What Every AI Model Provider Already Owes Brussels
Every provider of a general-purpose AI model sold or used in the EU has owed Brussels a defined set of duties since August 2, 2025, whether or not it ever signs anything voluntary. Article 53 of the AI Act requires up to date technical documentation covering training methods, data sources, energy use and intended purpose, kept for at least ten years after the model leaves the market.
The same article requires a public copyright policy that identifies how the provider respects rights holder opt outs, and a named contact point that must answer a downstream company's request within fourteen days. In the UK, which is not bound by the AI Act at all, the same ground is instead covered piecemeal by existing regulators such as the ICO and Ofcom under a principles based approach, with no single binding AI statute of its own as of 2026.
The Extra Tier for the Biggest Models
A smaller group of providers carries a heavier duty. Article 51 presumes a model poses systemic risk once its cumulative training run crosses 10 to the 25 floating point operations, a threshold high enough to catch only the frontier labs, and providers must notify the European Commission within two weeks of reasonably expecting to cross it.
A systemic risk provider must also run a documented safety and security framework, assess and mitigate the risks it finds, report serious incidents, and keep every record of that work for ten years. The presumption is rebuttable with evidence such as benchmark results, but the burden of making that case sits with the provider, not the Commission.
What Signing the Code Actually Buys You
The General Purpose AI Code of Practice is not a law. It is a voluntary template, built with the Commission and nearly a thousand outside contributors, that spells out exactly how a provider can satisfy the Article 53 and Article 51 duties above in a form Brussels already recognizes. Anthropic, OpenAI, Google, Microsoft, Amazon, IBM, Mistral AI, Cohere and Aleph Alpha have all signed it.
The payoff is a presumption of good faith. The AI Office has said it will not treat a signatory as having broken its commitments without cause, which in practice narrows how a fine gets calculated and how much a provider has to argue to avoid the top end of it. A signatory still has to actually meet the obligations; signing only changes how it gets to prove that.
Meta's Bet, and What It Actually Costs
Meta declined to sign, citing what it called legal uncertainty beyond the text of the AI Act itself. xAI signed only one of the code's three chapters, safety and security, and left transparency and copyright unsigned. Both companies remain fully bound by Article 53 and, where it applies, Article 51. Declining the code does not excuse the law.
What it removes is the shortcut. A non signatory must, in the AI Office's own words, demonstrate compliance by other appropriate means, built and argued from scratch for every request, with no pre approved template and no presumption of good faith attached. For a company the size of Meta that is an internal legal cost measured in specialist hours, not a headline risk, but it is a cost every signatory does not carry.
| Layer | Applies to | How compliance is shown | AI Office posture |
|---|---|---|---|
| Baseline duties (Article 53) | Every GPAI provider | Self-built documentation and copyright policy | Standard scrutiny |
| Systemic-risk duties (Article 51) | Models over 10 to the 25 FLOPs | Safety report filed before release | Standard scrutiny |
| Code of Practice, signed | Anthropic, OpenAI, Google, Microsoft, Amazon, IBM, Mistral AI and others | The code's own pre-approved template | Presumption of good faith |
| Code of Practice, declined | Meta; xAI on two of three chapters | Case by case, self-constructed evidence | Full burden of proof, no presumption |
The Audit That Just Tested the Theory
On September 1, 2026, the AI Office sent its first ever Article 91 requests for information to more than thirty general purpose AI providers, four weeks after its power to fine actually switched on. Reported recipients include OpenAI, Anthropic and Google. One track of questions covers safety and security practice for the most capable models. The other covers copyright and transparency, the same two subjects the Code of Practice's chapters were built to answer.
A provider that answers incompletely, incorrectly or misleadingly risks a fine up to fifteen million euros or three percent of global turnover, a penalty for the quality of the answer itself, separate from whatever the underlying practice turns out to be. For a signatory, that answer already exists in the documentation the code asks for. For a non signatory, it has to be assembled under deadline.
What This Means If You Buy AI, Not Just Build It
A company that licenses a general purpose model to build its own product inherits a slice of this risk whether it reads the fine print or not. If the underlying model's provider cannot produce clean documentation on request, the delay and uncertainty land on every product built on top of it, not only on the lab itself.
Asking a vendor which Code of Practice chapters it signed, and which it left out, is now a fair procurement question with a concrete answer, not a compliance formality. A model built by a non signatory is not illegal to use. It is simply one audit letter away from a slower, costlier answer than a signed one would give.
Read next: Brussels Just Tested Its New Power on 30 AI Companies | OpenAI Flips And Asks The UK For Mandatory AI Rules



