confirm with counsel.
  • Use it as a starting point for a scoping conversation, not as your final word.

A signatory changed, or something here out of date?

Tell us