GPAI Code of Practice: OpenAI, Microsoft, Google, and Anthropic Sign On
26 major AI providers have signed the EU's voluntary Code of Practice for general-purpose AI. Who's in, who's out, and what signing actually means for compliance.
Industry Alignment with EU Rules
In August 2025, 26 major AI providers signed the EU's General-Purpose AI (GPAI) Code of Practice—a voluntary framework demonstrating compliance with AI Act obligations. By early 2026, the signatory list includes most leading AI labs.
Notable Signatories
- OpenAI – GPT-4, GPT-5, DALL-E, Codex
- Microsoft – Azure OpenAI Service, Copilot infrastructure
- Google DeepMind – Gemini, PaLM
- Anthropic – Claude models
- Amazon – Bedrock, Titan models
- Mistral AI – European foundation model provider
- Stability AI – Stable Diffusion
- Cohere – Enterprise language models
- Plus 18 additional providers
Notable Non-Signatories
Meta Platforms has notably refused to sign, citing "legal uncertainties" beyond the AI Act's scope. Meta's Llama models remain subject to mandatory AI Act obligations but won't benefit from the Code's presumption of compliance. The EU has opened a formal investigation into Meta's AI practices.
xAI (Elon Musk's company) signed only the Safety & Security chapter, stating it will use "alternative means" for transparency and copyright compliance.
What Signing the Code Means
- Presumption of Compliance: Following the Code demonstrates good-faith adherence to AI Act obligations
- Regulatory Clarity: Clear expectations reduce legal uncertainty
- Collaborative Period: Until August 2026, the AI Office works constructively with signatories
- Reputational Benefit: Public commitment to responsible AI practices
The Three Pillars of the Code
| Chapter | Key Commitments |
|---|---|
| Transparency | Comprehensive model documentation, training data summaries, capability disclosures |
| Copyright | Respect EU Copyright Directive, implement opt-out mechanisms, no demonstrably pirated training data |
| Safety & Security | Risk assessments, adversarial testing, incident reporting, cybersecurity (systemic risk models only) |
Enforcement Coming August 2026
The grace period ends August 2, 2026. After that, non-compliant GPAI providers face fines up to 15 million euros or 3% of global turnover. Code signatories have a clear advantage in demonstrating compliance.