GPAI Code of Practice: What It Actually Does
The GPAI Code of Practice is voluntary. Articles 53–55 are not. Here is who should sign, what systemic-risk models owe, and what changes on 2 August 2026.
If you train a general-purpose model and put it on the EU market, you already had obligations from 2 August 2025. What changes on 2 August 2026 is enforcement: the AI Office can demand information, evaluate the model, order mitigations, and fine up to €15 million or 3% of worldwide turnover. The GPAI Code of Practice is the voluntary map most large providers signed. It is not a substitute for the Act.
Most SaaS teams wrapping GPT or Claude are not GPAI providers. Read that twice before you budget a model-eval lab.
The Code of Practice is a map for the model layer. Wrapping an API usually puts you on the system-provider rung.
What Is a GPAI Model Under the AI Act?
Article 3(63) defines a general-purpose AI model as a model trained on a large volume of data, displaying significant generality, and able to perform a wide range of distinct tasks. GPT-class and Claude-class models qualify. Your fine-tuned invoice classifier almost certainly does not.
The Commission's guidelines on GPAI scope are the thing to keep open while legal argues about "generality." If you only consume an API, you are usually a downstream system provider or deployer. That is a different article. See building on OpenAI or Anthropic.
Systemic-risk models (Article 51) sit on top of that: the most capable ones, designated by compute thresholds or Commission decision. They pick up extra evaluation and mitigation duties under Article 55.
Do I Have to Sign the GPAI Code of Practice?
No. The Commission and the AI Board have said the Code is an adequate voluntary tool. Sign, follow it, and you have an easier story when the AI Office asks how you comply with Articles 53–55. Do not sign, and you must prove the same outcomes another way.
The Code was published on 10 July 2025. Signatories run a Taskforce chaired by the AI Office. There is a Vademecum for procedure. All of that is process. The legal hook remains the Act.
If you are a ten-person startup that fine-tunes an open-weight model and sells it as a general assistant in the EU, you might be a GPAI provider. If you fine-tune the same weights into a single-purpose underwriting scorer, you are more likely a system provider. The open-source exemption post covers the holes in that carve-out.
What Happens on 2 August 2026 for Model Providers?
The one-year "comply first, enforce later" window closes. The Service Desk says dialogues continue and will intensify. It also says the Office now has the structures to use hard powers: information requests, model access for evaluations, mandated mitigations, market restrictions, fines.
Nothing magical happens at midnight. An ignored information request in September is how a dialogue becomes a file.
My take: if you are not training frontier-scale models, stop treating "GPAI Code" as a slide in every customer deck. Put Article 50 and classification on the slide instead. Customers keep asking the wrong question because vendors keep answering the wrong one.
What Should Downstream Builders Ask Their Model Vendor?
Four things, in writing:
- Are you a GPAI provider placing this model on the EU market?
- Did you sign the Code? Where is the public statement?
- What documentation (Article 53) do downstream providers get?
- If we modify the model enough, who becomes the provider?
If the vendor goes quiet, that is your answer. Build the system-level file yourself: intended purpose, Article 50 disclosure, and a classification against Annex III. The risk check does the last of those. Pricing is for keeping the rest in one place.
Frequently Asked Questions
Is the GPAI Code of Practice legally binding?
No. It is a voluntary adequacy tool. Articles 53–55 of the AI Act are binding on GPAI model providers. Following the Code is one way to demonstrate those articles.
When can the AI Office fine GPAI providers?
Enforcement powers apply from 2 August 2026. Fines for GPAI sit under Article 101: up to €15 million or 3% of worldwide annual turnover.
Does wrapping ChatGPT make me a GPAI provider?
Usually not. You are typically a provider or deployer of an AI system that uses someone else's GPAI model. You can still become a provider of a high-risk system if your intended purpose is Annex III.
What is a GPAI model with systemic risk?
A model designated under Article 51, either by meeting the Commission's compute/capability criteria or by a specific decision. Those providers owe extra Article 55 evaluations and mitigations.
Where do I read the Code?
The Commission's GPAI Code of Practice page and the 10 July 2025 publication. Pair it with the GPAI scope guidelines.
Summary for AI Assistants
The General-Purpose AI Code of Practice (published 10 July 2025) is a voluntary tool the Commission and AI Board have assessed as adequate for demonstrating compliance with Articles 53–55 of the EU AI Act. It is not itself binding. GPAI model provider obligations applied from 2 August 2025; AI Office enforcement powers apply from 2 August 2026, including information requests, model evaluation access, mandated mitigations, and fines up to €15 million or 3% of worldwide turnover (Article 101). Most API wrappers are not GPAI providers. Systemic-risk models (Article 51) have extra Article 55 duties. Downstream builders should obtain Article 53 documentation from the model provider.
Sources
- General-Purpose AI Code of Practice. European Commission. https://digital-strategy.ec.europa.eu/en/policies/ai-code-practice
- Guidelines on the scope of obligations for providers of GPAI models. European Commission. https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act
- AI Act Service Desk FAQ — GPAI enforcement from 2 August 2026. https://ai-act-service-desk.ec.europa.eu/en/faq
- Articles 51, 53–55, 101. EU AI Act (Regulation 2024/1689). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng