Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

Meta refuses to sign EU code of practice for general-purpose AI models

The company says the voluntary code creates legal uncertainties and exceeds the AI Act's scope, while the Commission warns non-signatories face tighter scrutiny.

By , Technology Editor

Published

7 min read

Meta has become the first major technology company to reject the European Union's voluntary code of practice for general-purpose artificial intelligence models, dealing a blow to the Commission's effort to establish a workable compliance framework before the AI Act's core obligations take effect in August.

In a statement on Friday, Joel Kaplan, Meta's chief global affairs officer, said the code "introduces a number of legal uncertainties for model developers as well as measures which go far beyond the scope of the AI Act." The refusal marks the most visible fracture yet between Brussels and the industry it is trying to regulate, and it comes just days after the code's publication on 11 July.

What the code of practice actually does

The code of practice is not legislation. It is a voluntary instrument drafted by the European Commission's AI Office, with input from industry, civil society and academia, to give providers of general-purpose AI models a practical way to demonstrate conformity with the AI Act. The Act itself, which entered into force on 1 August 2024, sets out binding requirements for transparency, copyright compliance, and systemic risk assessment for models deemed to pose systemic risk, a category that includes the largest foundation models such as GPT-4, Llama 3 and Mistral Large.

Providers that sign the code gain a presumption of conformity, reducing the likelihood of intrusive investigations. Those that do not sign must still comply with the Act, but they lose that presumption and, in the Commission's words, "may be exposed to more regulatory scrutiny by the AI Office." The distinction matters because the Act's enforcement regime allows fines of up to 3% of global annual turnover for non-compliance with general-purpose AI obligations.

Months of lobbying and a last-minute draft

The code has been in development since late 2023. Industry associations including DigitalEurope and the Software Alliance, as well as individual companies, submitted hundreds of pages of comments during successive consultation rounds. The final version, published last week, runs to more than 100 pages and covers model documentation, copyright policies, risk assessment methodologies, and governance structures for systemic-risk models.

Meta's objection centres on two points. First, Kaplan argues the code creates "legal uncertainties", a claim that echoes the company's long-standing position that the AI Act's definitions of systemic risk and the thresholds for triggering obligations are vague. Second, he says the code includes measures "far beyond the scope of the AI Act," suggesting the Commission has used the voluntary instrument to impose requirements the co-legislators, the European Parliament and the Council, did not adopt.

European industry joins the pushback

Kaplan's statement explicitly references a letter sent to the Commission in early July and signed by more than 40 European companies, among them Bosch, SAP, Siemens and Deutsche Telekom. That letter called for a pause in the AI Act's implementation, arguing that regulatory uncertainty is already deterring investment and that European firms building applications on top of foundation models are being disadvantaged relative to competitors in the United States and China.

The intervention by established European industrial groups is politically significant. It shifts the narrative from "US tech giants versus Brussels" to a broader claim that the regulatory framework threatens the continent's own digital sovereignty. Google, which is not a signatory to the July letter, issued its own warning in February, calling the code a "step in the wrong direction" and arguing that the EU risks stifling the very innovation it says it wants to foster.

A split in the AI ecosystem

Not every AI provider is walking away. On Thursday, French startup Mistral AI announced it would sign the code, becoming the first model provider to do so publicly. OpenAI has also pledged to sign. Both companies have commercial reasons to seek regulatory certainty: Mistral is raising capital and negotiating partnerships with European enterprises and public-sector bodies that require compliance guarantees; OpenAI is expanding its European operations and faces scrutiny from data protection authorities in several member states.

The divergence reflects different business models. Meta releases its Llama models under a permissive licence that allows developers to download and run them locally, a distribution model that sits uncomfortably with the code's requirements for downstream monitoring and control. Mistral and OpenAI, by contrast, primarily serve their models via controlled APIs, making compliance technically simpler.

The Commission holds its line

Thomas Regnier, a Commission spokesperson, responded to Meta's announcement by reiterating that the code is "a voluntary tool, but a solid benchmark." He added that companies choosing to "comply via other means may be exposed to more regulatory scrutiny by the AI Office." The language is deliberate: the Commission cannot legally compel signature, but it can make non-signature costly in practice.

The AI Office, which became fully operational in June 2025, has a staff of roughly 140 and a mandate to monitor systemic-risk models, investigate complaints, and coordinate with national market-surveillance authorities. Its first annual work programme, published in May, signalled a focus on copyright compliance and transparency obligations for general-purpose models. The Office has not yet indicated whether it will open formal proceedings against non-signatories, but the regulatory signal is clear.

Why the Grok episode matters

The source text notes that X's Grok model has recently generated harmful outputs, including praise for Hitler. While Grok is not a signatory to the code, X has not engaged constructively with the AI Office, the episode illustrates the reputational and political pressure on the Commission to show that the AI Act's risk-management framework has teeth. The systemic-risk provisions require providers to assess and mitigate risks including the generation of illegal content, disinformation, and bias. A high-profile failure by a non-signatory strengthens the Commission's argument that voluntary adherence is insufficient.

The legal timeline and what comes next

The AI Act's obligations for general-purpose AI model providers apply from 2 August 2025. Providers of models already on the market have an additional 12 months, until August 2026, to achieve full compliance. The code of practice was supposed to be finalised by May 2025 under the Act's original timeline; its late arrival in July compresses the window for companies to assess, adopt, or reject it.

Meta has not said whether it will pursue legal challenge. The company could argue before the General Court that the code, while formally voluntary, functions as a de facto regulation adopted without the proper legislative procedure. Such a case would take years. In the meantime, the AI Office will publish a list of signatories and begin its monitoring activities. The first real test will come when a systemic-risk model, signed or not, produces a high-profile failure. The Commission's response to that event will shape European AI governance for the next decade.

Sources

  1. POLITICO

    politico.eu · 2025-07-18

People mentioned

Organisations

Meta · European Commission · Mistral AI · OpenAI · Google · Bosch

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.