Last Updated: 16 November 2024

The first draft of the "General-Purpose AI Code of Practice" was released by the European Union to establish clear rules for general-purpose AI models. The EU is inviting feedback until November 28, 2024. This draft works in tandem with the AI Act, which came into effect in August 2024, laying the groundwork for transparency and accountability in AI development.
The AI Act is the first comprehensive legal framework on AI, addressing risks linked to AI systems and aiming to ensure trustworthy AI development across Europe.
Officially known as Regulation (EU) 2024/1689, the AI Act provides clear guidelines for AI developers and users. It aims to reduce risks while keeping administrative and financial burdens low, especially for small and medium-sized enterprises (SMEs).
The AI Act is part of a wider initiative to ensure ethical and responsible use of AI across Europe. This includes the AI Innovation Package and the Coordi
The development of this Code has involved collaboration from industry, academia, and civil society, with the European AI Office facilitating the drafting process. The draft also considered international approaches. Four specialized working groups were established, each focusing on different aspects of AI governance and risk management:
This draft aims to stay relevant by adapting to rapid technological changes. It aligns with existing EU laws, such as the Charter of Fundamental Rights of the European Union, and considers international approaches to address AI-related risks effectively.
The draft has several key objectives: clarifying how providers of general-purpose AI models can comply with regulations, ensuring everyone in the AI value chain understands their responsibilities, maintaining copyright compliance, and continuously assessing systemic risks. The Code aims to guide AI providers in meeting the AI Act's requirements, including transparency and risk management, ensuring seamless integration of AI models into products.
The draft also emphasizes copyright compliance, particularly in using copyrighted material to train AI models. Transparency measures require providing details about the web crawlers used and ensuring that GPAI providers have a direct point of contact for rights holders to address issues quickly
A key feature of the draft is its taxonomy of systemic risks—a classification of different types and sources of risks, including cybersecurity threats, biological hazards, large-scale disinformation, and loss of control over autonomous AI models. Given the rapid evolution of AI, this taxonomy will be updated regularly to stay relevant.
For AI models identified with systemic risks, the draft requires robust safety and security frameworks (SSFs). These frameworks include measures and Key Performance Indicators (KPIs) to ensure risks are effectively identified, analyzed, and managed throughout the AI model's lifecycle.
The draft introduces a “Safety and Security Framework” (SSF), requiring AI developers to forecast and mitigate systemic risks, including estimating when a model may develop "dangerous capabilities." The Chairs and Vice-Chairs have included open questions to highlight areas that need further progress in the SSF. It also encourages collaboration with independent experts, particularly for models posing significant systemic risks.
The AI Act takes a risk-based approach, categorizing AI systems into four levels: unacceptable risk, high risk, limited risk, and minimal or no risk.
The EU AI Act requires that the final version of this Code be ready by May 1, 2025, with the drafting process concluding after four rounds in April 2025. Transparency requirements for general-purpose AI makers will take effect on August 1, 2025. For powerful AI models with systemic risks, comprehensive risk assessments will be needed starting August 1, 2027.
The draft Code assumes there will only be a small number of GPAI makers with systemic risks, but it notes that future versions may need significant changes if this assumption turns out to be wrong. If more models are found to carry systemic risks, a more detailed system of measures could be added.
The current draft is a “high-level drafting plan”, outlining principles and objectives without going into too much detail. As the process continues, industry feedback will play a key role in shaping specific measures and KPIs. Stakeholders are invited to share their thoughts and help refine the document by providing feedback until November 28, 2024.
The collaborative input from stakeholders will help create a regulatory framework that not only encourages innovation but also keeps society safe from the risks of AI technology.
The EU’s Code of Practice for general-purpose AI aims to set a global benchmark for responsible AI development by focusing on transparency, risk management, and copyright compliance. The Code will also provide notable exemptions for providers of open-source models, following the AI Act.
While there is still a lot of detail to work out, the draft highlights the EU’s commitment to building a regulatory environment that supports innovation, respects fundamental rights, and ensures consumer protection. The EU’s approach is to clarify complex issues and provide enough context so that stakeholders can understand the implications and make their own informed decisions—this is a different approach compared to many traditional regulatory methods.