Summary: The voluntary instrument through which GPAI providers demonstrate compliance with AI Act Articles 53 and 55. Three chapters — Transparency, Copyright, Safety and Security — with the third carrying ten commitments and four appendices of substance.
Sources: raw/Laws/Overview of the Code of Practice _ EU Artificial Intelligence Act.md
Last updated: 2026-07-28
Status
Under Art 55(2), providers “may rely on codes of practice… to demonstrate compliance… until a harmonised standard is published,” and the Commission may approve a code by implementing act to give it “general validity within the Union” (source: raw/AI-regulations/Regulation - EU - 2024_1689.md). Codes were due by 2 May 2025 (Art 56(9)).
Providers who neither adhere to an approved code nor comply with a harmonised standard “shall demonstrate alternative adequate means of compliance for assessment by the Commission.” In practice: adhere, or justify yourself article by article.
Transparency Chapter
Up-to-date documentation for every GPAI model distributed in the EU, “except for models that are free, open-source, and pose no systemic risk,” following a standardised Model Documentation Form covering “licensing, technical specs, use cases, datasets, compute and energy usage, and more.” Stored securely for at least ten years, available on request to the AI Office and downstream users (source: Overview of the Code of Practice…md).
Measure 1.3 requires “Ensuring quality, integrity, and security of information” — the documentation itself is an asset to protect.
Copyright Chapter
Lawful access when crawling, respect for machine-readable rights signals like robots.txt, avoidance of sites flagged for infringement, technical safeguards to minimise infringing output, ToS prohibitions, and a designated contact point for rightsholder complaints.
Safety and Security Chapter — ten commitments
| # | Commitment |
|---|---|
| 1 | Safety and Security Framework |
| 2 | Systemic risk identification |
| 3 | Systemic risk analysis |
| 4 | Systemic risk acceptance determination |
| 5 | Safety mitigations |
| 6 | Security mitigations → code-of-practice-security-mitigations |
| 7 | Safety and Security Model Reports |
| 8 | Systemic risk responsibility allocation |
| 9 | Serious incident reporting → serious-incident-reporting |
| 10 | Additional documentation and transparency |
Commitment 1 — the Framework, and its clock
Must document existing and planned processes for assessing and mitigating systemic risk, including “justified trigger points,” risk-tier criteria, “comprehensive high-level mitigation strategies corresponding to each risk category,” and — notably — “projected timelines indicating when models are anticipated to surpass the current highest risk tier, supported by detailed justification, underlying assumptions, and utilization of forecasting methodologies, expert surveys, or professional estimates.”
Timing: confirmed “within four weeks of notifying the Commission that their GPAI model meets the threshold… and at minimum two weeks prior to market launch.” Full unredacted access to the AI Office “within five business days of final confirmation” (Measure 1.4).
Review at least annually, or earlier on triggers including “serious incidents or near-misses that demonstrate materialized systemic risks” and “declining mitigation effectiveness.” Reviews test both adequacy (do the measures work) and adherence (are they followed).
The forecasting requirement is the unusual one: providers must state on the record when they expect to exceed their own top risk tier.
Commitments 2–4 — identify, analyse, accept
Identification via “inventories, scenario analysis, and consultation with internal and external experts.” Analysis via “model-independent information, model evaluations, systemic risk modelling, systemic risk estimation, and post-market monitoring.”
Commitment 4 is the gate: “Before progressing with development or deployment, signatories must evaluate whether identified risks are acceptable, applying defined risk-tier frameworks with built-in safety margins. If risks are deemed unacceptable, immediate corrective actions are required” — Measure 4.2 covers “proceeding or not proceeding based on systemic risk acceptance determination.”
This is a stop condition written into a voluntary code. Whether it functions as one depends entirely on who owns the determination — which is why Commitment 8 exists.
Commitment 5 — safety mitigations
“Filtering, continuous monitoring, refusal training, phased access controls, downstream tool safeguards, and secure deployment environments.” The model-behaviour half; Commitment 6 is the infrastructure half.
Commitment 7 — Model Reports
Required before release, covering model description and behaviour, reasons for proceeding, documentation of identification/analysis/mitigation, external reports, and material changes to the risk landscape. SMEs and small midcaps “may provide reduced detail levels.”
Commitment 8 — organisational accountability
Requires “clear responsibilities” for oversight, ownership, monitoring and assurance; “allocation of appropriate resources”; and “promotion of a healthy risk culture,” which includes protections for whistleblowers. See whistleblowing.
The four-role split (oversight / ownership / monitoring / assurance) is a three-lines-of-defence structure applied to model risk.
Commitment 10 — retention and publication
Records retained “for a minimum of ten years.” High-level summaries of frameworks and model reports “should be published when needed to reduce risks, unless the model meets specific criteria qualifying it as ‘similarly safe or safer’” — the Appendix 2 safe-reference-model mechanism, which lets a provider avoid publication by demonstrating equivalence to an already-released model.
Appendix 3 — model evaluations
Covers “rigorous model evaluations,” model elicitation, “assessing mitigation effectiveness,” “Qualified Evaluation Teams and Resources,” and “independent external model evaluations.”
This is where Art 55(1)(a)‘s “conducting and documenting adversarial testing” becomes operational. See automated attack generation for the harness side.
Assessment
The Safety and Security chapter is the most substantive AI security governance document in this corpus — more concrete than NIST’s RMF, far more concrete than the Regulation it implements. Its weaknesses are that it is voluntary, that it applies only to GPAI with systemic risk, and that its control set (Appendix 4) is oriented toward weight theft rather than the agentic and injection attack surface.