GPAI rules (Chapter V) + Code of Practice
Issuer: European Commission / AI Office
Date: 2 AUG 2025
Status: IN FORCE in European Union, as of 29 JUL 2026
Documentation, copyright policy, training-data summary; systemic-risk tier >10²⁵ FLOPs; open-source carve-out; Meta declined to sign; enforcement powers activate 2 Aug 2026 (Implementing Reg. 2026/1755).
All general-purpose AI model providers owe technical documentation (Annex XI), downstream information (Annex XII), an EU copyright-compliance policy and a public training-data summary. Models above 10²⁵ FLOPs cumulative compute (or Commission designation) face systemic-risk extras: adversarial testing, EU-level risk assessment, incident reporting. The Code of Practice (10 Jul 2025) is the de facto compliance route, OpenAI, Google, Microsoft, Anthropic, Amazon, IBM and Mistral signed; Meta declined.
What it actually requires (5 provisions)
- Art. 53: documentation, copyright policy, public training-data summary for all GPAI providers
- Art. 51/55: systemic-risk tier (>10²⁵ FLOPs): adversarial testing, risk assessment, serious-incident reporting
- Art. 53(2): open-source carve-out from documentation duties (never from copyright/training-data duties)
- Legacy models (pre-Aug 2025) must comply by 2 Aug 2027 (Art. 111)
- Commission enforcement powers (fines to €15M/3%) activate 2 Aug 2026: Implementing Reg. (EU) 2026/1755
How its status moved
- CODEGPAI Code of Practice published 10 Jul 2025
- EFFECTIVEObligations apply 2 Aug 2025
- NEXTEnforcement powers switch on 2 Aug 2026
Sources (2)
Code of Practice: GPAI Code of Practice (10 Jul 2025)
Voluntary compliance route for general-purpose AI providers; signatories include OpenAI, Google, Microsoft, Anthropic, Amazon, IBM, Mistral AI: Meta declined.
Art. 101: AI Act: GPAI enforcement
From 2 Aug 2026 the Commission can fine general-purpose AI model providers up to €15M or 3% of worldwide turnover.
The rest of the European Union stack
5 more instruments in this jurisdiction, each with its own status, provisions and sources.
- EU AI Act: Regulation (EU) 2024/1689IN FORCEWorld's first horizontal AI law; four-tier risk pyramid; extraterritorial (Art. 2).
- Digital Omnibus on AI: Regulation (EU) 2026/1744IN FORCEDefers high-risk application to 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I); adds nudifier/NCII + AI-CSAM bans (2 Dec 2026); SME simplifications; substance of high-risk duties unchanged.
- European AI OfficeIN FORCEEU-level GPAI regulator: evaluate models, demand access, sanction; expanded remit under the Omnibus.
- Art. 50 transparency dutiesUPCOMINGChatbot disclosure; machine-readable synthetic-content marking; visible deepfake labels.
- GDPR Art. 22IN FORCERight not to be subject to purely automated decisions: the ancestor of the rights-based approach.
Where this sits in the wider picture
- The European Union regime dossier gives the doctrine this instrument belongs to, next to the other two jurisdictions.
- The Framework Explorer, filtered to EU lists every instrument in this jurisdiction in one filterable index.
- The governance simulator shows what these rules do to a real AI system, next to what the other two jurisdictions do to the same one.
- The timeline places this date beside what the other capitals were doing that month.
- This sits inside Regulation (EU) 2024/1689. Read the article text itself, with its cross references, in the free EU AI Act Explorer.
Knowing the instrument is step one. Complying with it is the job.
The programs teach the work that follows a rule like this one: classification calls, conformity assessment, filings, documentation, and the judgment to defend every decision.
VERIFIED 29 JUL 2026. Every fact on this page is drawn from the sources listed above and dated to the day it was checked. Study aid, not legal advice: the official texts are always authoritative.