TL;DR: EU AI Act GPAI Codes of Conduct 2026: Provider Obligations and Compliance, a practical compliance guide for enterprise and HR teams in 2026.
The EU AI Act created a new compliance instrument that does not exist in any prior EU technology law: the code of conduct for general-purpose AI (GPAI) model providers. Unlike a certification scheme or a third-party audit requirement, the GPAI Code of Practice is a living document drafted by industry participants under the AI Office's supervision. Providers that sign it and follow it get a legal presumption of conformity. Providers that ignore it face a harder road to demonstrating compliance.
This guide explains what the code covers, who it applies to, what legal weight it carries, and what obligations sit outside its scope. The target audience is legal and technical teams at companies that build, fine-tune, or distribute GPAI models to users in the EU.
What is the GPAI Code of Practice and how did it come about
The EU AI Act, which entered into force on 1 August 2024, directed the newly created AI Office to facilitate the preparation of codes of practice for GPAI providers. Article 56 of the Act states that providers adhering to such codes shall be presumed to comply with the obligations set out in Chapter V of the Act. The AI Office published a draft code in late 2025 and finalized the first full version in June 2026.
The drafting process was unusual. The AI Office convened working groups that included over 1,000 stakeholders: AI providers, civil society organizations, academic researchers, and representatives from EU member state authorities. The working groups produced text chapter by chapter, with the AI Office acting as chair rather than sole author. This means the code reflects negotiated positions, not unilateral regulator preferences.
The final 2026 code has four main chapters: transparency obligations, copyright-related obligations, systemic-risk assessment, and systemic-risk mitigation. Each chapter contains both mandatory commitments (for providers who sign) and optional "good practice" commitments that go beyond the legal baseline.
Providers of GPAI models with general availability in the EU are the primary audience. That includes providers of API-accessible foundation models, providers of open-weight models distributed for fine-tuning and deployment, and providers who offer model-as-a-service products. The code covers the provider of the base model, not downstream deployers who use those models as inputs.
Who must comply and who may comply voluntarily
The EU AI Act draws a line between GPAI models in general and GPAI models that pose systemic risk. Both categories face obligations, but the systemic-risk category faces substantially heavier ones.
All GPAI model providers placing models on the EU market must comply with a baseline set of obligations under Article 53. These include:
Maintaining technical documentation sufficient to allow downstream providers and the AI Office to assess the model's capabilities, limitations, and training process. The documentation requirements are spelled out in Annex XI of the Act.
Drawing up and publishing a policy that describes how copyright law is respected during training data collection and model outputs. This policy must be made publicly accessible, not just provided to the AI Office.
Publishing a summary of the training data used in the model, sufficient to allow anyone to understand what categories of data were used and at what scale. The summary must be on a publicly accessible register maintained by the AI Office.
Passing downstream information: a GPAI model provider must make available to downstream providers who integrate the model into their own products any information necessary for those providers to comply with their own AI Act obligations.
GPAI models with systemic risk face additional obligations under Article 55. These include adversarial testing (red-teaming) before release, tracking and reporting serious incidents to the AI Office within defined time windows, and implementing cybersecurity protection measures.
The systemic-risk threshold is set in Article 51 at training compute of 10^25 FLOPs. The AI Office published guidance in early 2026 clarifying that this threshold applies to the total compute used in the final training run of the base model, not cumulative across incremental updates. Fine-tuned versions of a threshold-exceeding model do not automatically inherit systemic-risk status unless the fine-tuning itself consumes compute above the threshold, which in practice it never does.
As of August 2026, the AI Office's public register lists a small number of models meeting the threshold. These come primarily from OpenAI (GPT-4o and later), Anthropic (Claude 3 family and later), Google DeepMind (Gemini 1.5 Ultra and later), and Meta (Llama 3.1 405B and models trained on larger runs). Most companies building AI products do not train models at this scale and are not systemic-risk providers.
Providers below the systemic-risk threshold who sign the code still benefit from the presumption of conformity for their Article 53 obligations. That is the main incentive for smaller GPAI providers to participate.
What the code covers in detail
The transparency chapter of the code translates Article 53 requirements into operational commitments. Signatories must maintain technical documentation in a specified format that covers: the model architecture, the number of parameters, the modalities supported, the training compute, the datasets used (with category breakdowns by domain and language), the evaluation benchmarks used and their results, and the intended use cases.
