Technische GIDS

The EU General-Purpose AI Code of Practice

The EU General-Purpose AI Code of Practice is a voluntary tool published in July 2025 to help GPAI providers demonstrate how they meet AI Act obligations.

  • 3 minuten lezen
  • Laatst bijgewerkt
Op deze pagina3 minuten lezen
  1. Overzicht
  2. Diepe duik
  3. Strategische impact
  4. The Future of The EU General-Purpose AI Code of Practice
  5. Implementatie in de echte wereld
  6. Risico's en vangrails
  7. Implementatie routekaart
  8. Blijf verkennen
  9. Veelgestelde vragen

Overzicht

It has transparency, copyright, and systemic-risk safety and security chapters; providers may instead show compliance through other adequate means or harmonised standards.

Diepe duik

Article 56 of the EU AI Act encourages the AI Office to facilitate codes of practice that support proper application of the Regulation. The General-Purpose AI Code of Practice was published on July 10, 2025, after independent experts and stakeholders developed its text. It has three chapters: Transparency and Copyright for GPAI providers generally, and Safety and Security for providers of models with systemic risk. The Commission’s current page lists signatories and states that the code is an adequate voluntary tool. The code translates duties into practical documentation and processes. Its Transparency chapter supports information providers must keep or give downstream developers, while the Copyright chapter supports the required policy for complying with EU copyright law and rights reservations. The Safety and Security chapter offers practices for systemic-risk evaluation, assessment, mitigation, incident handling, and cybersecurity. It is not a general AI-system code and does not replace Article 53 or Article 55. Signing is voluntary. Under Articles 53(4) and 55(2), providers may rely on an approved code to demonstrate compliance until harmonised standards are published. A provider that does not adhere to an approved code or applicable standard must demonstrate alternative adequate means for Commission assessment. Following the code is therefore a route to show compliance, not a product certificate, blanket authorization, or immunity from enforcement. Regulation (EU) 2026/1744 amended Article 56 to require the Commission and the AI Board to monitor codes and assess whether they adequately cover the GPAI obligations, with public assessment. The current Commission page reports its status through July 31, 2026. Providers should verify the latest approved version, signature status, and standards when planning compliance. This is an informational overview, not legal advice.

Strategische impact

Kosten en budget

Architectuurbeslissingen bepalen jarenlang de prestaties en bedrijfskosten.

Duidelijkere beslissingen

Technisch onderwijs helpt teams bij het kiezen van de juiste stapel, niet alleen de nieuwste.

Kwaliteitscontrole

Betere technische keuzes verminderen het aantal betrouwbaarheidsincidenten in de productie.

The Future of The EU General-Purpose AI Code of Practice

The Code of Practice may be updated as standards and implementation evidence develop. Regulation (EU) 2026/1744 makes adequacy review and ongoing monitoring explicit, so provider reliance should track the Commission’s current assessment. Providers can prepare an alternative compliance case if they do not sign or if a chapter fails to cover a specific duty. Check the current AI Office page before each major compliance review. Monitor any assessment published after the Commission’s latest review. Check the current Code before renewal.

Implementatie in de echte wereld

A provider signs the Transparency and Copyright chapters and uses the model documentation form to organize Article 53 evidence.

A systemic-risk provider compares its safety framework and incident process with the Safety and Security chapter before deciding whether to sign.

A provider that does not sign builds an alternative-compliance record because the Act still applies.

A compliance lead checks Commission updates on code adequacy, signatories, and harmonised standards rather than treating a past signature as permanent approval.

Risico's en vangrails

  • Het optimaliseren van één benchmark kan bredere systeemzwakheden verbergen.

  • Infrastructuur- en onderhoudskosten worden vaak onderschat.

  • De lacunes op het gebied van beveiliging en waarneembaarheid kunnen groter worden naarmate systemen complexer worden.

Implementatie routekaart

  1. Definieer latentie-, kwaliteits- en kostendoelen vóór implementatie.

  2. Benchmark onder realistische belasting- en gegevensomstandigheden.

  3. Instrumentbewaking op fouten, drift en gebruikersimpact.

  4. Bereid rollback- en incidentresponspaden voor voordat u gaat schalen.

Blijf verkennen

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the The EU General-Purpose AI Code of Practice quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Quiz starten

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Veelgestelde vragen

What is The EU General-Purpose AI Code of Practice?

The EU General-Purpose AI Code of Practice is a voluntary tool published in July 2025 to help GPAI providers demonstrate how they meet AI Act obligations. It has transparency, copyright, and systemic-risk safety and security chapters; providers may instead show compliance through other adequate means or harmonised standards.

When was the General-Purpose AI Code of Practice published?

The Commission states that the final GPAI Code of Practice was published on July 10, 2025.

Which chapters are in the GPAI Code of Practice?

The Code has Transparency and Copyright chapters and a Safety and Security chapter for systemic-risk models.

Who is the Safety and Security chapter relevant to?

The Commission says the Safety and Security chapter concerns the additional obligations for systemic-risk GPAI providers.

Which statement describes the legal status of signing the GPAI Code?

The code is voluntary; providers may rely on it for covered obligations or demonstrate alternative adequate means.

What may a provider that does not follow an approved Code or harmonised standard need to show?

Articles 53(4) and 55(2) require providers using another route to demonstrate alternative adequate means for assessment.