GPAI Code of Practice — the EU's voluntary compliance pathway for general-purpose AI providers, and its corrected signatory list
Europe (applies to providers placing models on the EU market globally) — signatories are US, EU and UK companies
Content
The July 2026 regulatory scan listed the GPAI Code as a unit candidate and named a signatory list that is wrong in two ways — it included Meta, which refused, and it omitted Amazon and sixteen others. This unit closes the gap with the Commission’s own roster and corrects the timeline claim: there is no GPAI harmonised-standard track, so the Code is not a stopgap for missing standards — it is the pathway.
Headline. The Code is unamended since 10 July 2025, declared adequate by Commission Opinion and AI Board assessment on 1 August 2025; it has 21 signatories plus xAI (Safety and Security chapter only); Meta is the one notable refuser; and what changed in 2026 is machinery — a Signatory Taskforce chaired by the AI Office, and the start of GPAI enforcement on 2 August 2026.
Structure and what each chapter discharges
Verbatim from the Commission’s code page: the Transparency and Copyright chapters “offer all providers of general-purpose AI models a way to demonstrate compliance with their obligations under Article 53 AI Act”; the Safety and Security chapter “is only relevant to the small number of providers of the most advanced models, those that are subject to the AI Act’s obligations for providers of general-purpose AI models with systemic risk under Article 55”. The Transparency chapter is accompanied by a Model Documentation Form.
Signing is by form, emailed to the AI Office (EU-AIOFFICE-CODE-SIGNATURES@ec.europa.eu). Signing is voluntary, and the Commission frames the benefit as administrative: signing “will reduce their administrative burden and give them more legal certainty and trust than if they proved compliance through other methods”. On non-signatories, the Commission spokesperson’s line is blunt: “If a provider decides not to sign the Code of Practice, it will have to demonstrate other means of compliance.” The often-repeated claim that signing earns a “rebuttable presumption of conformity” is law-firm gloss, not Commission language — treat it as secondary-source characterisation.
Signatories — the corrected list
The Commission page (last updated 31 July 2026) names 21 signatories: AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow, WRITER. In addition, verbatim: “xAI signed up to the Safety and Security Chapter; this means that it will have to demonstrate compliance with the AI Act’s obligations concerning transparency and copyright via alternative adequate means.”
Meta is not a signatory and has not reversed. Its refusal was announced on 18 July 2025 (“We have carefully reviewed the European Commission’s Code of Practice for general-purpose AI (GPAI) models and Meta won’t be signing it”, attributed to Joel Kaplan); Euronews reported on 23 July 2025 that Meta was “the first, and so far remains the only company to say it will not sign”. The July scan’s list — which included Meta and omitted Amazon, IBM, Cohere, ServiceNow, WRITER and others — should not be reused.
2026: machinery, not text
The Signatory Taskforce, chaired by the AI Office, exists to “facilitate a coherent application of the Code”, with a published Vademecum. Four meetings: 30 January 2026 (first), 13 March 2026 (copyright chapter), 27 March 2026 (safety and security chapter), 17 July 2026 (post-market usage analysis under Measure 3.5; treatment of “marginal-risk” clauses — the AI Office “highlighted that such clauses could only be invoked in exceptional circumstances and under appropriate evidentiary and procedural safeguards”; and Measure 1.3(4) on notifying rightsholders about web crawlers and robots.txt).
Enforcement started 2 August 2026. GPAI penalties run to €15m or 3% of worldwide annual turnover; prohibited-practice penalties to €35m or 7%. As of 14 September 2026 there were no formal investigations and no fines, and the AI Office’s own FAQ describes “technical compliance dialogues” as its preferred initial instrument, with formal powers held for unresolved concerns.
The standards point the July scan got wrong
The current Commission standardisation request is C(2025) 3871, replacing C(2023) 3215, covering ten areas (risk management, data governance, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment). prEN 18286 (AI Quality Management System) was the first draft harmonised standard to enter public enquiry, on 30 October 2025; independent tracking on 29 June 2026 records EN 18286 at formal-vote approval, several drafts at enquiry, a CEN-CENELEC Q4 2026 availability target, an amended request running to 28 February 2027, and zero standards cited in the Official Journal.
But these are harmonised standards for high-risk AI systems. There is no harmonised-standard track for Chapter V / GPAI obligations. The July scan’s “voluntary compliance pathway… until European standards come into effect (expected August 2027 or later)” is doubly wrong: the August 2027 date conflates the old high-risk application date (now 2 December 2027) with standards delivery, and no GPAI standard is coming at all. The Code is the durable pathway, not a stopgap.
Second code, easily confused
A separate instrument — the Code of Practice on Transparency of AI-Generated Content — was endorsed by the Commission and AI Board on 9 July 2026 and signed by more than 180 organisations (later counts: about 190). It implements the Article 50 marking obligations that apply from 2 August 2026; the Omnibus replaced its adequacy procedure with a single Commission adequacy assessment after consulting the AI Board. Do not conflate the two codes: one governs model providers’ compliance with Articles 53-55, the other governs machine-readable marking of AI-generated outputs under Article 50.
Agritech relevance
Most European agritech vendors are deployers, not GPAI providers: the Code reaches them indirectly, through their model suppliers’ transparency, documentation and copyright obligations. The chapters that matter downstream are Transparency (training-data summaries and model documentation) and Copyright (training-data sourcing), because they determine what an agritech vendor can know about the model it builds on. No agritech deployer compliance activity under Articles 53-55 was found (G-432) — unsurprising, since GPAI providers are the addressees.
What this unit is doing in the taxonomy
Anchors the provider-side compliance pathway of the EU regulatory layer — the route that shapes the models European agritech AI is built on. Distinguishes from:
- EU AI Act agrifood implications (
units/eu-ai-act-agrifood-implications.md) — the systems-side regime; this unit is the models-side pathway. - European AI Office governance architecture (
units/european-ai-office-governance-architecture.md) — the body that chairs the Taskforce and enforces the Code. - Machinery Regulation route (
units/eu-machinery-regulation-agricultural-ai.md) — an entirely different compliance path, for product-embedded AI.
Why it matters for talks
- The signatory list is a usable fact — 21 companies plus xAI, with Meta the one refuser, and the Commission’s own line about demonstrating compliance by other means.
- The “no GPAI standard” correction is the talk-grade insight. Anyone repeating “the Code is temporary until standards land” is wrong on two counts; the Code is the operative pathway for models.
- Technical compliance dialogues over fines is how EU AI enforcement actually starts in practice — a useful counterweight to penalty-structure scare figures.
- Two codes, two jobs (model providers vs AI-generated content marking) is worth stating explicitly, because the corpus and most commentary run them together.
- For agrifood, the Code is about what the model supplier must disclose — the practical lever a farm-data-cooperative or a farm advisory service has over the models it adopts.
Critical context
- Textbook caveat: the Code is voluntary, and non-signatories remain fully bound by Articles 53-55 with an alternative-means burden that is unspecified in practice.
- The presumption-of-conformity framing is commentary, not Commission text.
- No GPAI harmonised standard exists or is scheduled; available standards work is high-risk-only.
- Headcount, budget and enforcement statistics for the AI Office are not published consistently (
units/european-ai-office-governance-architecture.md). - Agritech’s exposure is indirect and largely undocumented; the corpus should not assert agritech Code compliance activity without a source.