The documentation must be updated whenever a significant model update occurs. The code defines "significant update" as any update that materially changes the model's capabilities, safety properties, or the types of outputs it can produce. Releasing a new context window size without retraining, for example, would not typically qualify.
The copyright chapter requires signatories to document their compliance with the EU's Text and Data Mining exception under Directive 2019/790 (the Digital Single Market Directive). Article 4 of that directive allows training on publicly available data unless rights holders have expressly reserved their rights. The code requires GPAI providers to: describe the process used to respect opt-out signals such as the robots.txt directives and meta-tags, document the sources of training data including any licensed datasets, and describe what filtering was applied for potentially infringing content.
For models that generate text, images, music, or code, the code also requires providers to document their policy on output filtering for copyright-infringing reproductions and to publish that policy.
The systemic-risk chapter is divided into two parts: assessment and mitigation. Providers of threshold-exceeding models must conduct a systemic-risk assessment before releasing any major model update. The assessment covers: potential for mass-scale manipulation of public opinion, capability to produce biological, chemical, nuclear, or radiological weapons information, potential for cyberattacks on critical infrastructure, and capability for autonomous action that circumvents human oversight.
The assessment must be documented using a methodology that can be independently reviewed. The code does not mandate a single methodology but references the AI Safety Institute's model evaluation protocols and METR's autonomous replication testing framework as accepted approaches. Signatories must share their assessment reports with the AI Office upon request.
Mitigation commitments include: technical safeguards against misuse (such as fine-tuning guardrails and output filters), incident reporting within 72 hours of discovering a serious incident, and participation in the AI Office's incident information-sharing system.
How the presumption of conformity works under Article 56
Article 56 of the EU AI Act states that GPAI model providers that adhere to a code of conduct that has been endorsed by the AI Office shall be presumed to be in compliance with the obligations set out in Articles 53 and 55 of the Act, insofar as those obligations are covered by the code.
The word "presumed" is legally significant. A presumption of conformity is rebuttable. If the AI Office investigates a specific provider and finds that despite signing the code, that provider is not actually following it, the presumption falls away and the provider faces full enforcement exposure.
The practical effect is that the presumption shifts the burden of proof in any enforcement proceeding. Without it, the AI Office would need to affirmatively demonstrate that the provider fails to meet the legal standard. With it, the AI Office needs to demonstrate that the provider fails to follow the code it signed. Since the code is more specific than the statute, this can be both easier and harder depending on the situation.
Signatories must annually submit a self-assessment to the AI Office describing how they have implemented each commitment in the code. For systemic-risk providers, this self-assessment is reviewed by the AI Office and may be followed by questions or requests for additional documentation. The AI Office can commission independent evaluations of systemic-risk models using its own contracted evaluators.
Providers that sign the code but subsequently fail to meet its requirements must notify the AI Office. The code includes a grace period for remediation that depends on the severity of the gap, but repeated non-conformities can result in the AI Office publicly withdrawing the presumption of conformity for that provider.
See the EU AI Act compliance guide for small teams for context on how these GPAI obligations fit into the broader compliance picture for teams deploying rather than building models.
Obligations that sit outside the code
Signing the code does not eliminate all compliance obligations for GPAI providers, and it does not transfer any obligations to downstream deployers.
The most significant gap is the EU fundamental rights impact assessment (FRIA) requirement in Article 27. When a downstream provider takes a GPAI model and integrates it into a high-risk AI system as defined in Annex III of the Act, that downstream provider must conduct a FRIA before deploying the system. The FRIA requirement applies to the deployer, not the GPAI model provider, but the GPAI provider's technical documentation must be detailed enough to support the downstream FRIA. If a GPAI provider's documentation is too vague about model limitations or failure modes, downstream deployers will struggle to complete their FRIAs, which creates both a legal risk and a commercial friction.
GPAI providers also remain subject to the AI Act's prohibited practices in Article 5, regardless of code adherence. If a GPAI model is used in ways that the Act prohibits, such as social scoring by public authorities or real-time biometric identification in public spaces for prohibited purposes, the provider may face liability if it knew or should have known about the downstream use.
