lawve-ai/gpai-code-of-practice
Assess compliance with the EU General-Purpose AI (GPAI) Code of Practice under the AI Act (Regulation (EU) 2024/1689, KI-Verordnung) Articles 51-56. Covers GPAI model identification (Art. 3(63)), systemic risk model designation (Art. 3(65), Art. 51, 10^25 FLOP training compute threshold), upstream provider obligations under Art. 53 (transparency, technical documentation, copyright policy and EU rights reservation, training data summary template), additional systemic risk obligations under Art. 55 (model evaluation benchmarks, adversarial red-teaming, AI Office incident notification under Art. 55(1)(c), cybersecurity), AI Office notification (Art. 52), downstream provider duties (Art. 25 quasi-provider), and Art. 53(2) open-source LLM exemption. Maps the 12 GPAI Code of Practice commitments across transparency, copyright, and safety-and-security chapters. DACH: BaFin, BSI, BNetzA, Betriebsrat. Use when asked about GPAI provider obligations, LLM or foundation model compliance, the Art. 51 systemic risk threshold, Art. 53 transparency requirements, Art. 55 systemic-risk obligations, AI Office notification, downstream Art. 25 duties, Art. 53(2) open-source exemption, or generative AI provider compliance under the EU AI Act.
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill gpai-code-of-practice
Assess compliance with the EU General-Purpose AI Code of Practice (Final Version, July 2025) and underlying AI Act obligations (Articles 51–56).
Important: This skill provides compliance workflow support, not legal advice. The Code of Practice is voluntary — providers can demonstrate compliance through alternative means. Always cite specific articles, commitments, and measures. Where facts are incomplete, state assumptions explicitly and ask targeted follow-up questions.
Follow this decision tree strictly in order.
Determine whether the entity falls within scope.
Definition (Article 3(63) + GPAI Guidelines): A GPAI model is one "trained with a large amount of data" that displays "significant generality" and is "capable of competently performing a wide range of distinct tasks." Indicative threshold: trained with >10^23 FLOPs and capable of generating text, audio, images, or video.
Check:
If YES to any → The entity is a GPAI model provider. Proceed to Step 2.
If NO → May still be a downstream provider/deployer with separate obligations. Document why GPAI provider status does not apply and stop.
Key distinction: The release mode (API, open weights, enterprise licence) does not affect whether a model is GPAI. It affects which exemptions apply.
Check whether the partial exemption under Article 53(2) applies:
If YES to both:
If NO → All obligations apply. Proceed to Step 3.
Determine whether the GPAI model has systemic risk:
| Criterion | Threshold | Source |
|-----------|-----------|--------|
| Compute-based presumption | Training compute >10^25 FLOPs | Article 51(2) |
| Commission designation | High-impact capabilities or equivalent impact based on Annex XIII criteria | Article 51(1)(b) |
If systemic risk → TWO obligation tiers apply:
If no systemic risk → Tier 1 only.
→ Currently ~5–15 companies worldwide have models meeting the systemic risk threshold.
Assess compliance with each obligation. The Code of Practice provides the compliance framework through two chapters:
| Obligation | AI Act Source | Code Measure | Key Requirements |
|-----------|--------------|-------------|-----------------|
| Technical documentation | Art. 53(1)(a), Annex XI | Measure 1.1 | Model Documentation Form — licensing, architecture, training, datasets, compute, energy |
| Downstream provider info | Art. 53(1)(b), Annex XII | Measure 1.2 | Capabilities, limitations, integration info — deliver within 14 days of request |
| Documentation integrity | Art. 53(1)(a)–(b) | Measure 1.3 | Accurate, tamper-proof, securely stored for ≥10 years |
| Training data summary | Art. 53(1)(d) | GPAI Template | Mandatory public disclosure — data sources, types, volumes, compliance measures |
→ For complete transparency requirements and the Model Documentation Form, read references/transparency-obligations.md.
| Obligation | Code Measure | Key Requirements |
|-----------|-------------|-----------------|
| Copyright policy | Measure 1.1 | Draw up, publish summary, define accountability |
| Lawful access only | Measure 1.2 | No circumventing paywalls; exclude piracy sites |
| Rights reservations | Measure 1.3 | Comply with robots.txt and machine-readable opt-outs |
| Record-keeping | Measure 1.4 | Maintain records of crawling and rights compliance |
| Output safeguards | Measure 1.5 | Technical measures to minimise infringing outputs |
| Terms of service | Measure 1.6 | Prohibit unauthorised copyright use by users |
| Complaints handling | Measure 1.7 | Designated contact point, fair complaint process |
→ For complete copyright requirements, read references/copyright-obligations.md.
