GPAI Code of Practice: Why It Matters When Picking an AI Tool
Most people choosing an AI writing tool never look past the model name and the price. That was defensible when there was nothing else to check. As of August 2026 there is something else to check, and it is a genuinely useful signal rather than another box-ticking exercise.
The EU AI Act’s rules for general-purpose AI, GPAI, providers came into force on August 2, 2025, with a one-year adjustment period built in. That period ended on August 2, 2026, which is when the European Commission’s AI Office gained the ability to actually enforce those rules: request technical documentation, evaluate a model directly, require corrective measures, and issue fines.
Once enforcement is real, the question of who signed up for accountability, and who did not, stops being abstract.
What The GPAI Rules Actually Ask For
Under Chapter V of the AI Act, providers of general-purpose AI models owe two baseline duties regardless of anything else: transparency toward the downstream deployers who build on their models, and respect for copyright in how the model was trained. Providers of the most capable, systemic-risk models owe more on top of that, including risk assessment and incident reporting.
None of that is optional. What is optional is how a provider proves it is meeting those duties.
Signing The Code Buys A Presumption, Not Immunity
The Commission published a GPAI Code of Practice as a voluntary compliance tool, and its core mechanism is a rebuttable presumption of conformity. A provider that signs the Code and follows it gets treated, in practice, as meeting the matching legal obligations, which is a meaningfully lighter administrative path than proving compliance from scratch.
A provider that does not sign is not automatically non-compliant. It just has to demonstrate compliance “by other adequate means” and be ready to explain that approach directly to regulators, without the shortcut the Code provides.
Two things worth being precise about, because vendors sometimes blur them in their own marketing. Signing the Code does not make a provider immune to fines: the AI Office can still act if it finds a real violation, though it is expected to account for Code commitments when deciding how large a fine should be. And the Code covers the GPAI-specific duties in Chapter V; it says nothing about, and does not substitute for, the separate transparency obligations under Article 50 that apply more broadly, which we cover in what changed under the EU AI Act on August 2, 2026.
Why Enforcement Power Changes What You Can Ask A Vendor
Before August 2, 2026, asking an AI vendor for its training data documentation or risk assessment was, practically, asking for a favor. There was no consequence for saying no beyond a bit of reputational friction. That changed once the AI Office gained the investigation and enforcement powers detailed in the Commission’s enforcement framework: the power to request documentation, evaluate a model, and fine up to the higher of 15 million euros or 3 percent of global turnover for the GPAI-specific obligations.
A provider that now has to be able to produce documentation for a regulator has a much easier time producing a version of it for you. The full breakdown of what those enforcement powers cover walks through the mechanics; the short version is that “we don’t share that” got a lot more expensive to say.
A Concrete Due-Diligence Question You Can Actually Ask
Here is the practical shift: whether an AI provider signed the GPAI Code of Practice, and whether it publishes the model documentation the Code expects, is now a specific, checkable fact rather than a vague reassurance. You do not need to evaluate a model’s training pipeline yourself. You need to ask one direct question and see whether the answer is a name and a document, or a paragraph about taking safety seriously.
That question sits well alongside the broader vendor-evaluation work in how to audit an AI vendor in 2026 and the more granular list in questions to ask an AI vendor about data. Add “did you sign the GPAI Code of Practice, and where is your model documentation” to that list. It is one of the few AI-vendor questions in 2026 that has a factual, verifiable answer instead of a marketing one.
A Wrivio Context for vendor due-diligence write-ups could say:
Rewrite this as a factual vendor evaluation note for an internal file. Keep every provider name, product name, date, and specific claim exactly as written. Do not soften a “did not answer” into anything that reads as reassurance, and do not add a compliance conclusion I have not actually reached.
Press Ctrl+Shift+Space, paste your notes, and check the diff before filing them. The failure mode worth watching for is a rewrite that turns “vendor declined to confirm” into something gentler, which quietly changes what your file actually documents.
Wrivio’s own cloud engine is proxied through our backend specifically so the underlying provider’s key never reaches your device, and Local mode goes further: it runs entirely on your machine and makes zero network calls during a rewrite, which is a different, stronger answer to “where does my text go” than any vendor documentation question can give you.
Common Questions
Does signing the GPAI Code of Practice mean a provider cannot be fined?
No. It gives a rebuttable presumption of conformity, which the AI Office is expected to weigh favorably, but it does not make a provider immune from enforcement if a real violation is found.
When could the AI Office actually start fining GPAI providers?
From August 2, 2026, when the one-year adjustment period after the GPAI rules’ August 2025 entry into force ended and enforcement powers entered into application.
What are the maximum fines for GPAI obligations?
The higher of 15 million euros or 3 percent of worldwide annual turnover for the GPAI-specific duties under Chapter V.
What should I actually ask an AI vendor because of this?
Whether they signed the GPAI Code of Practice and where their model documentation is published, since both are now specific, checkable facts rather than general reassurances.
Where can I read more about the enforcement mechanism itself?
The Commission’s enforcement policy page and the Chapter V enforcement explainer are the primary sources for how the AI Office exercises these powers.
Download Wrivio for Windows and choose Local mode when the text you are rewriting should never leave your machine, vendor documentation aside.
Read Next
California's No Robo Bosses Act: What SB 947 Actually Requires
SB 947 would bar California employers from firing workers on an algorithm's word alone. What it covers, what it does not, and the deadline that matters now.
New AI Disclosure Laws in 2026: A Simple Way to Sort Them
California, New York, and the EU each added AI disclosure duties in 2026. Here is a three-question test to tell which ones actually apply to your work.
EU AI Act Text Labeling Rules: Who Article 50 Actually Covers
Article 50 requires labeling AI-generated text in some cases, not all. Here is exactly which published text needs it, and which everyday drafting does not.
How to Tell a Client You Used AI on Their Work
A field-tested way to tell a client you used AI on their deliverable that leads with your judgment and answers the confidentiality question directly.
This article is filed underPrivacy & Compliance, which has 85 articles.