Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU publishes voluntary AI code as companies face August compliance deadline

Brussels has given OpenAI, Google, Meta and others weeks to sign up to guidance on transparency, copyright and systemic risk, or face tougher scrutiny under the AI Act from 2 August.

By , Technology Editor

Published

7 min read

The European Commission has placed the world's largest artificial intelligence companies on a tight summer timetable. On 10 July it published the final version of its voluntary Code of Practice for general-purpose AI models, giving providers such as OpenAI, Google and Meta a matter of weeks to decide whether to sign up or face stricter regulatory scrutiny when the AI Act's core obligations take effect on 2 August.

The code is not legally binding, but the Commission has made clear that adherence carries practical advantages. Thomas Regnier, a Commission spokesperson, told reporters that signatories would "benefit from more legal certainty and reduced administrative burden". Those that decline will need to demonstrate compliance with the AI Act through their own means, likely under closer examination from Brussels.

What the code requires

The document addresses three pillars the AI Act identifies for general-purpose model providers: transparency about training data and model capabilities, compliance with EU copyright law, and assessment and mitigation of systemic risks. The final text runs to dozens of pages and was shaped by 13 academic experts over nine months, producing four successive drafts discussed in plenaries and working groups with more than 1,000 registered participants.

Two requirements stand out. First, companies must "publish a summarised version" of the safety and security reports they file with regulators before putting a model on the market, a public transparency measure Parliament lawmakers had fought for. Second, the list of systemic risks that providers must evaluate now explicitly includes "risk to fundamental rights", wording that civil society groups had demanded and that earlier drafts had omitted.

Laura Lázaro Cabrera of the Center for Democracy and Technology called the fundamental rights inclusion "a positive step forward". The copyright section also survived industry pressure: it asks providers to put in place policies to respect rights holders' reservations under the EU's text and data mining exception, and to disclose how they comply.

Industry pushes back on burden and scope

The reaction from major US tech firms and their European lobby groups was immediate and critical. The Computer and Communications Industry Association (CCIA), whose members include Meta and Google, said the code "still imposes a disproportionate burden on AI providers". Boniface de Champris, senior policy manager at CCIA Europe, went further: "Without meaningful improvements, signatories remain at a disadvantage compared to non-signatories." He singled out "overly prescriptive" safety and security measures and a copyright section with "new disproportionate measures outside the Act's remit".

Google's spokesperson Mathilde Méchin struck a more measured tone, saying the company was "looking forward to reviewing the code and sharing our views". Meta did not issue a separate statement on publication day. The CCIA had previously called for a pause on the parts of the AI Act not yet implemented, specifically the obligations for deployers of high-risk AI systems that take effect next year.

Mistral breaks ranks as first signatory

French startup Mistral AI became the first company to announce it would sign the code on publication day. The decision is notable: Mistral has positioned itself as a European champion in foundation models and has lobbied for rules that do not entrench the advantages of better-resourced US incumbents. By signing early, it gains the legal certainty the Commission promises and may seek to shape how the code is interpreted in practice.

For the US giants, the calculation is more complex. OpenAI, Google and Meta each operate multiple general-purpose models that would fall under the code. Signing commits them to a common European baseline that goes beyond the AI Act's bare text in several areas, particularly on public transparency and fundamental rights risk assessment. Refusing to sign leaves them exposed to the Commission's investigative powers under Article 92 of the Act, which allows the executive to request information and conduct evaluations of systemic risks.

Parliament and civil society claim victories

The final code represents a partial win for the European Parliament and the campaign groups that shadowed the drafting. On 9 July, a cross-party group of MEPs expressed "great concern" about "the last-minute removal of key areas of the code of practice", citing public transparency of safety measures and the weakening of risk assessment provisions. The next day, both elements reappeared in strengthened form.

Aura Salla, a Finnish MEP from the European People's Party and a former Meta lobbyist, had warned ahead of publication that "the process for the code has so far not been well managed". Her intervention carried weight: as a conservative who once represented the industry, her criticism of the drafting process could not be dismissed as partisan. The Commission's Regnier, by contrast, described the process as "inclusive".

A drafting process that satisfied nobody

The nine-month exercise involved evening sessions to accommodate experts based in the United States and Canada, four working groups, and multiple plenary rounds. Yet both industry and civil society told reporters they felt their input had not been heard. Companies argued the guidance should not go beyond the AI Act's general direction; campaigners warned the rules were being watered down under intense lobbying.

This dynamic, where neither side feels heard, is familiar in Brussels digital policy. The AI Act itself was negotiated in 2023 amid similar tensions. The code of practice was always intended as a living document, updatable as technology and standards evolve. But the first version sets the baseline, and the bitterness of the drafting may make future revisions harder.

The August deadline and what follows

From 2 August, providers of general-purpose AI models placed on the EU market must comply with the AI Act's Article 53 obligations: maintain technical documentation, provide information to downstream providers, put in place a copyright policy, and publish a sufficiently detailed summary of training content. The code of practice is the Commission's recommended way to meet these requirements.

Companies that sign commit to the code's more detailed measures, including the systemic risk assessment methodology and the publication of summarised safety reports. They also agree to engage with the AI Office, the new body inside the Commission that will oversee enforcement. Non-signatories must be ready to prove their own compliance measures are equivalent, a higher evidential bar in practice.

Sources

  1. POLITICO

    politico.eu · 2025-07-10

People mentioned

  • Thomas Regnier

    European Commission spokesperson, European Commission

  • Boniface de Champris

    Senior policy manager, CCIA Europe

  • Laura Lázaro Cabrera

    Policy analyst, Center for Democracy and Technology

  • Aura Salla

    Member of the European Parliament, European Parliament

  • Mathilde Méchin

    Spokesperson, Google

Organisations

European Commission · European Parliament · CCIA Europe · Center for Democracy and Technology · OpenAI · Google

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.