Policy & Regulation Policy Brief High risk European Union

EU AI Act GPAI Obligations Now in Force — What the Voluntary Code of Practice Means Before Enforcement Begins

The obligations on general-purpose model providers have applied since August 2025. The enforcement powers behind them arrive later. Understanding that gap is most of what a compliance team needs to know this year.

Executive summary

The EU AI Act separates the date an obligation applies from the date a regulator can penalise a failure to meet it. General-purpose AI provisions sit in that gap. Providers are already required to maintain technical documentation, publish a training-data summary and operate a copyright policy; the Commission's formal enforcement powers over them begin later. The Code of Practice is the route through the gap, and signing it is a signal about method rather than a safe harbour.

Editorial note. This piece was written to give the section structure before launch. The subject analysis stands, but the specific development in the headline has not yet been verified against the primary document by this desk — the source is linked at the foot of the article. An editor should confirm it and rewrite the framing before this runs as reporting.

Most confusion about the EU AI Act's general-purpose provisions comes from treating one date as the whole story. The Act stages its application: different chapters bite at different times, and the moment an obligation formally applies is not the moment a regulator acquires the power to fine you for missing it. For general-purpose AI models, those two moments are separated by roughly a year.

That gap is not a grace period in the sense of nothing being required. The obligations exist. A provider placing a general-purpose model on the Union market is expected to maintain technical documentation describing the model's design and training process, to make specified information available to downstream providers building on it, to publish a sufficiently detailed summary of the content used for training, and to operate a policy for complying with Union copyright law — including honouring reservations of rights expressed through machine-readable means.

What the Code of Practice is, and what it is not

The Code of Practice was drafted to give providers a concrete way of demonstrating that they meet obligations the Act states at a level of generality. It is voluntary. Signing it does not create a legal defence, and declining to sign it does not create a presumption of breach — but a provider who signs and follows it has a documented method to point at, while one who does neither has to construct an equivalent account from scratch under time pressure.

The practical reading for a compliance function is that the Code sets the expected standard of evidence. Whether or not an organisation signs, the questions the Code asks are the questions a regulator is likely to ask, and an organisation that cannot answer them has a problem regardless of its signature status.

Systemic risk, and the threshold that triggers it

A second tier of obligation attaches to models classified as presenting systemic risk. That classification carries additional duties around evaluation, adversarial testing, incident reporting and cybersecurity. The threshold is defined partly by compute used in training and partly by Commission designation, which means a model can enter the tier without its provider having changed anything about it.

Organisations building on third-party models should establish which tier the models they depend on sit in, and should ask their providers directly rather than inferring it. The obligations that matter to a downstream deployer are shaped by the upstream classification.

What to do with the remaining time

The work that takes longest is not writing policies. It is establishing what an organisation actually trained on, what it actually deployed, and where the documentation for both currently lives — which in most organisations of any size is a genuine research exercise rather than a filing one. Teams that started with an inventory have found the rest tractable. Teams that started with a policy document have generally found they were writing about a system they could not describe.

References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission. AI Act — regulatory framework for artificial intelligence. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Source for the development reported here: neuralwatch.org

Cite this

Administrator (2026, May 23). EU AI Act GPAI Obligations Now in Force — What the Voluntary Code of Practice Means Before Enforcement Begins. AI News Report. https://www.ainewsreport.org.njangi.app/blog/eu-ai-act-gpai-obligations-in-force