Regulators are moving from debating abstract risk toward thresholds they can actually measure, audit, and enforce.
From principles to paperwork
The European Union’s General-Purpose AI Code of Practice is a voluntary route for providers to demonstrate compliance with AI Act obligations. Its three chapters cover transparency, copyright, and safety and security.
The practical shift is significant. Policy debates often revolve around broad ideas such as systemic risk. Compliance mechanisms turn those ideas into model documentation, safety frameworks, testing records, and named responsibilities.
What providers may have to surface
The Commission’s guidance for general-purpose model providers lists notifications for models with systemic risk, serious-incident reports, safety and security frameworks, model reports, and public summaries of training content among the relevant documents.
Compute remains important because it can help classify obligations and compare development efforts, but it is only one observable input. Regulators also need evidence about capability evaluations, mitigations, incidents, and how a deployed system actually behaves.
The implementation era
For builders, the near-term design opportunity is traceability: systems that preserve evaluation results, model lineage, incident context, and approval history without forcing teams to reconstruct them after the fact.
Read it for yourself.
Every source used in this dispatch is linked directly. Open the original material, inspect the claim, and draw your own conclusion.
- 01Primary source · July 10, 2025The General-Purpose AI Code of PracticeEuropean Commission
- 02Primary source · Updated April 28, 2026Guidelines for providers of general-purpose AI modelsEuropean Commission
Plain-language summary of European Commission materials, not legal advice. Readers should consult the linked official guidance for obligations applying to a specific model or organization.