Assess compliance with the EU General-Purpose AI Code of Practice (Final Version, July 2025) and underlying AI Act obligations (Articles 51–56).
Important: This skill provides compliance workflow support, not legal advice. The Code of Practice is voluntary — providers can demonstrate compliance through alternative means. Always cite specific articles, commitments, and measures. Where facts are incomplete, state assumptions explicitly and ask targeted follow-up questions.
Follow this decision tree strictly in order.
Determine whether the entity falls within scope.
Definition (Article 3(63) + GPAI Guidelines): A GPAI model is one "trained with a large amount of data" that displays "significant generality" and is "capable of competently performing a wide range of distinct tasks." Indicative threshold: trained with >10^23 FLOPs and capable of generating text, audio, images, or video.
Check:
If YES to any → The entity is a GPAI model provider. Proceed to Step 2. If NO → May still be a downstream provider/deployer with separate obligations. Document why GPAI provider status does not apply and stop.
Key distinction: The release mode (API, open weights, enterprise licence) does not affect whether a model is GPAI. It affects which exemptions apply.
Check whether the partial exemption under Article 53(2) applies:
If YES to both:
If NO → All obligations apply. Proceed to Step 3.
Determine whether the GPAI model has systemic risk:
| Criterion | Threshold | Source |
|---|---|---|
| Compute-based presumption | Training compute >10^25 FLOPs | Article 51(2) |
| Commission designation | High-impact capabilities or equivalent impact based on Annex XIII criteria | Article 51(1)(b) |
If systemic risk → TWO obligation tiers apply:
If no systemic risk → Tier 1 only.
→ Currently ~5–15 companies worldwide have models meeting the systemic risk threshold.
Assess compliance with each obligation. The Code of Practice provides the compliance framework through two chapters:
| Obligation | AI Act Source | Code Measure | Key Requirements |
|---|---|---|---|
| Technical documentation | Art. 53(1)(a), Annex XI | Measure 1.1 | Model Documentation Form — licensing, architecture, training, datasets, compute, energy |
| Downstream provider info | Art. 53(1)(b), Annex XII | Measure 1.2 | Capabilities, limitations, integration info — deliver within 14 days of request |
| Documentation integrity | Art. 53(1)(a)–(b) | Measure 1.3 | Accurate, tamper-proof, securely stored for ≥10 years |
| Training data summary | Art. 53(1)(d) | GPAI Template | Mandatory public disclosure — data sources, types, volumes, compliance measures |
→ For complete transparency requirements and the Model Documentation Form, read references/transparency-obligations.md.
| Obligation | Code Measure | Key Requirements |
|---|---|---|
| Copyright policy | Measure 1.1 | Draw up, publish summary, define accountability |
| Lawful access only | Measure 1.2 | No circumventing paywalls; exclude piracy sites |
| Rights reservations | Measure 1.3 | Comply with robots.txt and machine-readable opt-outs |
| Record-keeping | Measure 1.4 | Maintain records of crawling and rights compliance |
| Output safeguards | Measure 1.5 | Technical measures to minimise infringing outputs |
| Terms of service | Measure 1.6 | Prohibit unauthorised copyright use by users |
| Complaints handling | Measure 1.7 | Designated contact point, fair complaint process |
→ For complete copyright requirements, read references/copyright-obligations.md.
Only if the model has systemic risk (Step 3). Assess compliance with the Safety & Security chapter (Commitments 1–10):
| Commitment | Focus | Key Requirements |
|---|---|---|
| 1 | Safety & Security Framework | Create, implement, update, notify AI Office |
| 2 | Systemic risk identification | Structured process + risk scenarios |
| 3 | Systemic risk analysis | Evaluations, modelling, monitoring |
| 4 | Risk acceptance determination | Acceptance criteria + proceed/stop decision |
| 5 | Safety mitigations | Lifecycle safety measures |
| 6 | Security mitigations | Cybersecurity for model + infrastructure |
| 7 | Model Reports | Pre-market report to AI Office, keep updated |
| 8 | Responsibility allocation | Clear roles, resources, risk culture |
| 9 | Serious incident reporting | Track, document, report within deadlines |
| 10 | Additional documentation | Record-keeping (10 years), public transparency |
→ For complete systemic risk requirements, read references/systemic-risk-framework.md.
If the provider or deployer operates in Germany, Austria, or Switzerland, check additional requirements:
→ For DACH overlay details, read references/dach-specific.md.
If a provider needs to move fast, these are the five highest-impact actions in priority order:
Determine your status and sign the Code — Are you a GPAI model provider? If yes, sign the Code of Practice. Non-signatories face heavier scrutiny and must prove compliance through alternative means. This is the single highest-leverage decision.
Publish your training data summary — Mandatory under Article 53(1)(d), no exemption, must be public. Use the Commission's GPAI Template. This is the most visible obligation — absence is immediately noticeable.
Draft and publish your copyright policy — Required for ALL providers including open-source. Must be operational, not a legal placeholder. Designate a complaints contact point. (See references/copyright-obligations.md for what a good policy looks like.)
Complete the Model Documentation Form — Technical documentation covering architecture, training, datasets, compute. Must be ready for AI Office requests. 14-day response window for downstream providers.
If systemic risk: build your Safety & Security Framework — This is the biggest lift. Start with Commitments 1–4 (Framework → Risk ID → Analysis → Acceptance). The Model Report (Commitment 7) depends on having these in place first.
Enforcement timeline: AI Office enforcement actions begin 2 August 2026 in current law. Legacy GPAI models (placed on the market before 2 August 2025) have until 2 August 2027. The 7 May 2026 provisional Council/Parliament agreement on the Digital Omnibus leaves these GPAI dates unchanged; only Annex III high-risk and Annex I dates would shift if formally adopted. Until adoption plus Official Journal publication, current-law dates remain authoritative.
Use these questions at intake to gather the information needed for assessment:
Model & Provider
Distribution & Use 5. How is the model distributed (API, download, integrated product)? 6. Who are the downstream providers/deployers integrating this model? 7. Is the model fine-tuned or modified from a base model? By how much?
Training Data 8. What data sources were used for training? 9. Is web-scraped data involved? How are rights reservations handled? 10. What copyright compliance measures are in place?
Risk & Compliance 11. Has the model been designated as having systemic risk? 12. What documentation currently exists (model cards, technical docs)? 13. Has the provider signed the Code of Practice? 14. What cybersecurity measures protect the model and infrastructure?
If answers are incomplete, state assumptions explicitly and flag gaps.
Load these as needed based on assessment progress:
| File | When to read |
|---|---|
| references/transparency-obligations.md | Assessing Transparency chapter — Model Documentation Form, Annex XI/XII requirements |
| references/copyright-obligations.md | Assessing Copyright chapter — policy, crawling, rights reservations, complaints |
| references/systemic-risk-framework.md | Model has systemic risk — all 10 Safety & Security commitments with measures |
| references/compliance-timeline.md | Building a compliance roadmap — all deadlines, enforcement dates, grace periods |
| references/dach-specific.md | Provider/deployer in Germany/Austria/Switzerland — BNetzA, BSI, works council |
| references/templates.md | Producing deliverables — gap assessment, compliance memo, executive summary templates |
Every GPAI Code of Practice assessment produces three deliverables:
Compliance Gap Assessment — Systematic evaluation of each applicable commitment and measure, identifying gaps, current status (compliant/partial/non-compliant), and remediation actions with priority and timeline.
GPAI Compliance Memo — Formal record documenting the provider determination, scope analysis, applicable obligations, Code of Practice adherence status, cited articles and measures, and key assumptions.
Executive Summary — One-page summary for leadership with provider status, obligation tier, key gaps, enforcement timeline, and recommended next steps.
→ For complete templates, read references/templates.md.
| Violation | Maximum Fine | AI Act Source |
|---|---|---|
| Systemic risk obligations (Art. 55) | €15M or 3% global annual turnover | Art. 101(2) |
| General GPAI obligations (Art. 53) | €7.5M or 1% global annual turnover | Art. 101(3) |
| Incorrect/misleading information to AI Office | €7.5M or 1% global annual turnover | Art. 101(3) |
For SMEs and startups, the lower of the two amounts applies.
Enforcement note: While GPAI obligations apply since 2 August 2025, the AI Office's formal enforcement actions (requests for information, access to models, model recalls) begin 2 August 2026. This grace period is for working with the AI Office toward compliance — not a safe harbour.
Non-signatories to the Code of Practice face "a larger number of requests for information and requests for access" and must demonstrate compliance through alternative, potentially more burdensome means (Articles 53(4), 55(2), 56).
This skill provides structured compliance workflow support based on Regulation (EU) 2024/1689 and the GPAI Code of Practice (Final Version, July 2025). It does not constitute legal advice. The Code of Practice is a voluntary compliance tool — adherence creates a presumption of compliance but is not conclusive evidence. Assessment outcomes should be reviewed by qualified legal counsel. The EU AI Act is subject to delegated acts, implementing acts, harmonised standards (expected 2027+), and ongoing AI Office guidance that may affect interpretation.