Additionally, GDPR obligations apply independently. If a GPAI model processes personal data during training or inference, GDPR requirements apply in full: lawful basis, data subject rights, data protection impact assessments, and so on. The GPAI Code of Practice does not address GDPR compliance and signing it provides no GDPR safe harbor.
The AI regulation deadline calendar 2026 tracks all relevant EU AI Act dates, including when GPAI documentation requirements fully apply and when the AI Office's oversight powers over systemic-risk models became active.
Documentation checklist for GPAI providers
The following is what GPAI model providers need to document and maintain to satisfy both the code and the underlying Article 53 requirements. This list is drawn from Annex XI of the EU AI Act and the final 2026 code commitments.
For all GPAI providers, regardless of systemic-risk status:
Technical documentation must include the model architecture and type, the number of parameters in the released version, the training data description (categories, languages, approximate size), the training compute used in the final training run expressed in FLOPs, the evaluation benchmarks used to assess the model and their results, the model's supported modalities (text, image, audio, etc.), the intended deployment contexts, and the known limitations and failure modes.
The copyright policy must be published publicly and must describe: the legal basis for training data collection, the process for respecting rights-holder opt-outs, the sources of licensed data used in training, and the output filtering policy for potential copyright infringement.
The training data summary must be published on the AI Office's register. The register became operational in the first quarter of 2026.
Downstream information packages must be made available to any provider who integrates the model into their own product. These packages must contain the information necessary for downstream compliance under the Act, including model capability descriptions, known failure modes relevant to high-risk uses, and any technical constraints on how the model should be deployed.
For systemic-risk GPAI providers only, the additional documentation requirements include:
The systemic-risk assessment report, covering the four risk categories described earlier. This must be completed before each major model release and updated if a subsequent evaluation reveals new risk information.
Incident logs covering all serious incidents involving the model, including the date, nature, severity, and measures taken in response. Logs must be maintained for at least three years and made available to the AI Office on request.
Red-teaming and adversarial testing records, including the methodology used, the teams involved (internal or third-party), the findings, and the mitigations implemented in response.
Cybersecurity protection documentation describing the technical and organisational measures in place to protect model weights, training infrastructure, and inference systems.
See the EU AI Act GPAI compliance checklist August 2026 for a printable version of these requirements with status tracking fields.
Reading the code alongside Article 56
The 2026 GPAI Code of Practice is not short. The final text runs to approximately 90 pages including annexes. For legal and technical teams trying to implement it, the most practical approach is to map each commitment in the code to a named owner in your organization, assign a documentation artifact or process to each commitment, and set a review cadence aligned with your model release cycle.
The code's self-assessment template is the most useful starting point. The AI Office published the template alongside the final code. It is structured as a table with one row per commitment, columns for the provider's implementation description, the evidence artifact, and the date of last review. Teams that fill in this table have, in effect, a gap analysis showing what documentation they are missing.
For providers below the systemic-risk threshold, the baseline obligations are manageable if documentation discipline is established early. The hardest part is not the volume of documentation but the habit of updating it when model changes occur. A training data summary that was accurate in 2025 may be inaccurate after a mid-2026 retraining run. The code requires updates, not one-time filings.
For threshold-exceeding providers, the systemic-risk assessment process requires dedicated resources: either internal safety teams with the capacity to run evaluations, or contracted third-party evaluators. Several organizations, including Apollo Research, Redwood Research, and the UK AI Security Institute, have published evaluation frameworks that the AI Office considers acceptable methodology. Using an accepted methodology is not required, but it substantially reduces the risk of an AI Office finding that the assessment was inadequate.
The EU AI Act's compliance architecture for GPAI is relatively new territory. Unlike GDPR, which has a decade of enforcement decisions to learn from, the GPAI obligations are being interpreted in real time. Teams that engage actively with the AI Office's published guidance, participate in the stakeholder processes, and build documentation practices now will be in a significantly better position than those who wait for enforcement to clarify the rules.
Related Reading
- EU AI Act compliance guide for small teams
- EU AI Act GPAI compliance checklist August 2026
- AI regulation deadline calendar 2026
- EU AI Act August 2026: What's Delayed and What Still Applies
- EU AI Act enforcement starts August 2, 2026: what it means and what to d
- EU AI Act GPAI Code of Practice: What It Requires and the August 2026 Co
- Meta Skipped the EU AI Code: What Llama Deployers Must Do Now
