General-Purpose AI Code of Practice (GPAI CoP)
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| AI Act adopted | Mar 13, 2024 | Article 56 mandates a GPAI Code of Practice |
| Multi-stakeholder drafting begins | 2024-11 | European AI Office leads process with independent experts and industry |
| GPAI obligations enter force | Aug 2, 2025 | Articles 53–55 of the AI Act become enforceable |
| Code of Practice finalized | Jul 10, 2025 | Published by European Commission ahead of GPAI enforcement date |
| Enforcement of GPAI fines | Aug 2, 2026 | European Commission can impose penalties for AI Act GPAI infringements |
Regulatory Crosswalk
Binding regulations that require the same obligations this standard addresses. Implementing this standard can help satisfy these regulatory requirements.
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
GPAI Transparency and Documentation (Article 53)
The GPAI Code mandates a public-facing Model Documentation Form for every GPAI model — a standardized disclosure covering technical specs, training data, compute, and energy use. This is the first binding-effect transparency template for foundation models globally, operationalizing an EU obligation that applies to providers worldwide.
Requirements
| Requirement | Details |
|---|---|
| Model Documentation Form | Draft and maintain a comprehensive Model Documentation Form covering technical specifications, training data characteristics, computational resources, and energy consumption |
| Downstream disclosure | Proactively provide documentation to downstream providers integrating the GPAI model into AI systems |
| Authority disclosure | Make documentation available on request to the European AI Office and national competent authorities |
| Contact publication | Publicly disclose contact information (e.g., website) for documentation requests |
| GPAI Template | Complete and publicly disclose a mandatory GPAI Template with training data details |
Penalties
| Violation | Fine |
|---|---|
| AI Act Article 53 infringement | Up to €15 million or 3% of worldwide annual turnover (whichever is higher) |
Training Data and Copyright Governance (Article 53)
All GPAI providers must implement copyright-compliant training data policies — including robots.txt compliance, mechanisms to prevent infringing outputs, and public training data disclosure. This directly affects every foundation model provider operating in or serving the EU, making EU copyright law a de facto data governance standard for global AI training pipelines.
Requirements
| Requirement | Details |
|---|---|
| Copyright compliance policy | Implement and maintain a policy for compliance with EU copyright law throughout the training data pipeline |
| Robots.txt compliance | Honor robots.txt opt-out protocols when crawling data for training |
| Infringing output prevention | Establish mechanisms to prevent generation of copyright-infringing outputs |
| Complaint mechanism | Create a complaint mechanism for rights holders regarding copyright infringements |
| Training data disclosure | Publicly disclose a summary of training data used, including data sources and characteristics |
Penalties
| Violation | Fine |
|---|---|
| AI Act Article 53 infringement | Up to €15 million or 3% of worldwide annual turnover (whichever is higher) |
Technical Documentation and Record-Keeping (Article 53)
Requirements
| Requirement | Details |
|---|---|
| Model Documentation Form maintenance | Keep the Model Documentation Form current and updated as the model evolves |
| Training records | Maintain records of training data characteristics, sources, and processing |
| Compute and energy records | Document computational resources and energy consumption used in training |
| Confidential disclosure | Provide documentation to AI Office under confidentiality protections when requested |
Penalties
| Violation | Fine |
|---|---|
| AI Act Article 53 infringement | Up to €15 million or 3% of worldwide annual turnover (whichever is higher) |
Systemic Risk Assessment (Article 55)
Applies only to the most powerful GPAI models (above 10²⁵ FLOPs training compute, or Commission-designated). The Safety and Security chapter operationalizes the most demanding tier of EU AI regulation — requiring state-of-the-art adversarial testing, red-teaming, and cybersecurity measures for models that pose systemic risks to the EU.
Requirements
| Requirement | Details |
|---|---|
| Systemic risk assessment | Assess and mitigate systemic risks arising from the GPAI model, including risks to health, safety, fundamental rights, society, and democracy |
| Adversarial testing | Conduct adversarial testing and red-teaming to identify dangerous capabilities |
| Cybersecurity measures | Implement cybersecurity controls appropriate to the model's risk level |
| Safety practices | Apply state-of-the-art safety practices for high-capability model development and deployment |
| Ongoing monitoring | Continuously monitor for emerging systemic risks post-deployment |
Penalties
| Violation | Fine |
|---|---|
| AI Act Article 55 infringement | Up to €15 million or 3% of worldwide annual turnover (whichever is higher) |
Cite this regulation
Permalink: https://everyailaw.com/regulation/eu-gpai-code-of-practice/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “General-Purpose AI Code of Practice (GPAI CoP)”, EveryAILaw.com, Mar 26, 2026. https://everyailaw.com/regulation/eu-gpai-code-of-practice/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.