Berlin: As Germany’s startups and research labs race to build on the latest generation of foundation models, the question of whose rules those models must follow is being settled less in any single capital than in a voluntary code that most of the industry has now signed. The European Union’s General-Purpose AI Code of Practice, published by the bloc’s AI Office in July 2025, has become the main route by which developers of large models demonstrate they comply with the AI Act, and the roster of signatories says a good deal about where the industry stands.
The code is organised into three chapters. Two, on transparency and on copyright, apply to all providers of general-purpose models and cover documentation of how a model was built and respect for the opt-outs that rights holders can use to keep their work out of training data. The third, on safety and security, binds only the makers of the most capable systems, those trained with computing power above a threshold of ten to the twenty-fifth floating-point operations, where regulators fear risks that could ripple across society.
By June the code had drawn roughly two dozen signatories, among them Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, Cohere and Samsung Electronics. The notable holdout is Meta, which has declined to sign, arguing the framework reaches beyond the law itself. The startup xAI signed only the safety and security chapter, committing to demonstrate compliance with the transparency and copyright rules by other means, a stance the Commission has signalled it will scrutinise closely.
The legal scaffolding behind the code is already partly live. Bans on a set of prohibited AI practices have applied since February 2025, and obligations specific to general-purpose models since August 2025. What has not yet arrived is hard enforcement. The Commission’s powers to act against providers, by demanding information, requesting access to models or ordering changes, are due to become available from 2 August 2026. That one-year grace period is meant to give companies room to work alongside the AI Office and adjust their practices before penalties are on the table.
For a developer in Berlin, the practical effect is a compliance landscape that is firming up faster than the enforcement that will eventually police it. Signing the code is not mandatory, but it offers a presumption of conformity that spares companies from negotiating their own bespoke path to compliance, a meaningful advantage for smaller European firms without large legal teams. Critics on one side warn the obligations could entrench incumbents able to absorb the paperwork, while critics on the other fear a voluntary instrument lacks the bite to constrain the largest players. With formal investigations into prohibited practices already opened earlier in the year and the enforcement deadline now weeks away, the gap between writing the rules and applying them is about to close.




