Short answer. The EU AI Act General-Purpose AI Code of Practice is a voluntary rulebook, published on 10 July 2025, that shows providers of general-purpose AI models how to meet Articles 53 and 55 of the AI Act. It has 3 chapters: Transparency, Copyright, and Safety and Security. 26 organisations signed the full Code, including OpenAI, Google, Anthropic, Microsoft, and Mistral AI. Signing gives a provider a presumption of compliance and a lighter administrative check from the EU AI Office.
The Code turns two dense AI Act articles into concrete measures a model provider can adopt today. It governs the models behind the tools most banks already use. 94% of Ableneo’s 2025 production projects run on large language models, and almost all of those models are general-purpose.
Three things change in practice:
For a provider, adopting the Code is the fastest route to demonstrate conformity. For every company downstream, it means the documentation you receive from a model vendor is now more predictable.
Articles 53 and 55 have applied since 2 August 2025. From 2 August 2026 the AI Office can enforce them, with fines up to 3% of global annual turnover or EUR 15 million for a general-purpose AI provider, whichever is higher. Banks and insurers rarely build foundation models, so they are almost always deployers or downstream providers, not the entities the Code binds directly.
The relevance is second order and still real. The Code sets the quality of the documentation a regulated firm can demand from its model vendor, and that documentation feeds the firm’s own high-risk obligations under the Act and its ICT and model risk controls under DORA and existing supervisory guidance.
Timing matters for procurement. Models placed on the EU market before 2 August 2025 have until 2 August 2027 to comply, so a bank may run a mix of documented and not-yet-documented models for two years. A vendor’s decision to sign the Code is one signal of how quickly its documentation will be ready.
The GPAI Code of Practice, published 10 July 2025, shows model providers how to meet Articles 53 and 55 of the EU AI Act.
The Code was drafted by independent experts in a multi-stakeholder process run by the AI Office, then endorsed by the European Commission and the AI Board. It is organised into three chapters. Transparency and Copyright apply to every provider of a general-purpose AI model. The Transparency chapter defines a Model Documentation Form: a single file describing the model’s capabilities, limitations, training process, and intended uses, kept current and shared with the AI Office and with downstream providers on request. The Copyright chapter asks providers to maintain a copyright policy, honour machine-readable opt-outs from text and data mining, and publish a summary of training content.
The Safety and Security chapter applies only to models with systemic risk. Those providers run model evaluations, track serious incidents, and report them to the AI Office. Providers of free and open-source models are exempt from the documentation duties unless their model carries systemic risk.
No. The Code is voluntary, and a provider can prove compliance with Articles 53 and 55 by other means. The incentive to sign is practical. The European Commission and the AI Board confirmed the Code as an adequate voluntary tool, so a signatory is presumed to comply with the corresponding legal duties. That presumption lowers the administrative burden and gives more legal certainty than assembling a bespoke compliance case. A provider that does not sign still has to meet the same articles, without the safe harbour.
26 organisations signed the full Code, including Amazon, Anthropic, Cohere, Google, IBM, Microsoft, Mistral AI, and OpenAI. Meta declined to sign, citing legal uncertainty. xAI signed only the Safety and Security chapter. For a bank, the signatory list is a procurement signal. If the model behind your assistant or your document-processing pipeline comes from a signatory, the standard documentation and the training-content summary should already exist and be available to you.
Most financial firms in Central Europe consume general-purpose models through vendors and cloud platforms. They are deployers, and often downstream providers when they wrap a model into a customer-facing system. The Code places no new duties on them. It changes what they can expect and what they should ask for.
Under Article 53(1)(b), a model provider must give downstream providers the documentation they need to understand the model’s capabilities and limits, within 14 days of a request. A bank should fold that entitlement into vendor contracts and AI use-case reviews, so the model documentation, the training-content summary, and the known limitations land in the same file that supports the bank’s own high-risk assessment.
Many banking AI systems, including credit scoring, fraud detection, and some customer-facing decisions, fall into the high-risk tier whose core obligations apply from 2 August 2026. A high-risk deployer needs to document the AI it operates, monitor performance in production, and keep humans in control. The GPAI Code feeds that work from the supply side. The provider documentation it standardises is a direct input to the deployer’s technical file, risk assessment, and monitoring plan. Read the Code next to Article 53, the high-risk requirements, and DORA’s ICT risk rules, not on its own.
Ableneo has shipped 34 production AI projects across banking, insurance, and other regulated sectors, and 94% of them run on large language models, so the flow of model documentation from provider to deployer is a working part of our delivery, not a theory. We map each client’s AI use cases to the right AI Act role, provider, deployer, or downstream provider, and turn vendor documentation into governance a supervisor can inspect. Our AI transformation FAQ sets out how these obligations connect. Regulated production is the standard we hold every model to.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.