GPAI Code of Practice
Updated 2026-06-16 based on S-2026-06-eu-ai-office-external-evaluators — the EU AI Office is gathering expert input on independence and qualification requirements for external evaluators of GPAI models with systemic risk (workshop scheduled 15 July 2026), operationalising the Code’s Safety & Security commitment to provide independent external evaluators with model access. Added to “How it’s used” and resolves part of the open thread on systemic-risk evaluation methodology. ⚠️ Item is search-derived; exact instrument and dates unconfirmed against a primary page.
Category: regulatory instrument Maturity: adopted in stages (provider obligations applied 2 August 2025; enforcement begins 2 August 2026) First seen: 2026-03-20 Last updated: 2026-06-16
What it is
The General-Purpose AI Code of Practice under the EU AI Act. Governs the obligations of providers of General-Purpose AI models — including transparency requirements, copyright policy, training-data summary, and systemic-risk notification. Distinct from but related to the Code of Practice on marking and labelling of AI-generated content under Article 50 [S-2026-04-29-eu-ai-office-gpai].
How it’s used
- GPAI provider obligations have applied since 2 August 2025; full enforcement (including fines up to 6% of global annual turnover) begins 2 August 2026 [S-2026-04-29-eu-ai-office-gpai].
- Pre-2 August 2025 GPAI models on the market have until 2 August 2027 to comply [S-2026-04-29-eu-ai-office-gpai].
- Deployers / embedders of third-party GPAI models in regulated financial-services workflows must evidence upstream-provider compliance — copyright policy, training-data summary — within their own AI governance and third-party risk frameworks [S-2026-04-29-eu-ai-office-gpai].
- GPAI Code of Practice Signatory Taskforce met in March 2026 (second meeting on 13 March 2026); firms are aligning quality management systems with the emerging prEN 18286 harmonised standard.
- The Digital Omnibus proposal does not delay GPAI obligations — they remain on the 2 August 2026 track [S-2025-11-19-eu-digital-omnibus].
- Under the Code’s Safety & Security commitments, signatories must provide a sufficient number of independent external evaluators with access to their most advanced model versions; in June 2026 the AI Office began gathering expert input on the independence and qualification requirements for such external evaluators of GPAI models with systemic risk, with a workshop scheduled 15 July 2026 [S-2026-06-eu-ai-office-external-evaluators]. This signals an emerging, regulator-shaped market for independent AI model evaluation that overlaps directly with independent assurance practice [inference — link to service line is the wiki’s own, not the source’s].
Theoretical basis
- implements → EU AI Act — operationalises Article 50 / GPAI marking and labelling obligations.
- relates-to → Operational Resilience and Third Party Risk — deployer obligations interact with third-party risk.
- relates-to → CEN-CENELEC JTC 21 — harmonised standards work (prEN 18286).
- relates-to → EU AI Office (European Commission) — body running the external-evaluator independence/qualification process under the Code [S-2026-06-eu-ai-office-external-evaluators].
- relevant-to → Service Line — Independent Governance Assurance — regulator-defined independent external evaluation overlaps with independent assurance practice [inference].
Strengths / weaknesses
Not synthesised in detail. Strength: provides a concrete compliance vehicle for GPAI providers. Weakness flagged in corpus: GPAI systemic-risk evaluation methodology is still being published by the AI Office [S-2026-05-06-paul-ai-data-pathway] — partially addressed by the June 2026 move to define independence and qualification requirements for external evaluators, though the criteria themselves are not yet set [S-2026-06-eu-ai-office-external-evaluators].
Tensions
None surfaced — though the Digital Omnibus political process creates uncertainty about whether GPAI dates will ultimately be touched by compromise. See EU AI Act Tensions.