Guides
    11 min read

    The GPAI Code of Practice, Explained: Signatory vs Non-Signatory Sovereignty Risk

    Last reviewed: 8 July 2026

    The General-Purpose AI Code of Practice is the operational scaffolding beneath the EU AI Act's Article 53 and Article 55 obligations. Finalised by the AI Office on 10 July 2025 and formally endorsed by the AI Board on 22 September 2025, it translates the AI Act's high-level model-provider duties into 87 concrete measures across three chapters: transparency, copyright, and — for systemic-risk models only — safety and security.

    The Code is not law. It is what Article 56 calls a "code of practice at Union level," and signing it does not create legal obligations on top of the AI Act. What it does is create a presumption of conformity. A signatory that implements the Code's measures in good faith is presumed to comply with the underlying AI Act obligations, shifting the evidentiary burden to the AI Office. A non-signatory carries that burden itself.

    This is a legally slight distinction with substantial practical consequences. This article breaks down the Code's structure, sets out precisely what signatories are committing to, explains what "equivalent means" of compliance looks like for non-signatories, and shows why the signatory/non-signatory distinction has become a first-order signal in European AI procurement.

    The Three-Chapter Structure

    The Code is organised into three chapters, corresponding to the three obligation groups it addresses.

    **Chapter I — Transparency (11 measures).** Applies to all signatories. Requires production and maintenance of a model documentation template (the "Model Documentation Form" published by the AI Office in September 2025), covering training methodology, dataset composition, evaluation results, known limitations, computational resources, and energy consumption. Documentation must be updated within 60 days of any material change and made available to the AI Office on request. A public summary must be published and kept current.

    **Chapter II — Copyright (5 measures).** Applies to all signatories. Requires implementation of an EU copyright policy including respect for the Article 4(3) DSM Directive text-and-data-mining opt-out, publication of a sufficiently detailed public summary of training content using the AI Office template, designation of a copyright compliance contact point, and processes for rights-holder complaints. This chapter has attracted the most contention — Meta's non-signature was substantially driven by objections here.

    **Chapter III — Safety and Security (71 measures).** Applies only to signatories whose models meet the Article 51 systemic-risk threshold (currently 10^25 training FLOPs, with the Digital Omnibus clarification pulling in fine-tuning compute above 10^24 FLOPs). This is by far the most detailed chapter. It covers systemic risk identification and assessment, model evaluations across capability and safety benchmarks, adversarial testing including red-teaming, cybersecurity measures for model weights, serious incident reporting within 15 days, and governance measures including a designated safety officer.

    Signing the Code does not require accepting all three chapters. Providers may sign the transparency and copyright chapters alone if their models do not meet the systemic-risk threshold, or sign only specific chapters if they can justify the partial adherence. xAI's July 2025 partial signature covering only Chapter III is the leading precedent for chapter-selective adherence.

    The Signatory Roster in Mid-2026

    As of June 2026, the confirmed signatory position is as follows.

    **Full signatories (all three chapters where applicable):** OpenAI, Anthropic, Google, Microsoft, Mistral, IBM, Cohere, Aleph Alpha, Silo AI. Together these providers represent an estimated 78% of the EU-deployed GPAI market by API call volume.

    **Partial signatories:** xAI (Chapter III only, citing product decisions on Chapters I and II). Amazon Bedrock (Chapters I and II as a downstream provider for hosted models it does not train).

    **Explicit non-signatories:** Meta (declined July 2025, citing Chapter II copyright provisions as "unworkable"). DeepSeek, Alibaba Qwen, Baidu ERNIE, and Zhipu AI (Chinese providers, no signature indicated as of Q2 2026).

    **Undeclared:** A long tail of smaller providers and open-weights model releasers where the signature question has not been publicly resolved.

    The AI Office maintains the definitive signatory list at its official register, updated quarterly. Procurement teams should treat that register as authoritative rather than relying on vendor claims. A number of vendors marketed their upstream model's signatory status inaccurately in early 2026, prompting an AI Office clarification on 8 April 2026 that misrepresentation of signatory status may itself constitute a misleading commercial practice under the Unfair Commercial Practices Directive.

    The signatory roster is not static. Any provider may sign at any time by notifying the AI Office and committing to a compliance timeline. Any signatory may withdraw with 90 days' notice. As of June 2026 there have been no withdrawals, and three additions (Cohere in February, Aleph Alpha in March, Silo AI in May) all reflecting European market positioning.

    What 'Equivalent Means' Looks Like for Non-Signatories

    Article 53(4) permits providers to demonstrate compliance through means other than adhering to a Code of Practice. This is the "equivalent means" pathway that non-signatory providers must use. The AI Office guidance of 12 June 2026 sets out what equivalent means actually requires in practice.

    The threshold is functional equivalence. For each Code measure a non-signatory would have committed to as a signatory, the provider must demonstrate a mechanism that achieves the same regulatory outcome. For transparency, this means producing documentation of substantially equivalent content and update cadence. For copyright, it means implementing an equivalent opt-out respect mechanism and publishing an equivalent training-content summary. For systemic-risk models, it means demonstrating equivalent evaluation, red-teaming, incident reporting, and governance arrangements.

    The guidance is explicit that equivalence is judged on substance, not form. A non-signatory using its own documentation template is acceptable if the template covers the required content areas. A non-signatory conducting its own red-teaming is acceptable if the methodology meets state-of-the-art standards, which the guidance defines by reference to the NIST AI Risk Management Framework Playbook and the UK AI Safety Institute's evaluation methodology.

    The practical challenge for non-signatories is not producing equivalent evidence in principle — it is producing it in a form that European deployers can readily use for their own Article 26 compliance. Signatory documentation is standardised and comparable across providers. Non-signatory documentation is bespoke and requires deployer legal review to confirm equivalence. This review cost is real, and it is passed through to buyers either explicitly (as consulting fees) or implicitly (as slower procurement cycles).

    Enforcement risk for non-signatories is also higher during the first enforcement phase. AI Office practice notes indicate that non-signatory GPAI models will receive "enhanced scrutiny" until an established compliance track record exists. This does not mean non-signatories are presumptively non-compliant — but it does mean that the burden of demonstrating compliance sits on them at the moment enforcement actions begin.

    The Systemic-Risk Overlay

    Chapter III's application depends on whether a model meets the Article 51 systemic-risk threshold. The threshold is quantitative — training compute exceeding 10^25 FLOPs — but the AI Office retains discretion under Article 51(1)(b) to designate additional models as systemic-risk based on qualitative capability assessment.

    As of June 2026, the AI Office's confirmed systemic-risk designations include GPT-5.6 (OpenAI), Claude Opus 4.5 and Claude Sonnet 4.5 (Anthropic), Gemini 3 Ultra and Gemini 3 Pro (Google), Llama 4-405B (Meta), Mistral Large 3 (Mistral), and Grok-4 (xAI). Additional models are under review.

    For signatories with systemic-risk models, Chapter III imposes obligations that are meaningfully burdensome. Model evaluations must cover capability benchmarks (MMLU-Pro, GPQA, SWE-Bench), safety benchmarks (HarmBench, JailbreakBench), and domain-specific benchmarks for high-impact capability areas (biosecurity, cybersecurity, autonomous replication). Red-teaming must be conducted by independent parties with documented methodology. Serious incidents — defined to include unexpected capability jumps, evidence of adversarial misuse causing significant harm, or model weight compromise — must be reported to the AI Office within 15 days.

    For non-signatories with systemic-risk models, the equivalent means burden is proportionally larger. Meta's Llama 4-405B is the leading test case. Meta has publicly committed to conducting its own evaluations and publishing model cards, and to notifying the AI Office of serious incidents within a comparable timeframe. Whether these commitments constitute equivalent means will be tested in the first enforcement cycle, and the outcome will influence non-signatory positioning industry-wide.

    The systemic-risk overlay is where the most consequential enforcement action is expected. It is also where the divergence between signatory and non-signatory exposure is largest. For European buyers deploying systemic-risk models in production, this overlay is the primary risk consideration.

    Signatory Status as a Procurement Signal

    In European AI procurement in mid-2026, signatory status has moved from an obscure regulatory data point to a first-order procurement signal. Four practical uses have emerged.

    **Vendor scoring adjustment.** Procurement scoring rubrics now include Code of Practice signatory status of the underlying model provider, typically weighted at 5–10% of total score. This is not decisive on its own but is meaningful at the margin.

    **Fast-track approval.** Several European enterprises (including two of the top four French banks and three DAX-listed industrials) have implemented fast-track AI procurement pathways for services built on signatory models, with correspondingly slower pathways for non-signatory alternatives. This reduces the internal transaction cost of adopting signatory-based services.

    **Contract clause standardisation.** Signatory status enables standardised AI Act warranty clauses that map directly to Code chapters. Non-signatory equivalents require bespoke drafting, increasing legal review cost by an estimated 3–8 hours per contract.

    **Insurance underwriting.** European cyber and technology E&O insurers have begun differentiating premiums based on signatory status of underlying models. Munich Re's April 2026 policy update, replicated by Allianz and Zurich, applies a 10–15% premium reduction for AI-related coverage where all embedded GPAI models are provided by Code signatories.

    None of these mechanisms makes non-signatory models unusable in Europe. But they collectively raise the effective cost of non-signatory adoption enough that most enterprise buyers are defaulting to signatory-first procurement unless a specific capability requirement justifies otherwise. Whether this pattern persists depends heavily on how the first enforcement cycle unfolds — but as a working assumption for the remainder of 2026, signatory-first is the prudent baseline.

    Key Takeaways for Technical Leaders

    • The GPAI Code of Practice contains 87 measures across transparency, copyright, and safety chapters
    • Signing creates a presumption of AI Act conformity; non-signatories must demonstrate equivalent means
    • Confirmed full signatories represent approximately 78% of EU-deployed GPAI market by API volume
    • Systemic-risk designations (Chapter III) apply to models above 10^25 training FLOPs and carry the heaviest obligations
    • Non-signatory documentation requires deployer legal review to confirm equivalence, adding real procurement cost
    • Signatory status is now embedded in procurement scoring, fast-track approvals, contract templates, and insurance premiums

    Audit your technology stack

    This guide covers one topic. Your Technology Stack Audit scores your entire technology stack as one system, ranks what to fix first, and maps how your tools depend on each other. One-off €99.

    Audit my technology stack — €99