Code of Practice (EU AI Act)

Code of Practice (EU AI Act)

A code of practice within the meaning of the EU AI Act is a voluntary set of rules with which AI providers demonstrate that they comply with the requirements of the law. Those who sign have to provide less proof themselves — but in return commit to concrete rules on transparency, copyright, and safety.

In 2024, the European Union passed a law that sets out rules for Artificial Intelligence: the AI Act. Laws like this are deliberately written in general terms so that they still fit five years from now. That is exactly what creates a problem for companies. The law states, for example, that providers of large AI systems must describe “in sufficient detail” what data they used to train their system. What “sufficient detail” actually means is nowhere specified. A code of practice fills this gap: experts, authorities, and companies jointly write down what concrete behavior counts as compliant. Signing is voluntary, but it brings tangible advantages.

The bridge between legal text and practice

Without a code, every company would have to guess for itself what the law requires of it. This guessing would be costly and would only be clarified in court — years later. The code replaces the guesswork with a coordinated list of measures. Anyone who fulfills them can assume they are on the safe side. Lawyers call this a presumption of conformity.

For authorities, this brings the same advantage. The responsible supervisory body does not have to examine every company from scratch. It can check signatories for compliance with the code, which is faster and more consistent. For companies that do not sign, the opposite is true — it becomes more burdensome. They must prove on their own that they comply with the law.

Voluntary therefore does not mean without consequences. A signature is legally binding as soon as it is given. And forgoing it does not trigger fines, but it does bring significantly more documentation obligations and more scrutiny from supervisory authorities. This pressure is entirely intentional.

How such a code comes into being

Responsible for the process is the AI Office, a department of the EU Commission for AI oversight. It invites stakeholders: providers of large AI systems, researchers, publishers, consumer protection groups, and civil rights organizations. Drafts emerge over several rounds, with all sides giving feedback. For the first code for general-purpose AI models, almost a thousand participants were registered. In the end, the Commission assesses whether the text is fit for purpose.

In terms of content, such a code breaks down into chapters. One chapter deals with transparency: providers fill out a standardized form about their model, covering things like compute used and data sources. A second chapter deals with copyright, i.e., the handling of protected texts and images during training. A third applies only to the largest systems and their potential risks.

It is important to distinguish this from a standard. Technical standards are developed by dedicated standardization organizations and often take years. A code of practice is the faster interim solution until such standards are ready. It is also not a law and cannot expand the law. It may only spell out in detail what already applies anyway.

Who signs and who disputes

In the news, the term usually comes up when a major technology company makes a decision. The providers of well-known chatbots and language models are in focus here because their systems fall under the rules for general-purpose AI. Some have signed, others initially only individual chapters, and others not at all. Such decisions are also signals to investors and policymakers.

Criticism comes from two sides at once. Parts of the industry consider the requirements too bureaucratic and warn that Europe is falling behind. Consumer and copyright associations, conversely, consider the code too weak and too heavily co-written by the companies themselves. That both accusations are raised at the same time is typical of negotiated compromises.

This will rarely affect you directly. Indirectly, it will: if a model in the future discloses which data sources it used, or if it declines requests on certain topics, a code may well be behind it. Similar voluntary sets of rules exist outside AI as well, for instance in the advertising industry. The underlying principle is always the same: self-regulation instead of detailed legislation.

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.