AI Regulation Tracker · EU AI Act · Framework

What does General-Purpose AI Code of Practice say about AI in banking?

Published Jul 10, 2025 · Last reviewed Aug 26, 2026

The General-Purpose AI Code of Practice was published by the European Commission on July 10, 2025 as a voluntary tool for GPAI model providers to demonstrate compliance with Articles 53 and 55 of the AI Act, which applied from August 2, 2025. It has three chapters — Transparency (with a Model Documentation Form), Copyright, and Safety and Security for models with systemic risk — and was confirmed as adequate by the Commission and the AI Board. Signatories include Anthropic, Google, Microsoft and OpenAI; xAI signed only the Safety and Security chapter.

DocumentGeneral-Purpose AI Code of PracticeGeneral-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters)
Issued byRegulation (EU) 2024/1689 — the EU Artificial Intelligence Act
TypeFramework
StatusIn force
PublishedJul 10, 2025
EffectiveAug 2, 2025
Applies toProviders of general-purpose AI models placed on the EU market; indirectly, banks that build on those models through vendors
Official sourcedigital-strategy.ec.europa.eu
Use casesGenerative & agentic AI · Third-party & vendor AI · Model risk management

What are the key points of General-Purpose AI Code of Practice?

  • Transparency chapter: a standard Model Documentation Form providers must complete and share with downstream providers and, on request, the AI Office.
  • Copyright chapter: commitments on EU copyright compliance, including respecting machine-readable opt-outs when crawling training data.
  • Safety and Security chapter: applies only to GPAI models with systemic risk (Art. 55), covering risk assessment, incident reporting and cybersecurity.
  • Adherence gives providers a presumption-of-good-faith route and lower administrative burden; non-signatories must demonstrate compliance by other means.
  • GPAI obligations applied from August 2, 2025; the Commission's enforcement powers over GPAI providers begin August 2, 2026.
  • Banks are typically downstream deployers: the Code determines what documentation they can expect to receive from foundation-model vendors for their own third-party and model-risk records.

What did General-Purpose AI Code of Practice change for banks?

For banks, the Code standardises what foundation-model vendors will disclose — capabilities, limitations, training-data summaries, evaluation results — which becomes the evidentiary base for vendor due diligence and model-risk documentation of generative-AI use cases. It does not impose direct duties on banks unless they fine-tune a model so substantially that they become a GPAI provider.

Does the GPAI Code of Practice apply to banks?

Only if a bank itself places a general-purpose AI model on the EU market. Banks using vendor models are downstream deployers; the Code matters to them as the source of standardised model documentation from providers.

Which companies signed the GPAI Code of Practice?

Around two dozen providers including Anthropic, Google, Microsoft and OpenAI signed all chapters; xAI signed the Safety and Security chapter only.

DateDocumentStatus
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI)Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
May 19, 2026Draft Commission guidelines on high-risk classificationDraft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI ActProposed
Nov 21, 2025EBA factsheet on the AI ActAI Act: implications for the EU banking and payments sector (EBA factsheet)Final
Feb 4, 2025Commission guidelines on prohibited AI practicesCommission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)In force
Jul 12, 2024Regulation (EU) 2024/1689Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)In force
Oct 30, 2023Consumer Credit Directive (EU) 2023/2225Directive (EU) 2023/2225 on credit agreements for consumers (CCD2) — automated creditworthiness assessment provisionsFinal

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →