Skip to content

The Code of Conduct for AI Developers: Guide to the EU AI Act

At a glance: The EU Code of Conduct for AI developers governs documentation, copyright protection and security standards. The new rules take effect as of August 2, 2025, with enforcement beginning one year later. Older models have until August 2, 2027 to achieve compliance.

The EU has adopted a Code of Conduct for artificial intelligence developers, which takes effect on August 2, 2025. The Code provides a comprehensive framework for meeting the requirements of the EU AI Act – with a transitional period until August 2026 for regulatory enforcement measures.

The Code of Conduct provides developers of general-purpose AI (GPAI) models with a proven framework to meet the strict requirements of the EU AI Act. Although compliance with the Code is voluntary, providers may also use alternative compliance methods.

The key obligations span three main areas: First, signatories must maintain comprehensive, up-to-date documentation for each GPAI model – with the exception of free open-source models without systemic risk. This documentation follows standardized forms and must be securely retained for ten years.

Second, the Code strictly regulates copyright protection. Developers must establish robust policies that respect EU copyright laws and require that web crawling data is legally accessible. Technical protective measures are intended to minimize the generation of content from protected works, and terms and conditions must prohibit unauthorized use.

Third, the Code commits AI model developers with systemic risks to comprehensive security measures. They must develop an innovative security and safety framework that defines evaluation triggers, risk categories, mitigation strategies and organizational accountability. Systemic risks are identified through structured processes such as inventories, scenario analyses and expert consultations and analyzed with rigorous evaluation methods including simulations and adversarial testing.

The timeline provides a workable transition period: all new models as of August 2, 2025 must comply, but regulatory enforcement measures do not begin until one year later. For models published before August 2, 2025, a transition period applies until August 2, 2027.

Share on: