Join our Newsletter — 33% off our NHI Course
Home Glossary AI Security Code of Practice on GPAI
AI Security

Code of Practice on GPAI

← Back to Glossary
By NHI Mgmt Group Updated September 10, 2026 Domain: AI Security

The Code of Practice on GPAI is a voluntary framework that helps providers align with the EU AI Act’s general-purpose AI obligations. It translates legal expectations into practical actions, including documentation, risk management, and safeguards. Organisations use it to reduce compliance friction and prepare for formal enforcement.

Expanded Definition

The Code of Practice on GPAI is a voluntary compliance bridge for providers of general-purpose AI under the EU AI Act. It is not a law itself and it does not replace the Act, but it helps organisations translate high-level legal duties into operational practices such as technical documentation, risk management, and model governance. Its practical value is that it reduces ambiguity before formal supervision or enforcement applies.

Guidance versus consensus matters here. The Code reflects an agreed route for demonstrating good-faith alignment, but it does not settle every implementation detail across the market. That distinction is important because a provider may follow the Code and still need to address product-specific or use-case-specific obligations elsewhere in its lifecycle. The EU AI Act remains the primary legal reference point, while the Code is a practical interpretation layer.

A common misunderstanding is to treat the Code as a substitute for internal governance. In practice, it is most useful when it is mapped to real ownership, evidence collection, and review cycles, so that compliance claims can be supported if challenged.

Examples and Use Cases

Providers use the Code of Practice on GPAI in several practical ways:

  • A foundation model provider uses it to structure documentation for model capabilities, limitations, and intended deployment context.
  • A product team maps its internal risk reviews to the Code so legal, engineering, and compliance teams share one control baseline.
  • An AI governance function uses it to identify where training-data summaries, evaluation records, or safety testing evidence should be retained.
  • A procurement team uses it to compare supplier commitments against a recognised public compliance benchmark before signing a contract.
  • A compliance lead uses it to reduce friction between policy requirements and the evidence needed for supervisory review.

The main trade-off is that voluntary alignment can improve readiness without guaranteeing full regulatory sufficiency. Providers still need to assess whether their model, distribution channel, or downstream use introduces obligations beyond the scope of the Code.

In NHI Management Group terms, the strongest use case is organisational translation: the Code helps teams turn abstract AI compliance duties into traceable controls, artifacts, and accountabilities.

Security Implications

Misreading the Code of Practice on GPAI as a complete control framework can create governance gaps. If a provider relies on it too narrowly, it may under-document model behaviour, understate known limitations, or fail to preserve evidence of evaluation and mitigation decisions. Those gaps matter because compliance failures in GPAI programmes are often visibility problems before they become enforcement problems.

Security consequences can also appear indirectly. A weak documentation posture makes it harder to detect unsafe model changes, explain prior assurance decisions, or demonstrate that safeguards were applied consistently across releases. That can leave an organisation unable to prove what it knew, when it knew it, and what it changed in response.

A practical symptom is fragmentation: engineering tracks model controls one way, legal tracks obligations another way, and no one can reconstruct a single audit trail. The Code is valuable precisely because it encourages that evidence trail to be built early, before the organisation is forced to assemble it under pressure.

Domain and Governance Relevance

The Code of Practice on GPAI matters most in AI governance because it sits between legal obligation and operational execution. It helps turn abstract requirements into repeatable provider behaviour, which makes it relevant to ownership, accountability, and assurance. For organisations building or distributing general-purpose models, the key question is not whether the Code is mandatory, but whether it produces evidence that the provider can defend.

Its relationship to identity and access is secondary, not primary. However, when GPAI systems are developed, tested, or released by many teams, governance depends on clear responsibility for approvals, documentation, and change control. That is where the Code can indirectly improve trust in the surrounding control environment.

Used well, it supports a defensible compliance posture without pretending to be the whole governance model. Used badly, it becomes a checkbox exercise that leaves organisations with policy language but little operational proof.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the technical controls, while EU AI Act and ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
EU AI ActGPAI obligations — General-Purpose AI Provider ObligationsThe Code operationalises provider duties under the EU AI Act for GPAI.
Recommendation — Map Code commitments to GPAI duties and retain evidence for supervisory review.
ISO/IEC 42001:2023A.5 — AI Risk ManagementThe Code supports organisational AI risk governance and documented controls.
Recommendation — Align AI risk processes and records so the Code becomes auditable governance practice.
NIST AI RMFGOVERN — GovernThe Code translates high-level AI governance expectations into provider practice.
Recommendation — Use GOVERN to assign accountability for model documentation, review, and oversight.
NIST AI 600-1A1 — Document and Govern AI SystemsThe Code emphasises documentation and operational governance for GPAI providers.
Recommendation — Document model purpose, limits, and evaluation results before deployment decisions.
NIST CSF 2.0GV.RM — Risk Management StrategyThe Code strengthens cross-functional AI risk governance and evidence readiness.
Recommendation — Embed the Code into risk management so compliance evidence is available when needed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org