Published on 10 July 2025 and facilitated by the European AI Office: a voluntary way for the labs that train general-purpose models to show how they meet Articles 53 and 55. It changes none of their duties, buys lighter paperwork and legal certainty, and most of them signed.
You don’t sign this Code yourself. You still depend on it.
Signed by the labs that train the models. Your compliance leans on it anyway.
Our promise
“Nobody certifies this. We can evidence you.”
Every finding is written against the duty it answers — the Act’s where it reaches you, the Code’s where it does not. The fee is fixed at $25,000, and nothing is charged until you approve it.
Request this readiness assessmentThe Code of Practice, in three chapters
You are not offered it. Deployers cannot sign, gain nothing by asking, and are dependent on it anyway: your own compliance leans on documentation the Code says a provider should hand down to you. Whether it reached you is a question about your file, not about their signature.
Our review is the independent read. We settle your role for each system, test the upstream documentation against what should have come with it, triage which systems are high-risk, and hand you the position and the gap list, every finding mapped to the duty that it answers.
Three chapters. Two bind every provider.
The third was written for frontier models only, and probably not for yours.
- Transparency - the standardised Model Documentation Form
- Capabilities, limitations, training-data information, compute
- Including what must reach downstream providers - you
- Copyright - an EU copyright policy, and opt-outs respected
- Safety & Security - above 10^25 FLOP of training compute
- Safety frameworks, evaluations, systemic-risk mitigation
- Serious-incident reporting to the AI Office, and cybersecurity
- A small group of frontier models — check before you ask for it
Three positions. You are one of them.
The lab that trained the model
A general-purpose AI model provider is who the Code is for, and who signs it. Signing undertakes to the AI Office how it will meet Articles 53 and 55: the documentation it maintains, the copyright policy it keeps, and the safety work behind a systemic-risk model. Two dozen have signed.
The deployer, who cannot sign it
You are almost certainly here. Deployers are not offered the Code and gain nothing by asking for it. What you have instead is your own set of Act duties - human oversight, informing the people it is used on, logging, intended purpose - and a hard dependency on documentation from upstream.
When you become a provider of it
Put your own name on a model, change what it is for, or modify it substantially, and the Act makes you its provider - and if what you now provide is itself general-purpose, the Article 53 documentation duty becomes yours. Fine-tuning a bought-in model into your product is how that happens by accident.
“Our model provider signed the Code, so we’re covered.”
They signed for their duties. Yours never moved.
It is the most common finding we write up.
- Who it is for
- AI product teams
- SaaS & platform vendors
- Procurement & vendor risk
- Legal & compliance
- Banking, insurance and HR tech
Meta declined. A non-signatory still carries the Act’s obligations; what it does not carry is the Code’s agreed way of showing them.
xAI signed one chapter. Safety & Security only — which says nothing about the transparency documentation you would be relying on.
The AI Office gains its enforcement powers over general-purpose models from August 2026. Adherence is assessed there, not by an auditor.
Two vendors, two answers. Which chapters reach you turns on whose model you run and whether they signed. Ask per vendor, not per company.
Three questions. Then you’ll know your position.
No email, no signup. A position, not a determination.
Where you stand
Four moments, and two have already passed.
The general-purpose obligations are live and were never deferred. Only the high-risk regime is moving, and it is agreed rather than adopted.
-
Prohibited
Since Feb 2025The unacceptable-risk bans have applied since February 2025, and the omnibus does not touch them.
-
GPAI live
Since 2 Aug 2025The general-purpose AI obligations came into application, and were not deferred with anything else.
-
Enforcement
From Aug 2026The AI Office gains its enforcement powers over general-purpose AI models from August 2026.
-
High-risk
Set for Dec 2027Annex III high-risk is set to be deferred here under the Digital Omnibus - agreed, not yet adopted.
Teams read “the AI Act has been delayed” and stand down. It has not: the general-purpose obligations have applied since August 2025 and the prohibitions since February 2025. What is moving is Annex III high-risk, and as of mid-2026 that was agreed rather than formally adopted.
What the Code asks, what we ship
12 things the Code asks of a provider, and what an engagement hands you for each one. Paired, so every claim on this page can be checked against the row beside it.
- Which role you hold Provider, deployer, downstream provider - or two at once
- A written determination of your role for each system, so a signatory's undertaking is never mistaken for yours.
- Whether you became a provider Your name on it, a new purpose, or a substantial change
- An assessment of whether what you did makes you the provider - and which duties follow if it does.
- Model documentation Transparency chapter - the standardised Model Documentation Form
- The form you were handed read against the fields it is supposed to carry, with the thin ones named.
- Capabilities and limitations Transparency chapter - what the model can and cannot do
- Whether what the provider states about the model actually covers the way you are using it.
- Training-data information Transparency chapter - the summary a provider must publish
- The published summary checked against your own use, and the questions it leaves you exposed on.
- What must reach you Transparency chapter - the downstream-provider disclosure
- A list of what the Code says should have come down the chain to you, and what actually did.
- Copyright policy Copyright chapter - a policy to comply with EU copyright law
- Whether your provider holds one, what it says, and what your own contract does with the residue.
- Rights reservations Copyright chapter - machine-readable opt-outs respected
- The upstream commitment recorded, and your own exposure where your outputs are published.
- Safety framework Safety & Security - systemic-risk models only
- Whether the model you buy is in that group at all, and what its provider has committed to.
