The Code of Practice and how GPAI is actually enforced
Lesson 5 of 5 in Transparency and General-Purpose AI: Art 50 and the GPAI Chapter.
Arts 53 and 55 state outcomes, not methods — ‘adequate cybersecurity’, ‘state-of-the-art evaluations’. In the high-risk world, harmonised standards fill that gap. For GPAI, standards were never going to arrive by August 2025, so Art 56 built a bridge: codes of practice, drawn up with industry, the AI Board, civil society and academia, facilitated by the AI Office.
The GPAI Code of Practice was published in July 2025, in three chapters that map cleanly onto the statute:
- Transparency — implements the Art 53 documentation duties, built around a model documentation form covering both Annex XI and Annex XII content.
- Copyright — implements the Art 53(1)(c) copyright policy: honouring machine-readable TDM reservations, not circumventing paywalls, handling complaints from rights holders.
- Safety and Security — for systemic-risk providers only: implements Art 55 with a safety-and-security framework, model evaluations, incident processes and weight-security measures.
Signing is voluntary. But the incentives are engineered: adherence to an adequate code is a recognised means to demonstrate compliance — authorities take it into account, supervision is lighter, and the AI Office focuses scrutiny on non-signatories, who must prove their ‘adequate alternative means’ from scratch. Not a legal safe harbour; very much a practical one. Eventually, harmonised standards are meant to supersede the code — publication in the OJ would ground a presumption of conformity. If the code proves inadequate or cannot be finalised, the Commission may impose common rules by implementing act.
Demonstrating GPAI compliance: three routes
- GPAI provider owes Arts 53/55
- Harmonised standard cited in the OJ?
None yet as of this writing — the standards route is the destination, not the present. Check current status.
- Apply the standard
Presumption of conformity for the covered duties.
- Sign the Code of Practice?
- Adhere to the Code
Recognised demonstration route: commitments in the Transparency, Copyright and (if systemic-risk) Safety & Security chapters, monitored by the AI Office.
- Adequate alternative means
Document your own measures and be ready to justify their adequacy to the AI Office — the burden of persuasion is yours.
- Compliance demonstrated (never guaranteed)
All routes remain subject to AI Office supervision and Art 101 fines: up to €15M or 3% of worldwide turnover.
Enforcement architecture, in one paragraph: the AI Office is the exclusive supervisor of GPAI providers — the one place in the Act where the Commission itself, not national authorities, holds the pen. It can demand documentation, order model evaluations by qualified external evaluators, require mitigation measures, and ultimately restrict, recall or withdraw a model. Fines under Art 101 reach €15M or 3% of worldwide annual turnover, whichever is higher. National market surveillance authorities still police the systems built on those models — a two-lane enforcement design that mirrors the model/system split running through this whole module.
The clock recap, worth committing to memory: GPAI chapter applicable 2 August 2025; Code of Practice published July 2025; models placed on the market before 2 August 2025 must comply by 2 August 2027.
Key terms: code of practice, AI Office, harmonised standards, presumption of conformity
Tool: Which Rules Apply? — Feed the wizard a model’s facts — compute, licence, modality, market date — and watch it assemble the exact obligation stack and deadlines.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.