Most confusion about the EU AI Act's general-purpose provisions comes from treating one date as the whole story. The Act stages its application: different chapters bite at different times, and the moment an obligation formally applies is not the moment a regulator acquires the power to fine you for missing it. For general-purpose AI models, those two moments are separated by roughly a year.
That gap is not a grace period in the sense of nothing being required. The obligations exist. A provider placing a general-purpose model on the Union market is expected to maintain technical documentation describing the model's design and training process, to make specified information available to downstream providers building on it, to publish a sufficiently detailed summary of the content used for training, and to operate a policy for complying with Union copyright law — including honouring reservations of rights expressed through machine-readable means.
What the Code of Practice is, and what it is not
The Code of Practice was drafted to give providers a concrete way of demonstrating that they meet obligations the Act states at a level of generality. It is voluntary. Signing it does not create a legal defence, and declining to sign it does not create a presumption of breach — but a provider who signs and follows it has a documented method to point at, while one who does neither has to construct an equivalent account from scratch under time pressure.
The practical reading for a compliance function is that the Code sets the expected standard of evidence. Whether or not an organisation signs, the questions the Code asks are the questions a regulator is likely to ask, and an organisation that cannot answer them has a problem regardless of its signature status.
Systemic risk, and the threshold that triggers it
A second tier of obligation attaches to models classified as presenting systemic risk. That classification carries additional duties around evaluation, adversarial testing, incident reporting and cybersecurity. The threshold is defined partly by compute used in training and partly by Commission designation, which means a model can enter the tier without its provider having changed anything about it.
Organisations building on third-party models should establish which tier the models they depend on sit in, and should ask their providers directly rather than inferring it. The obligations that matter to a downstream deployer are shaped by the upstream classification.
What to do with the remaining time
The work that takes longest is not writing policies. It is establishing what an organisation actually trained on, what it actually deployed, and where the documentation for both currently lives — which in most organisations of any size is a genuine research exercise rather than a filing one. Teams that started with an inventory have found the rest tractable. Teams that started with a policy document have generally found they were writing about a system they could not describe.