- Model evaluations Safety & Security - evaluated before and after release
- The evaluation evidence you can actually obtain, and the gap between that and what you assumed.
- Incident reporting Safety & Security - serious incidents reported to the AI Office
- Your own route for noticing and escalating an incident, which the upstream duty does not give you.
- Cybersecurity Safety & Security - the model and its weights, upstream
- The line between what the provider secures and what you do, drawn before an incident draws it.
Somebody else’s file, independently read
From model builders to everyday deployers.
-
Place
Where you sit in the value chain: provider, deployer, or both at once.
-
Read the file
The upstream documentation you rely on, tested against what you owe.
-
Sign off and file
You see the draft first. Then the position, the gaps and the record - dated.
Why buyers bring the Code to iDharma
Genuinely independent
We build, resell and operate no AI systems of our own, and take no fee tied to what we find.
We read what was signed
A signature is an undertaking. We check what was actually handed down against what it promised.
Your side of the chain
Written for a deployer, because that is who you are - not reworded provider guidance.
We do not certify, and say so
There is no certificate against this Code. Anyone offering you one is selling something else.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Position report
The whole assessment in one document: your role settled for every system you build or deploy, the Act duties that follow from each role, the upstream documentation you rely on read against what it is supposed to contain, every gap mapped to the chapter or article it belongs to, and the findings written in plain language rather than in the Act's.
AI system register
Every system, the model behind it, your role, its tier and its owner, in a workbook your own team can keep current after we hand it over.
Documentation gap list
What the Transparency chapter says should have reached you, what actually did, and which of the shortfalls you can do something about.
Vendor question set
The questions to put to a model provider, in their own vocabulary, so an answer can be checked rather than filed as reassurance.
Article 50 notice pack
Chatbot and synthetic-media disclosures, marked up ready to drop into the places your users actually meet them, because those duties are live.
Scope memo
Which systems were in scope, which were not, and why each call was made - the written record behind your own AI inventory.
Signatory reliance memo
What your provider's signature actually discharges, which of your duties it leaves entirely open, and what changes if they withdraw it.
Real numbers, upfront.
- Scope
- Set by the Act, not by us
- Frame
- The Code’s three chapters
- Re-read
- Annually, or on a model change - $21,000 against your known baseline
The Act fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request your assessment- Your role, determined per system
- Upstream documentation read and gap-listed
- High-risk classification triage
- Article 50 notice text, ready to post
Four things an assessment can actually produce
Nobody can certify you against this Code — there is no body and no certificate. These four are checkable, and they are what we hand you.
Your place,
determined
Where you sit in the value chain - provider, deployer or downstream provider - and which obligations and which dates reach you rather than the ones in the headlines.
The tier,
triaged
Whether a system falls under Annex III or Annex I, against the omnibus's clarified carve-outs and its deferred timeline - and saying where the answer is arguable.
The file,
read
The upstream model documentation you rely on, checked for whether it is present, complete and sufficient for your compliance, not just the provider's.
The frame,
borrowed
The engagement run against Transparency, Copyright and Safety & Security - a regulator-recognised frame, credible even for a deployer who never signs it.
Four cards, and not one of them is a certificate.
Do we need to "sign" the GPAI Code of Practice?
No. The Code is signed by general-purpose AI model providers. If you buy or deploy those models you do not sign it - and cannot. What you can do is align to its structure and check that your provider held up their end.
Is the Code legally binding?
No. The EU AI Act is the law; the Code is a voluntary tool for showing compliance with it. Signing does not change a provider's underlying obligations - it buys reduced administrative burden and more legal certainty.
Our model provider signed. Are we covered?
For their duties, not yours. A signature is an undertaking about the provider's documentation and policies - it says nothing about your oversight, your logging, or your disclosures, and none of those transfer.
Have the EU AI Act deadlines been delayed?
Not the ones on this page. GPAI obligations have applied since 2 August 2025 and were not deferred. High-risk is SET to be deferred to December 2027 under the Digital Omnibus - agreed May 2026, and pending formal adoption.
Can an iDharma assessment certify EU AI Act compliance?
No, and nobody can certify you against the Code either - there is no accredited body and no certificate. What we issue is an independent readiness assessment: your position, your gaps, and a prioritised roadmap, with evidence behind each finding.
Turn a moving target into a documented position
An independent read gives you evidence you were ready - useful as the rules shift, and as buyers ask.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which AI systems you build or use, and what each decides
- Which model sits behind each one, and whose it is
- Any documentation the provider gave you
- Whether you fine-tuned, rebranded or repurposed it
- Your target readiness date, if you have one
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Regulation (EU) 2024/1689 - the AI Act
- GPAI Code of Practice, 10 July 2025
- GPAI applies
- 2 August 2025
- Enforced from
- August 2026
What it means
- Informational only, and it reflects our understanding of the Act and the Code as of 2026 — not legal advice, and no professional relationship arises from reading it.
- Where a scope question is arguable, our reports say so rather than the convenient thing.
Scope & limitation
- Signatory status changes. It is checked at the engagement, not taken from here.
- The omnibus deferrals were agreed May 2026, pending adoption — confirm with counsel.
- Use it as a starting point for a scoping conversation, not as your final word.
A signatory changed, or something here out of date?
Tell usFrom Insights
Then what do you build?
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.