Industry Analysis 7 min read

GPAI Code of Practice: OpenAI, Microsoft, Google, and Anthropic Sign On

26 major AI providers have signed the EU's voluntary Code of Practice for general-purpose AI. Who's in, who's out, and what signing actually means for compliance.

By Dr. Marcus Weber · Published

Industry Alignment with EU Rules

In August 2025, 26 major AI providers signed the EU's General-Purpose AI (GPAI) Code of Practice—a voluntary framework demonstrating compliance with AI Act obligations. By early 2026, the signatory list includes most leading AI labs.

Notable Signatories

  • OpenAI – GPT-4, GPT-5, DALL-E, Codex
  • Microsoft – Azure OpenAI Service, Copilot infrastructure
  • Google DeepMind – Gemini, PaLM
  • Anthropic – Claude models
  • Amazon – Bedrock, Titan models
  • Mistral AI – European foundation model provider
  • Stability AI – Stable Diffusion
  • Cohere – Enterprise language models
  • Plus 18 additional providers

Notable Non-Signatories

Meta Platforms has notably refused to sign, citing "legal uncertainties" beyond the AI Act's scope. Meta's Llama models remain subject to mandatory AI Act obligations but won't benefit from the Code's presumption of compliance. The EU has opened a formal investigation into Meta's AI practices.

xAI (Elon Musk's company) signed only the Safety & Security chapter, stating it will use "alternative means" for transparency and copyright compliance.

What Signing the Code Means

  • Presumption of Compliance: Following the Code demonstrates good-faith adherence to AI Act obligations
  • Regulatory Clarity: Clear expectations reduce legal uncertainty
  • Collaborative Period: Until August 2026, the AI Office works constructively with signatories
  • Reputational Benefit: Public commitment to responsible AI practices

The Three Pillars of the Code

ChapterKey Commitments
TransparencyComprehensive model documentation, training data summaries, capability disclosures
CopyrightRespect EU Copyright Directive, implement opt-out mechanisms, no demonstrably pirated training data
Safety & SecurityRisk assessments, adversarial testing, incident reporting, cybersecurity (systemic risk models only)

Enforcement Coming August 2026

The grace period ends August 2, 2026. After that, non-compliant GPAI providers face fines up to 15 million euros or 3% of global turnover. Code signatories have a clear advantage in demonstrating compliance.