Ahead of the May deadline for establishing guidelines on how general-purpose AI (GPAI) providers should comply with the EU AI Act’s regulations for major AI companies, a third draft of the Code of Practice was released on Tuesday. This Code has been in development since last year, and this version is anticipated to be the final revision before the guidelines are officially finalized in the coming months.
A website has been launched to enhance the Code’s accessibility. Written feedback on the latest draft must be submitted by March 30, 2025.
The EU’s risk-based AI rulebook includes specific obligations for the most advanced AI model developers, focusing on transparency, copyright, and risk mitigation. The Code is designed to guide GPAI model makers in meeting these legal requirements and avoiding potential penalties for non-compliance. Violations of GPAI provisions under the AI Act could result in fines of up to 3% of global annual revenue.
Here’s the perfectly rephrased version of your text while maintaining the structure and meaning:
Streamlined
The latest iteration of the Code is described as having “a more streamlined structure with refined commitments and measures” compared to previous versions, incorporating feedback from the second draft released in December.
Additional input from stakeholders, working group discussions, and workshops will contribute to refining this third draft into the final guidelines. Experts anticipate achieving greater “clarity and coherence” in the finalized version of the Code.
The draft is divided into several sections outlining commitments for GPAIs, along with detailed guidance on transparency and copyright measures. It also includes a section on safety and security obligations for the most advanced models, categorized under systemic risk (GPAISR).
Regarding transparency, the guidance provides an example of a model documentation form that GPAIs may be required to complete. This is intended to ensure that downstream users of AI technology have access to essential information to support their compliance efforts.
Meanwhile, the copyright section remains one of the most contentious areas for Big AI.
The current draft frequently uses terms such as “best efforts,” “reasonable measures,” and “appropriate measures” when addressing compliance with obligations like respecting rights during web crawling for data collection or mitigating the risk of generating copyright-infringing content.
Such cautious wording suggests that major AI companies may interpret the requirements as allowing flexibility to continue using protected content for training while seeking forgiveness later. However, whether stricter language will be introduced in the final version remains uncertain.
Notably, language from an earlier draft—stating that GPAIs should provide a direct and efficient way for rightsholders to submit complaints—appears to have been softened. The latest version only states: “Signatories will designate a point of contact for communication with affected rightsholders and provide easily accessible information about it.”
Additionally, the text suggests that GPAIs may refuse to address copyright complaints if they are deemed “manifestly unfounded or excessive, in particular because of their repetitive character.” This implies that attempts by creatives to leverage AI tools for detecting copyright violations and automating complaint submissions could result in their grievances being ignored.
On safety and security, the AI Act’s requirements to assess and mitigate systemic risks already apply only to a subset of the most advanced models—those trained using computing power exceeding 10^25 FLOPs. However, the latest draft further narrows some previously recommended measures based on feedback.
US Pressure
Absent from the EU’s press release on the new draft are sharp criticisms of European regulation—particularly AI-related policies—coming from the U.S. administration under President Donald Trump.
At the Paris AI Action Summit last month, U.S. Vice President JD Vance dismissed the need for AI safety regulations, advocating instead for an “AI opportunity” approach. He also cautioned that excessive regulation in Europe could stifle innovation.
In response, the EU has already moved to scrap one AI safety measure—the AI Liability Directive. Additionally, lawmakers have hinted at an upcoming “omnibus” package of reforms aimed at reducing bureaucracy for businesses, including adjustments to sustainability reporting requirements. However, with the AI Act still being implemented, external pressure to weaken regulatory requirements remains evident.
At the Mobile World Congress in Barcelona earlier this month, French GPAI model developer Mistral—one of the most vocal critics of the AI Act during its 2023 negotiations—raised concerns about the feasibility of complying with certain provisions. Founder Arthur Mensch stated that the company is “working with regulators to ensure these issues are resolved.”
While the GPAI Code is being developed by independent experts, the European Commission—through its AI Office, which oversees enforcement and regulatory matters—is concurrently preparing additional “clarifying” guidance. This will further define GPAI obligations and responsibilities under the law.
Expect further guidance from the AI Office “in due time,” as the Commission has indicated it will “clarify … the scope of the rules.” This could offer lawmakers an avenue to respond to U.S. lobbying efforts pushing for AI deregulation.



