The European Commission has published the final version of the General-Purpose AI Code of Practice, a voluntary tool developed by 13 independent experts, with input from over 1,000 stakeholders. It aims to support AI transparency, copyright, safety, and security.
The Code is designed to help the AI industry comply with the EU AI Act’s rules on general-purpose AI, which will enter into force on 2 August 2025. These rules will become enforceable by the AI Office of the Commission one year later for new models, and two years later for existing models.
The General-Purpose AI Code of Practice consists of three chapters: Transparency, Copyright, and Safety and Security.
The European Commission notes that some general-purpose AI models could carry systemic risks, such as risks to fundamental rights and safety. These include lowering barriers to the development of chemical or biological weapons or the risk of losing control over a model. The AI Act requires model providers to assess and mitigate these systemic risks, and the safety and security chapter of the new Code sets out relevant practices for systemic risk management.
The Code includes the following key AI security management requirements:
Adoption of a security framework
- Providers must adopt and implement a safety and security framework, tailored to the AI model’s risks.
- The framework must cover the entire lifecycle of the model (development, deployment, and post-market).
Systemic risk identification and assessment
- Systemic risks (those with wide-scale or long-term potential impact) must be identified and assessed.
- Assessment includes threat modelling, model evaluation, scenario testing, and risk estimation.
Security goals definition
- Providers must define clear security goals, including the types of threat actors (e.g. non-state actors, insider threats) their security mitigations are designed to defend against.
Implementation of security mitigations
- Security measures must be appropriate to the model’s capabilities, and deployment context and may be staged as model capabilities grow.
- Providers may deviate from listed security controls but must justify equivalence of protection.
- Security mitigations include controls such as: infrastructure hardening, access controls, monitoring and auditing systems, and secure model deployment practices.
Post-market monitoring
- Continuous surveillance must be carried out after deployment to detect misuse, vulnerabilities, or breaches.
Incident response and reporting
- Providers must implement processes for tracking and reporting serious incidents, including:
- Root cause analysis
- Timely reporting to the EC AI Office (within 2 to 15 days depending on the incident type)
- Periodic updates and final reporting within 60 days.
Security assurance and governance
- Responsibilities for security must be clearly assigned across executive, operational, and oversight levels.
- Internal and external security audits and assurance processes must be in place, with resources allocated accordingly.
Transparency and documentation
- Providers must maintain documentation of security measures, evaluation results, and any mitigations.
- Summarised public reporting of frameworks and model safety/security profiles is required, unless models are demonstrably low-risk.






