From Voluntary Code to Enforcement: How the GPAI Code of Practice Shapes Expectations

On 2 August 2026 — a date now two weeks away — the European Commission’s enforcement powers over general-purpose AI models activate. For the past year, the GPAI obligations under the EU AI Act have existed largely on paper, with the AI Office limited to persuasion. From that date, it can request documentation, evaluate models directly, order corrective measures, restrict market access, and impose fines up to 3% of global annual turnover or €15 million. The voluntary Code of Practice that’s been quietly operating in the background for a year is about to become the practical difference between good-faith cooperation and full enforcement scrutiny.

I’ve written about the AI Act’s obligations mapped to engineering work generally, and about fine-tuning’s provider-obligation threshold specifically. The Code of Practice sits at a different layer — not the high-risk-system obligations most of that other coverage addresses, but the specific rules governing providers of the underlying general-purpose models themselves, and the enforcement date arriving now changes what “voluntary” actually means in practice.

What the Code actually covers, and why voluntary isn’t the same as optional

Published in final form on 10 July 2025 after a multistakeholder process involving nearly a thousand participants, the Code organises around three chapters. Transparency and Copyright apply to every GPAI provider — technical documentation, model cards, training-data policies, and rights-holder summaries. Safety and Security applies only to providers of GPAI models with systemic risk, defined as models trained above the 10²⁵ FLOP threshold — a narrow group, currently estimated at five to fifteen companies worldwide, but a group that includes the models underlying a meaningful share of enterprise AI deployment.

Free · 4 minutes

Do you know what could take the business down — and have you priced it?

Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.

The Code itself is genuinely voluntary — no law requires a provider to sign it. What changes on 2 August is the practical consequence of that choice. Signatories receive what the AI Office calls a presumption of good faith: the Office will not treat a signatory as in breach simply because full implementation is still in progress, and adherence to the Code will be weighed as a mitigating factor if a fine is ever assessed. Non-signatories face a different posture entirely — more frequent information requests, a higher documentation burden to demonstrate compliance through other means, and no presumption of good faith to fall back on while the AI Office builds its picture of the provider’s actual practices.

Where this actually matters beyond the handful of frontier labs

Roughly two dozen providers have signed the Code so far, and at least one major provider’s public refusal to sign has been widely noted — a genuinely consequential signal, given that the AI Office has indicated non-signatories will receive more intensive scrutiny. For most organisations reading this, the direct signatory question doesn’t apply — you’re a deployer, not a GPAI provider. But the Code’s status shapes something that does affect deployers directly: which providers can demonstrate a credible compliance posture to the downstream customers, regulators, and auditors who increasingly ask about it, and which providers are one AI Office information request away from a materially more scrutinised relationship.

This connects directly to the model-provenance diligence I’ve written about generally — a provider’s Code of Practice status is now a concrete, checkable data point in that diligence, not a nuance. An organisation building critical infrastructure on a non-signatory’s systemic-risk model is building on a foundation the AI Office is specifically positioned to scrutinise harder, starting now.

What checking this actually revealed

A fintech reviewing its AI vendor stack ahead of the enforcement date found that its core underwriting-support model came from a provider that had not signed the Code, a fact nobody at the firm had previously flagged as relevant because the firm’s own AI governance had focused entirely on its own compliance, not its suppliers’. With enforcement now live, that provider faces materially higher scrutiny than a signatory would, and any disruption to that provider’s ability to serve the EU market becomes the firm’s own operational risk. The fix wasn’t necessarily switching providers immediately — it was adding provider Code-of-Practice status as a standing item in ongoing AI vendor risk review, rather than a fact nobody had thought to check.

Assessing a specific AI vendor relationship’s exposure under the Code of Practice’s now-live enforcement environment — and what that means for downstream deployment risk — is exactly the kind of vendor diligence a technology control assessment is built to perform.

This is worth checking now specifically, not on the next routine vendor review cycle — the enforcement date has already arrived, and the AI Office’s early scrutiny priorities are being set in these first weeks.

The same 2 August enforcement date activates a second obligation — see the training-data transparency template.

A short, direct question to every material AI vendor — are you a Code of Practice signatory, and if not, what’s your alternative compliance posture — is a modest ask that produces a genuinely useful answer either way.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming