The General-Purpose AI Code of Practice is a voluntary tool designed to help providers of GPAI models demonstrate how they meet specified EU AI Act obligations. It does not certify every downstream application using a signatory's model.

GPAI obligations began applying to relevant new models in August 2025. Commission enforcement powers began applying in August 2026, and the timetable contains later treatment for certain models already on the market. Verify the exact dates and transition under the amended law.

Enterprise buyers should use the Code to improve upstream evidence, then assess their own AI system and role.

GPAI model duties sit upstream of AI-system duties

A GPAI model is capable of performing a wide range of distinct tasks and can be integrated into many downstream systems. The model provider's obligations concern the model. A downstream provider or deployer assesses the application, intended purpose, data, users, outputs, and actions.

One model can support an internal writing assistant and a high-risk employment system. The Code does not assign those downstream classifications.

The final Code contains commitments addressing transparency and copyright for GPAI providers. A safety and security chapter applies to providers of GPAI models with systemic risk.

The Commission has also issued GPAI-scope guidelines and a public template for summaries of training content. The Code and guidelines perform different jobs. The guidelines express the Commission's interpretation of scope, while the Code offers a voluntary compliance route for covered duties.

Read the actual chapter and provider commitment relevant to the model. A summary badge cannot replace it.

Signatory status is evidence with a defined scope

Ask whether the exact model provider has signed the Code, which chapters and commitments apply, and which model versions are covered. Record the date and supporting material.

Non-signatory status does not by itself prove non-compliance. The provider must meet applicable legal duties through another supported approach. Signatory status also does not prove the enterprise's downstream retrieval, permissions, transparency, or human oversight.

Ask model providers for seven downstream inputs

  1. Exact provider, model, version, release date, and distribution method.
  2. Acceptable-use policy and prohibited applications.
  3. Capabilities, limitations, supported languages, modalities, and evaluation information.
  4. Input and output format, integration requirements, and known technical dependencies.
  5. Data-use, retention, copyright, and training-content information relevant to the service.
  6. Model change, deprecation, incident, and corrective-action notices.
  7. Systemic-risk documentation where applicable and available to the buyer's role.

Ask how the information can be incorporated into the downstream technical file and instructions. Protect confidential information while obtaining the evidence your duties require.

Skybridge binds each provider route to release evidence

Skybridge can route tasks through several model providers. That flexibility creates a governance obligation: every released Compsia system must name the route actually used for each material task.

The provider inventory should record model terms, regions, retention, documentation, and fallback behavior. The release test should identify the model and instruction version. If a fallback provider can receive the same data, it belongs in the data and legal path.

Current architecture places Skybridge in the system-integration and operation layer rather than training or placing its own GPAI model on the market. A material fine-tune, significant modification, distribution model, or branding change triggers a new role assessment.

Reassess when the model or route changes

Set triggers for a new model family, version, provider, fallback, modality, training method, context length, data term, acceptable-use policy, or safety notice. Decide which changes require renewed acceptance tests or customer notice.

Maintain performance evidence for the real task. Upstream model quality can change without a visible application-code change. The EU AI Act vendor checklist provides the wider supplier review.

The Code does not replace downstream model selection. Buyers still need task-specific evaluation across supported languages, source use, error classes, latency, cost, and failure behavior. A model can have strong upstream documentation and perform poorly on the operation the enterprise needs.

Build a controlled comparison using representative and appropriately authorized cases. Keep the application instructions, retrieval set, output format, and scoring method stable while comparing model routes. Record cases where a cheaper or faster model changes omission, unsupported assertion, refusal, or tool-choice behavior. Select the route for the defined result and risk, then preserve the evidence with the release.

Review provider documentation for information that changes the evaluation. A new acceptable-use restriction may rule out a task. A context or modality change may alter data exposure. A safety notice may require a test or temporary suspension. The operating owner needs a provider-notice path that reaches the release process.

Where a fallback model exists, evaluate it too. A continuity route that has never passed the acceptance corpus is an untested second system hiding behind the first.

GPAI Code questions

Is the GPAI Code mandatory?

The Code is a voluntary compliance tool. Applicable AI Act obligations remain legal duties for covered providers.

Does using a Code signatory make our AI system compliant?

No. Signatory evidence concerns defined GPAI provider commitments. The downstream system still needs its own classification, controls, and evidence.

Are all open-source models exempt?

The Act and Commission guidance contain conditions and limits for open-source treatment. Do not assume a universal exemption from the licence label alone.

Primary references

  1. Regulation (EU) 2024/1689, the Artificial Intelligence ActEUR-Lex
  2. Regulation (EU) 2026/1744, the 2026 AI OmnibusEUR-Lex
  3. AI Act regulatory framework and implementation timelineEuropean Commission
  4. General-Purpose AI Code of PracticeEuropean Commission

Continue reading: EU AI Act Provider vs Deployer: Assign the Right Role.