{"slug": "eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act", "title": "EU GPAI Code of Practice: What Signatories Commit to Under the AI Act", "summary": "The European Union's voluntary General-Purpose AI Code of Practice, finalized in July 2025, provides a framework for providers to support compliance with the EU AI Act, covering transparency, copyright, and safety and security. Major companies including Amazon, Google, Microsoft, OpenAI, and Anthropic are signatories, but official EU materials do not substantiate claims of nearly 190 signatories, with early reports indicating a smaller group. The code is a governance signal, not a substitute for thorough due diligence by enterprise buyers.", "body_md": "The European Union's voluntary [ General-Purpose AI Code of Practice](https://scalevise.com/resources/gpai-compliance-2026-documentation-ai-office-sandbox/) gives providers of general-purpose AI models a practical framework for supporting compliance with the EU AI Act. Finalised in July 2025, the code addresses transparency, copyright, and safety and security. Its public signatory list includes major AI and technology companies, but official EU material does not support claims that roughly 190 organisations have signed the GPAI code.\n\nThe distinction matters for companies assessing AI suppliers. Signing the code can signal engagement with the EU's emerging governance expectations, but it is not a substitute for examining a provider's specific commitments, documentation, and product-level controls. The European Commission describes the code as a voluntary instrument, and its [official GPAI Code of Practice page](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai) states that the signatory process and public information continue to be updated.\n\nThe code is designed for providers of general-purpose AI models, a category that can include models used across multiple downstream applications. Rather than creating a separate legal regime, it is intended to help providers demonstrate how they can meet relevant [AI Act obligations](https://scalevise.com/resources/eu-ai-act-2026/).\n\nIts three chapters cover different aspects of provider responsibility:\n\n| Code chapter | Primary focus | Why it matters to AI buyers |\n|---|---|---|\n| Transparency | Provider information and documentation | Helps buyers assess whether a model provider can supply information needed for downstream use. |\n| Copyright | Copyright-related provider commitments | Relevant to procurement reviews involving training-data and intellectual-property governance. |\n| Safety and security | Risk management for the most capable models | Relevant when evaluating higher-risk model deployments and supplier assurance. |\n\nSigning is not necessarily all-or-nothing across the code's chapters. The available information notes that xAI signed only the Safety and Security chapter. That detail is important because a company name on a signatory list alone does not establish identical commitments across providers.\n\nPublic EU materials identify prominent signatories including Amazon, Aleph Alpha, Almawave, Anthropic, Google, IBM, Microsoft, OpenAI, and Mistral AI. The Commission also makes clear that additional providers can join and that the list evolves over time.\n\nHowever, the official sources cited for the GPAI code do not substantiate a total near 190 signatories. Early public reporting and EU communications described a substantially smaller group, often as more than 23 providers. A reliable reading of the public record is therefore that the code has attracted notable participation and remains open to further signatories, not that hundreds of organisations are confirmed participants.\n\nFor [procurement and compliance teams](https://scalevise.com/resources/eu-ai-compliance-check-2026/), the count is less useful than the scope of a supplier's participation. A provider's adherence to one chapter, several chapters, or the full code can affect the evidence available for vendor assessments. It can also indicate how actively the provider is preparing for the AI Act's requirements.\n\nThe GPAI code is a useful governance signal, but it should be treated as one input in a broader due-diligence process. Enterprise buyers still need to assess the particular model, intended use case, contractual terms, available documentation, and internal controls.\n\nIn practice, teams evaluating an AI provider can use code participation to frame more specific questions:\n\nThis approach avoids turning a voluntary signature into a blanket assurance of legal compliance or operational suitability. It also reflects the code's purpose: supporting providers as they work to comply with the AI Act, rather than replacing the underlying obligations.\n\nOrganizations integrating general-purpose AI into regulated or business-critical workflows can work with Scalevise on [ AI governance, architecture, and implementation](https://scalevise.com/resources/ai-governance/) that connect supplier evaluation with practical deployment controls.\n\n**What is the EU GPAI Code of Practice?**\n\nThe General-Purpose AI Code of Practice is a voluntary EU instrument intended to help providers of general-purpose AI models support compliance with the AI Act. It covers transparency, copyright, and safety and security.\n\n**Which companies have signed the GPAI Code of Practice?**\n\nPublic EU information lists companies including Amazon, Aleph Alpha, Almawave, Anthropic, Google, IBM, Microsoft, OpenAI, and Mistral AI. The Commission says the signatory process and list continue to be updated.\n\n**Have 190 organisations signed the EU GPAI Code of Practice?**\n\nOfficial EU sources for the GPAI code do not support that figure. Public material has described a substantially smaller, growing group of providers, including early references to more than 23 providers.\n\n**Does every signatory commit to all three GPAI Code chapters?**\n\nNo. Participation can differ by chapter. Available information notes that xAI signed the Safety and Security chapter only.\n\nThe EU GPAI Code of Practice is a meaningful voluntary compliance framework for general-purpose AI providers, particularly because it connects transparency, copyright, and safety commitments to the AI Act. Its signatory roster is important, but buyers should verify each provider's specific chapter participation and supporting documentation rather than relying on an unsupported headline total.", "url": "https://wpnews.pro/news/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act", "canonical_source": "https://dev.to/alifar/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act-1006", "published_at": "2026-08-04 06:50:30+00:00", "updated_at": "2026-08-04 07:11:31.219578+00:00", "lang": "en", "topics": ["ai-policy"], "entities": ["European Union", "Amazon", "Google", "Microsoft", "OpenAI", "Anthropic", "Mistral AI", "IBM"], "alternates": {"html": "https://wpnews.pro/news/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act", "markdown": "https://wpnews.pro/news/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act.md", "text": "https://wpnews.pro/news/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act.txt", "jsonld": "https://wpnews.pro/news/eu-gpai-code-of-practice-what-signatories-commit-to-under-the-ai-act.jsonld"}}