DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

EU’s General-Purpose AI Code of Practice: What Businesses Need to Know

The EU’s voluntary General-Purpose AI Code is a compliance route for model providers, not a new law for every AI user. Learn how scope, duties and deadlines work.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU’s General-Purpose AI (GPAI) Code of Practice is a voluntary way for in-scope AI model providers to show how they comply with existing, binding obligations under the AI Act. It is not a new law, and it does not automatically apply to every business that uses AI. As of October 2026, the Commission’s GPAI enforcement powers are in application, so providers should establish whether they are in scope, which duties apply, and whether signing the Code fits their compliance approach.

What does the Code do—and who is it for?

The European Commission received the final Code on 10 July 2025. It is a voluntary compliance tool for providers of general-purpose AI models placed on the EU market. A provider may sign and implement the relevant parts of the Code to demonstrate how it meets applicable AI Act duties; signing does not replace or waive those duties. The Commission and the AI Board have confirmed the Code as an adequate voluntary tool, citing potential benefits including reduced administrative burden and greater legal certainty. The Commission’s announcement described its purpose as helping industry comply with the Act’s GPAI rules.

That distinction matters for companies deciding whether this is their issue. A business that buys or uses an AI service is not, just by doing so, necessarily a GPAI model provider. But an organization that develops a model, places one on the EU market, or modifies a model in a way that changes its provider status may have provider duties. The Commission’s guidelines on GPAI model providers address scope, provider status and placing a model on the market; the answer depends on the model and the organization’s role, not merely on whether it uses AI.

The Code was drafted by 13 independent experts and followed a multi-stakeholder process. The Commission’s Q&A, last updated 20 July 2026, reports more than 1,400 participants, over 1,600 written submissions and feedback from 40 workshops. Those are figures from the later Q&A; the Commission’s July 2025 announcement separately reported more than 1,000 stakeholders. Commission Q&A on the GPAI Code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which parts of the Code apply to which providers?

The Code has three chapters. Transparency and Copyright address obligations for GPAI model providers generally; Safety and Security is for the narrower group whose models are classified as having systemic risk.

Code chapter Who it concerns What it helps address
Transparency GPAI model providers generally A Model Documentation Form to organize information needed for sufficient transparency, including information relevant to downstream providers.
Copyright GPAI model providers generally Practical measures for putting in place a policy to comply with EU copyright law.
Safety and Security Providers of GPAI models with systemic risk Practices for assessing and managing systemic risks, including security-related measures.

The Code’s Transparency and Copyright chapters relate to Article 53 of the AI Act. Its Safety and Security chapter concerns the additional Article 55 rules for providers of systemic-risk models. The Commission’s GPAI Code policy page and Q&A describe the chapters and their relationship to the Act.

How can a business tell whether its model is in scope?

The Commission’s July 2025 guidelines describe a GPAI model as one trained using compute exceeding 1023 floating-point operations and capable of generating language (text or audio), text-to-image, or text-to-video. This is a scope criterion described alongside specified generative capabilities; it is not a shortcut for deciding every legal question about a particular model or company. The guidelines also address when a model modifier may count as a provider.

Systemic risk is a separate, narrower classification. The Commission’s Q&A says the Act currently presumes high-impact capabilities for models trained with cumulative compute greater than 1025 floating-point operations. The classification also concerns high-impact capabilities and impact on the Union market, so compute alone does not settle whether a model is systemic-risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some free and open-source models that meet transparency conditions may be exempt from certain obligations. Open-source status by itself does not establish an exemption; providers should check the conditions in the Commission’s guidelines before relying on one.

What duties apply, and when?

For providers subject to the ordinary GPAI requirements, core Article 53 duties include preparing technical documentation, giving information to downstream providers, maintaining a copyright policy, and publishing a summary of training content. Providers of models classified as systemic risk have additional duties: notifying the AI Office without delay, conducting evaluations, mitigating risks, reporting serious incidents and meeting cybersecurity requirements. The Commission’s GPAI Q&A and provider guidelines describe these requirements.

Model’s EU-market status Relevant GPAI timing
Newly placed on the EU market Provider obligations applied from 2 August 2025.
Already on the market before 2 August 2025 Relevant AI Act obligations are due by 2 August 2027.
Enforcement The Commission’s GPAI enforcement powers apply from 2 August 2026.

These dates concern GPAI obligations and models placed on the EU market; they are not general start dates for every AI Act provision or every AI system. They are set out in the Commission’s GPAI provider guidance.

How should an affected provider approach compliance?

  1. Establish the organization’s role. Use the Commission’s scope and provider guidance to assess whether the organization provides a GPAI model, including whether a modification changes its status. A company can have more than one role, for example as a model provider and a downstream system provider.
  2. Map duties to each model. Identify the Article 53 documentation, downstream information, copyright-policy and training-content-summary requirements that apply. Assess any claimed free/open-source exemption against its conditions rather than assuming one applies.
  3. Assess systemic risk separately. Determine whether the model falls within the systemic-risk rules; if it does, plan for notification to the AI Office and the additional evaluation, mitigation, incident-reporting and cybersecurity duties.
  4. Choose a compliance demonstration route. Decide whether to sign the Code and implement the relevant chapters or use another adequate approach. The Commission lists the form and signature process on its GPAI Code page; check that page for the current procedure.
  5. Track applicable dates and changes. Apply the transition dates to the model’s market status, and check official guidance for updates before relying on a particular interpretation or process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is this the same as the EU’s other AI transparency code?

No. The GPAI Code concerns model providers, model-level documentation and training-data transparency, among other provider obligations. The separate Article 50 Code of Practice on transparency of AI-generated content, published in 2026, addresses marking and labelling AI-generated or manipulated content at system level. The Commission describes the two codes as complementary, but directed at different obligations and audiences. Its GPAI Q&A explains how they interact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.