Helsinki: Compliance with the European voluntary code for general-purpose artificial intelligence models is about to stop being purely advisory. The Signatory Taskforce of the General-Purpose AI Code of Practice, set up at its first meeting on 30 January, has spent the spring grinding through interpretive notes and adherence templates ahead of the 2 August window, when the AI Office gains formal power to issue information requests, demand model access and, in the harshest cases, recall systems from the market. Three Finnish developers, joined by counsel from a Helsinki software cluster, attended the taskforce’s most recent meeting and described the agenda as a moving target.
The Code itself sits inside the broader AI Act architecture but is operationally distinct. Providers who sign on agree to a published menu of practices for transparency, copyright handling and systemic risk management. In return, the Commission has stated that adherence will be treated as a presumption of compliance under the corresponding sections of the Act and as a mitigating factor in fine calculations should enforcement open later. That swap, voluntary commitments for measured leniency, is what has drawn most of the major foundation model developers to the table even as some North American firms have publicly hesitated.
The August date matters because it converts the AI Office’s posture from a consultative body into a regulator with deadlines. From that moment, providers whose general-purpose models cross the systemic risk threshold must produce model evaluation reports, incident registers and copyright filtering documentation on a calendar set by the Office. The Code reduces some of that burden by giving signatories a recognised template. Non-signatories will have to design their own documentation, which the Office can still accept but may scrutinise more closely.
For European developers the practical question is whether the Code’s transparency obligations are compatible with their existing trade-secret protections. The taskforce has worked through three rounds of clarification on the so-called downstream summary, the document each signatory must publish explaining what training data categories were used. Industry submissions argue for high-level categorisation rather than dataset-level disclosure. Civil society participants have pushed for more granularity. The taskforce has not formally taken a side, but its draft guidance leans toward category-level reporting while preserving litigation protections.
There is also a quieter conversation about the Code’s relationship to copyright. Signatories must adopt a policy that respects rights reservations expressed by content holders, including those made through machine-readable opt-outs. The mechanics of how that interacts with existing licensing markets, particularly in the news and audiovisual sectors, are still being debated, and several Finnish publishers have used the taskforce process to argue for tighter enforcement standards. The AI Office has signalled it intends to publish a separate interpretive note on rights reservation before the enforcement window opens.
For now, the Code stays voluntary and the cap on penalties stays distant, but the calendar is unforgiving. By the second week of August, signatories will need to demonstrate live processes for incident reporting and risk mitigation. Non-signatories will face the same expectations through a slower and probably more contentious route. The wider question, hovering over the taskforce’s June agenda, is whether the Code can hold its design without being formally folded into binding guidelines once enforcement begins to bite.




