The OECD.AI Policy Navigator

Our policy navigator is a living repository from more than 80 jurisdictions and organisations. Use the filters to browse initiatives and find what you are looking for.

EU General-Purpose AI (GPAI) Code of Practice


Added by:   OECD analyst
Added on:   21 Jul 2026
Updated by:   OECD analyst
Updated on:   28 Jul 2026

A co-regulatory instrument under Article 56 of the EU AI Act, developed through a multi-stakeholder process led by the EU AI Office, which translates the AI Act's obligations for General Purpose AI (GPAI) model providers into specific, operationalisable compliance measures covering transparency, copyright, systemic risk assessment, safety testing, incident reporting and governance.

Initiative overview

The GPAI Code of Practice is one of the most consequential instruments under the EU AI Act for frontier AI model developers, as it directly operationalises the obligations in Chapter V of the Act for providers of general-purpose AI models. The Code was developed through an unprecedented multi-stakeholder drafting process coordinated by the EU AI Office, running from November 2024. It involved over 1,000 stakeholders including AI developers (OpenAI, Google DeepMind, Meta, Anthropic, Mistral, Aleph Alpha and others), academic researchers, civil society organisations, standards bodies, and national competent authorities. Draft versions were published iteratively with a final adopted version targeted for May 2025. The Code is structured across four substantive chapters: transparency and copyright obligations (requiring model documentation, training data disclosure, compliance with EU copyright law, and reservation of rights mechanisms); safety and security for non-systemic-risk models; additional systemic risk obligations (covering adversarial testing, red-teaming, cybersecurity measures, serious incident reporting, and model evaluations against safety benchmarks); and governance and accountability. The Code includes specific "measures" and "key performance indicators" for each obligation, enabling both self-assessment by providers and external verification by the AI Office. Compliance with the Code creates a presumption of conformity under the AI Act, substantially reducing legal uncertainty for GPAI providers. Non-compliance with GPAI obligations under the AI Act (where the Code applies) can result in fines of up to EUR 15 million or 3% of global annual turnover.