The EU publishes a voluntary code of practice to help companies follow its AI Act, including requiring developers to provide up-to-date AI feature documentation
digital-strategy.ec.europa.eu/en/ policies/... Yoshua Bengio / @yoshuabengio : All of us who drafted the Chapter are independent experts. With lots of useful input from industry, civil society, and academia, we have created a practical framework for streamlined but effective compliance. Thanks to everyone involved! — 3/3 @cdteu : We call on the Commission to refrain from pursuing a deregulation agenda and champion the proper enforcement and implementation of the AI Act and the wider EU #digital rulebook. @ec.europa.eu : General-purpose AI must be safe and transparent. — The Code of Practice is now available. — It is designed to help industry comply with the AI Act's rules on general-purpose AI, which will enter into application on 2 August — More info ↓ — europa.eu/! xFkbjC [image] Aída Ponce Del Castillo / @aida.follows.technology : No to simplification of EU digital laws — Weakening the AI Act would undermine accountability, the protection of society and workers and bring legal uncertainty — I have co-signed the letter led by @cdteu.bsky.social 👇🏼 [embedded post] Yoshua Bengio / @yoshuabengio : The Code of Practice is out. I co-wrote the Safety & Security Chapter, which is an implementation tool to help frontier AI companies comply with the EU AI Act in a lean but effective way. I am proud of the result! — 1/3 [image] Yoshua Bengio / @yoshuabengio : digital-strategy.ec.europa.eu/en/ policies/... The Code also has two other, separate Chapters (Copyright, Transparency). The Chapter I co-chaired (Safety & Security) is a compliance tool for the small number of frontier AI companies to whom the “Systemic Risk” obligations of the AI Act apply. — 2/3 Marietje Schaake / @marietjeschaake : The Code of Practice is out! The final result of months of drafting based on the AI Act and feedback from MEPs, Member State governments, civil society, the hundreds of people in the working groups, and AI companies, here ↘️ — digital-strategy.ec.europa.eu/en/ policies/... Mastodon: @eunews@mastodon.social : Everything tech giants will hate about the EU's new AI rules — The European Union is moving to force AI companies to be more transparent than ever, publishing a code of practice Thursday that will help tech giants prepare to comply with the EU's landmark AI Act. — https://arstechnica.com/... X: Markus Anderljung / @manderljung : What's next? The Commission and 27 Member States will formally decide on approval in coming weeks. Frontier AI companies can then choose whether to sign on - those who do can expect streamlined compliance and more trust from the AI Office. Mia Hoffmann / @mia_hoffmann_ : The final draft of the AI Act's code of practice for general-purpose AI models was published today! https://digital-strategy.ec.europa.eu/ ... I'll dig into it more over the coming days, but a few notes on background and what to expect next: Markus Anderljung / @manderljung : So what does the Safety & Security chapter do? Companies must have a Framework where they pre-define when risk is acceptable and keep risk to acceptable levels, via risk assessment and mitigation. Then they evidence their adherence to their Framework in a Model Report. Markus Anderljung / @manderljung : The EU's Code of Practice for General-Purpose AI is out. As one of the co-chairs who drafted the Safety & Security Chapter, focused on frontier AI, I'm proud of what we've put together. It's a lean but effective framework for frontier AI companies to comply with the AI Act. [image] Markus Anderljung / @manderljung : The challenge: the AI Act imposes requirements on providers of the most advanced models - like OpenAI, Anthropic, Google, Mistral, Meta. But these requirements are very high level. It says they should “assess and mitigate systemic risk”. But what does that mean? [image] Marietje Schaake / @marietjeschaake : The Code of Practice is out! the final result of months of drafting based on the AI Act, feedback from MEPs, MS govts, civil society, people in the working groups, and AI companies. The Code helps companies comply with the AI Act's legal obligations ↘️ https://digital-strategy.ec.europa.eu/ ... Shakeel / @shakeelhashim : Here's a neat way to compare the final draft to the previous version: https://draftable.com/... Shakeel / @shakeelhashim : Putting some stuff that jumps out at me in this thread. First: the list of “specified systemic risks”: [image] Luca Bertuzzi / @bertuzluca : NEW: The final draft of the AI Act's code of practice for general-purpose AI models is finally out. https://digital-strategy.ec.europa.eu/ ... LinkedIn: Sarah Andrew : I'm cautiously happy. The newest EU General-Purpose AI Code of Practice dropped today—a document that social and digital justice organisations poured … Adam Rendle : Guidance on how to comply with the copyright parts of the obligations on providers of general-purpose AI in the EU AI Act is now available. Topics covered are: … Forums: r/europe : Everything tech giants will hate about the EU's new AI rules | EU rules ask tech giants to publicly track how and when AI models go off the rails. r/technology : Everything tech giants will hate about the EU's new AI rules | EU rules ask tech giants to publicly track how and when AI models go off the rails
Context & Ripple Effects
The EU’s AI Act moved from a political agreement into an implementation problem for general-purpose model providers. A first draft of the Code had already outlined copyright and systemic-risk provisions; this version makes the compliance route more operational.
The code concentrates on frontier general-purpose AI providers, including companies such as OpenAI, Anthropic, Google, Mistral, and Meta. It turns the Act’s broad governance ambition into voluntary practices that may ease engagement with the AI Office for companies that adopt them.
First-order effects
- Frontier-model developers that sign the code must maintain current documentation of their AI features, adding a recurring governance task rather than a one-time filing.
- Signatories gain a defined path toward streamlined compliance and greater trust from the AI Office, while participation remains optional.
Second-order effects
- Providers will have to decide whether the reduced compliance friction and credibility of signing outweigh the operational burden of maintaining documentation and meeting the code’s other commitments.
- The code gives customers, partners, and downstream deployers a more consistent basis for assessing model-provider transparency, potentially making documented providers easier to procure.
Third-order effects
- If widely adopted, the code could make continuously maintained model documentation a baseline assurance artifact for general-purpose AI, extending the earlier finding that provider compliance was feasible into day-to-day operations.
- Voluntary codes may become a practical bridge between statutory AI rules and enforcement, but uneven provider participation would limit how uniform that governance layer becomes.
The trend: AI governance is shifting from high-level legal obligations toward operational evidence—documentation, risk practices, and auditable processes—for frontier model providers.