The EU’s approach to governing general-purpose AI: The AI Act and Code of Practice

The European Union’s framework for regulating AI entered a decisive phase this summer. On 10 July 2025, the European Commission unveiled its long-awaited General-Purpose AI (GPAI) Code of Practice, a voluntary framework developed in consultation with nearly 1,000 stakeholders including Member State representatives, industry actors, academic experts, and the European AI Office, a regulatory entity sitting within the European Commission that serves as the central hub for enforcing GPAI provisions of the AI Act. The Code is designed to serve as a practical roadmap for providers of GPAI models to demonstrate compliance with the new GPAI rules under Regulation (EU) 2024/1689 (AI Act). Signatories demonstrating compliance so far include Microsoft, Amazon, Google, and OpenAI amongst others.
The Act defines a GPAI model as “an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications”.
GPAI obligations under the EU AI Act – Disclosure of training data sources
On 2 August 2025, the latest roll-out of copyright and transparency laws under the Act came into force. This latest set of rules covers transparency about the data used to train models, the establishment and compliance with copyright policies, and strict provisions for “systemic risk” AI models (a description of which is set out below).
One of the most notable features is the obligation on providers to publish a summary of the content used for training their models using a standardised Template for the Public Summary of Training Content issued by the Commission in July 2025. The template requires providers to classify their training data sources, e.g. distinguishing between public datasets, licensed material, scraped online content, or user-generated data, and to explain how data was collected and processed before use in training. Providers must also document compliance, including respect for rightsholders’ opt-outs under the text and data mining exception set out in Directive (EU) 2019/790) (EU Copyright Directive), which allows creators to opt out of their works being used to train AI.
The GPAI Code of Practice
The Code is intended to serve as a playbook for providers navigating the Act. It consists of three chapters that mirror GPAI obligations in the Act:
- Transparency
The transparency chapter provides a toolkit for providers to meet their obligations under Articles 53 and 55 of the Act. Its central focus is the preparation and maintenance of comprehensive model documentation whenever a model is placed on the market. Such documentation should include an explanation of how models are trained, what data categories were used, the resources consumed, and the intended use cases. The Code provides a model documentation template for providers to record relevant details.
The chapter also sets out how this information should be shared: providers must disclose relevant details to downstream developers integrating the model into their own systems and, when requested, to the AI Office or national authorities.
- Copyright
The copyright chapter is centred around Article 53(1)(c) of the Act, which deals with compliance with EU copyright and related rights. The Code outlines how providers can demonstrate compliance, including drawing up, implementing and maintaining a copyright compliance policy ensuring that their models are trained in line with EU copyright law. Key measures include:
- Lawful web trawling – Providers should ensure that any scraping of online data respects copyright law, including avoiding paywalled or infringing sources
- Respecting rights reservations – Providers are required to respect rightsholders’ reservations of rights, including opt-outs from text and data mining. Crawlers must be able to detect and comply with the Robot Exclusion Protocol (robots.txt), a technical standard for indicating whether online content can be accessed and reused. Providers are expected to publish information about the crawlers they use, their robots.txt features, and their methods for detecting rights reservations
- Output safeguards – Providers should mitigate the risk of copyright-infringing outputs by putting in place technical safeguards to prevent models from reproducing protected training data in an unlawful way and ensure their terms of use prohibit infringing uses. These obligations apply whether providers deploy the model themselves or make it available to others
- Rightsholder redress – providers should designate a point of contact for rightsholders and establish mechanisms for submitting complaints
- Safety and security
The longest of the three chapters, this chapter is focused on the obligations in Article 55(1) of the Act and applies specifically to GPAI models with systemic risk. These are defined in the Act as “the most advanced (i.e. state-of-the-art) models at any given point in time”. It sets out a systemic risk management framework, requiring providers to continuously identify, assess, and mitigate risks across the model lifecycle.
Obligations in Article 55(1) include carrying out model evaluations, documenting and reporting serious incidents to the AI Office and, in some cases, national competent authorities, and maintaining cybersecurity protections for both the model and the physical infrastructure.
The Code lays out ten commitments on providers of systemic risk models, including the establishment of a dedicated Safety and Security Framework which sets out the provider’s internal processes for handling systemic risks across all phases of the model’s lifecycle. Notification of this framework should be made to the AI Office as well as to stakeholders. Complementing the framework is a requirement to prepare a Safety and Security Model Report which consolidates information on risk management activities and has to be shared with the AI Office before the model reaches the market.
What comes next?
As of 2 August 2025, providers placing GPAI models on the EU market must now comply with their obligations under the Act. Models that present a systemic risk must be notified to the AI Office. The Commission has made clear that in the first year, enforcement will be co-operative rather than punitive, with the AI Office working closely with providers to help them adjust.
That transitional leniency ends on 2 August 2026 for models placed on the market on or after that date, and the Commission’s full enforcement powers take effect, including:
- Fines of up to €35 million or 7% of global annual turnover for the most serious infringements, such as failing to comply with obligations for GPAI models that present systemic risk
- Fines of up to €15 million or 3% of global turnover for other breaches of the Act
- Fines of up to €7.5 million or 1.5% of turnover for supplying incorrect or misleading information to regulators
GPAI models already on the market before 2 August 2025 benefit from a longer runway: they must be fully compliant by 2 August 2027. Meanwhile, the AI Office will review the Code every two years to keep pace with technological and regulatory developments.
Copyright issues in litigation
Several elements of the Code’s copyright chapter are already the subject of active litigation. In the UK, Getty Images’ action against Stability AI originally challenged the use of copyrighted photographs in training. Due to jurisdictional and evidential challenges, it has since dropped its primary copyright claim from the High Court case that commenced in June. However, the secondary claim remains: that using a model trained on infringing data could itself constitute infringement. The forthcoming judgment will therefore not determine whether the initial training and development of the GPAI model was itself infringing, but it is expected to provide important clarity on how and whether the output of such a model can constitute infringement.
In France, a coalition of authors and publishers launched an action against Meta for using copyrighted literary works without permission to train its GPAI model. Separately, a landmark reference now before the Court of Justice of the European Union (CJEU) will test whether training and output generation by large models constitute “acts of reproduction” or “communication to the public” under the EU Copyright Directive and Directive 2001/29/EC (InfoSoc Directive), as well as whether training of models falls outside the scope of the text and data mining exception provided in Article 4 of the EU Copyright Directive.
Pending judicial clarity on issues such as those above, the Code of Practice is currently the most practical roadmap for providers. The measures set out provide a defensible basis for compliance while courts resolve outstanding questions.