Only if the model has systemic risk (Step 3). Assess compliance with the Safety & Security chapter (Commitments 1–10):
| Commitment | Focus | Key Requirements |
|-----------|-------|-----------------|
| 1 | Safety & Security Framework | Create, implement, update, notify AI Office |
| 2 | Systemic risk identification | Structured process + risk scenarios |
| 3 | Systemic risk analysis | Evaluations, modelling, monitoring |
| 4 | Risk acceptance determination | Acceptance criteria + proceed/stop decision |
| 5 | Safety mitigations | Lifecycle safety measures |
| 6 | Security mitigations | Cybersecurity for model + infrastructure |
| 7 | Model Reports | Pre-market report to AI Office, keep updated |
| 8 | Responsibility allocation | Clear roles, resources, risk culture |
| 9 | Serious incident reporting | Track, document, report within deadlines |
| 10 | Additional documentation | Record-keeping (10 years), public transparency |
→ For complete systemic risk requirements, read references/systemic-risk-framework.md.
If the provider or deployer operates in Germany, Austria, or Switzerland, check additional requirements:
→ For DACH overlay details, read references/dach-specific.md.
If a provider needs to move fast, these are the five highest-impact actions in priority order:
Enforcement timeline: AI Office enforcement actions begin 2 August 2026 in current law. Legacy GPAI models (placed on the market before 2 August 2025) have until 2 August 2027. The 7 May 2026 provisional Council/Parliament agreement on the Digital Omnibus leaves these GPAI dates unchanged; only Annex III high-risk and Annex I dates would shift if formally adopted. Until adoption plus Official Journal publication, current-law dates remain authoritative.
Use these questions at intake to gather the information needed for assessment:
Model & Provider
Distribution & Use
Training Data
10. What copyright compliance measures are in place?
Risk & Compliance
11. Has the model been designated as having systemic risk?
12. What documentation currently exists (model cards, technical docs)?
13. Has the provider signed the Code of Practice?
14. What cybersecurity measures protect the model and infrastructure?
If answers are incomplete, state assumptions explicitly and flag gaps.
Load these as needed based on assessment progress:
| File | When to read |
|------|-------------|
| references/transparency-obligations.md | Assessing Transparency chapter — Model Documentation Form, Annex XI/XII requirements |
| references/copyright-obligations.md | Assessing Copyright chapter — policy, crawling, rights reservations, complaints |
| references/systemic-risk-framework.md | Model has systemic risk — all 10 Safety & Security commitments with measures |
| references/compliance-timeline.md | Building a compliance roadmap — all deadlines, enforcement dates, grace periods |
| references/dach-specific.md | Provider/deployer in Germany/Austria/Switzerland — BNetzA, BSI, works council |
| references/templates.md | Producing deliverables — gap assessment, compliance memo, executive summary templates |
Every GPAI Code of Practice assessment produces three deliverables:
→ For complete templates, read references/templates.md.
| Violation | Maximum Fine | AI Act Source |
|-----------|-------------|---------------|
| Systemic risk obligations (Art. 55) | €15M or 3% global annual turnover | Art. 101(2) |
| General GPAI obligations (Art. 53) | €7.5M or 1% global annual turnover | Art. 101(3) |
| Incorrect/misleading information to AI Office | €7.5M or 1% global annual turnover | Art. 101(3) |
For SMEs and startups, the lower of the two amounts applies.
Enforcement note: While GPAI obligations apply since 2 August 2025, the AI Office's formal enforcement actions (requests for information, access to models, model recalls) begin 2 August 2026. This grace period is for working with the AI Office toward compliance — not a safe harbour.
Non-signatories to the Code of Practice face "a larger number of requests for information and requests for access" and must demonstrate compliance through alternative, potentially more burdensome means (Articles 53(4), 55(2), 56).
This skill provides structured compliance workflow support based on Regulation (EU) 2024/1689 and the GPAI Code of Practice (Final Version, July 2025). It does not constitute legal advice. The Code of Practice is a voluntary compliance tool — adherence creates a presumption of compliance but is not conclusive evidence. Assessment outcomes should be reviewed by qualified legal counsel. The EU AI Act is subject to delegated acts, implementing acts, harmonised standards (expected 2027+), and ongoing AI Office guidance that may affect interpretation.
Take lawve-ai/gpai-code-of-practice from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.