The General-Purpose AI Code of Practice — the voluntary instrument the EU AI Office published on 10 July 2025 to help providers of general-purpose AI models demonstrate compliance — has settled into its role as the default compliance pathway. It is organised into three chapters: Transparency, Copyright, and Safety and Security.
By mid-2026 the signatory base had grown to roughly two dozen organisations, including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI, Mistral AI, Aleph Alpha, Cohere and Samsung Electronics. Adherence is not all-or-nothing: xAI, for example, signed only the Safety and Security chapter. Signatories have established a Signatory Taskforce, chaired by the AI Office, to keep application of the Code coherent across providers.
The Code is voluntary, but it sits on top of obligations that are not. From 2 August 2026 the Commission can enforce the GPAI provider obligations directly and impose fines for non-compliance. For signatories, the Commission has said it will focus enforcement on monitoring adherence to the Code, and may treat a provider's commitments under the Code as a mitigating factor when setting the level of any fine — a concrete incentive to sign and to document conformance.
For deployers, the Code is a procurement lever. Asking whether a model vendor has signed, and to which chapters, is now a fast proxy for how much of the transparency, copyright and safety documentation you can expect to receive. Veritome captures GPAI provider disclosures as evidence against the relevant Article 53 and 55 obligations, so the vendor's Code posture flows straight into your own file.
Sources: European Commission, "Signatory Taskforce of the General-Purpose AI Code of Practice"; Latham & Watkins, "EU AI Act: GPAI Model Obligations in Force and Final GPAI Code of Practice in Place".
Need help with EU AI Act compliance?
Veritome automates risk classification, document generation, and compliance tracking for your AI systems.
Founders offer