SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Introduction to the EU AI Act 'General-Purpose AI Code of Practice': What Japanese Engineers Need to Know

The evolution of AI technology is remarkable, and its use continues to spread across the globe. However, with this rapid development, ethical, legal, and social challenges have also emerged. In the European Union (EU) in particular, the 'EU AI Act' has been introduced as a comprehensive regulatory framework for AI, significantly impacting AI developers worldwide.

In this article, we will explain the key points that Japanese engineers should know about the 'General-Purpose AI (GPAI) Code of Practice,' which is one of the most important mechanisms within the EU AI Act.


This time, we will be interpreting this site.

This document focuses on the Code of Practice for General-Purpose AI (GPAI) designed to facilitate the implementation of the EU AI Act. Specifically, it explains how GPAI model providers can demonstrate compliance during the transition period from August 2025, when the AI Act obligations take effect, until 2027 and beyond, when the corresponding European standards are adopted. This code imposes requirements regarding transparency and copyright on all GPAI model providers, and additional requirements regarding safety and security on providers of GPAI models with systemic risk. Although it is not legally binding, by complying with this code, providers can demonstrate compliance, and may face reduced fines compared to non-compliant entities. This code was formulated through a collaborative process involving numerous stakeholders, and major AI companies have signed it.

What is the General-Purpose AI Code of Practice?

Following the introduction of the EU AI Act, the implementation of regulations is proceeding in stages. Obligations under the AI Act, particularly those concerning general-purpose AI model providers, have been in effect since August 2, 2025. However, the formulation of 'harmonised European standards' to specifically operationalize these obligations usually takes more than three years, and may take even longer for advanced technical standards like those for GPAI.

This General-Purpose AI Code of Practice was introduced as a tool to bridge the 'interim period' until these standards are formulated.

Purpose: It serves as a guideline for complying with the obligations of the AI Act (specifically Articles 53 and 55) and is an important means for GPAI model providers to demonstrate compliance with the AI Act.

Legal Binding Force: It is not legally binding. However, by following it, providers can prove that they are in compliance with the AI Act until the standards are introduced.

Formulation Process: It was developed with the participation of the AI Office and a wide range of stakeholders, including academics, independent experts, GPAI model providers, downstream deployers, and civil society organizations. The final version was published in July 2025.

Who is subject to this?

This Code of Practice applies to all GPAI model providers and providers of 'GPAI models with systemic risk'.

1. All GPAI model providers

The **chapters on 'Transparency' and 'Copyright'** of the Code of Practice apply.

Definition of GPAI model: The AI Act defines it as a 'model that displays significant generality, is capable of competently performing a wide range of distinct tasks, and can be integrated into a variety of downstream systems or applications.'

Indicative criteria: For example, models trained with 10^23 FLOPs (floating-point operations) or more that can generate language, text-to-image, or text-to-video may be considered GPAI.

Applicable Providers: Includes individuals, legal entities, or public authorities that develop GPAI models and place them on the market under their own name or trademark.

Exemptions: GPAI models released under a free and open-source license that do not pose systemic risks are exempt from certain obligations.

2. Providers of GPAI Models with Systemic Risk

The **'Safety and Security' chapter** of the Code of Practice applies.

Definition of Systemic Risk: Defined as risks specific to the high-impact capabilities of a GPAI model, which have the potential to cause widespread and serious negative impacts on public health, safety, public security, fundamental rights, or society as a whole.

Indicator Criteria: Models trained with a compute amount exceeding 10^25 FLOPs are presumed to have systemic risk (rebuttable). It is estimated that approximately 11 companies worldwide currently provide models exceeding this threshold.

Downstream Modifiers: If a downstream modifier modifies a model using compute exceeding one-third of the original model's training compute, they may be considered a new GPAI model provider (or a GPAI model provider with systemic risk).

Specific Content of the Code of Practice

The Code of Practice consists of the following three chapters, each setting out specific commitments and measures to achieve them.

1. Transparency Chapter (Applies to all GPAI model providers)

Maintenance of Model Documentation: For all GPAI models distributed within the EU (with some exceptions), providers commit to maintaining up-to-date and comprehensive documentation detailing licenses, technical specifications, use cases, datasets, compute, and energy consumption.

Provision of Information: This documentation must be made available upon request to the AI Office or downstream users, and public disclosure is encouraged.

2. Copyright Chapter (Applies to all GPAI model providers)

Development of Copyright Policy: Providers commit to developing and regularly updating a robust copyright policy that clarifies internal responsibilities and complies with existing Union copyright law.

Legality of Data Collection: Ensure that data collected through web crawling is legally accessible and respect machine-readable rights signals such as robots.txt.

Prevention of Infringing Content: Implement technical protection measures to minimize the generation of infringing content and explicitly prohibit misuse in terms of service.

Complaint Handling: Provide a point of contact for copyright holders to submit complaints and process them through an efficient and fair process.

3. Safety and Security Chapter (Applies only to GPAI model providers with systemic risk)

Safety and Security Framework: Before model release, providers commit to developing a state-of-the-art safety and security framework that outlines evaluation triggers, risk categories, mitigation strategies, forecasting methods, and organizational responsibilities.

Risk Assessment and Mitigation: Identify systemic risks through structured processes such as inventory surveys, scenario analysis, and consultations with internal and external experts, and assess acceptable risks by applying a defined risk hierarchy framework.

Model Reporting: Submit a mandatory 'Safety and Security Model Report' before release and update it as risks evolve.

Organizational Responsibility: Clearly assign oversight, ownership, monitoring, and assurance roles within the organization's governance structure, and ensure adequate resources, a strong risk culture, and whistleblower protection.

Serious Incident Reporting: Promptly track, document, and report serious incidents to regulatory authorities.

Record Keeping: Maintain detailed records of safety and risk management activities for at least 10 years.

Why is compliance with the Code of Practice important?

While the Code of Practice is voluntary, there are significant benefits to complying with it.

Demonstrating Compliance: By signing, you can easily demonstrate compliance with obligations under the AI Act.

Trust from Regulators: The European Commission focuses on monitoring compliance with the Code of Practice, and may increase trust in signatories and consider it a mitigating factor when determining the amount of fines.

Impact on Non-Signatories: On the other hand, providers who do not sign the Code of Practice must prove compliance through other appropriate means, and may receive more requests for information or be required to provide more detailed information.

Key Signatories: Many major GPAI model developers, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and OpenAI, have signed (with the exception of META and companies based in China).

Enforcement and Future Outlook

Enforcement of GPAI Rules: From August 2, 2025, all new models released on or after that date will be subject to compliance obligations.

Start of Regulatory Measures: Regulatory measures by the European Commission, such as requests for information, access to models, and model recalls, will begin on August 2, 2026.

Grace Period for Existing Models: Providers of models released before August 2, 2025, must bring them into compliance with the AI Act by August 2, 2027.

Regulatory Stance: The European Commission has stated that it will take a cooperative, gradual, and proportionate approach to the supervision, investigation, enforcement, and monitoring of GPAI provisions.

Future Possibilities: The European Commission may also approve the Code of Practice through implementing acts, giving it 'general validity' within the EU.

Summary

The EU AI Act's General-Purpose AI Code of Practice is an essential guideline that Japanese engineers who may deploy AI models in the EU market cannot afford to ignore. Although it is not legally binding, complying with it is a wise choice to facilitate compliance and gain trust from regulators.

To ensure that the AI models you develop are accepted and trusted in the global market, it is crucial to understand the contents of this Code of Practice and keep a close eye on future developments.

If you plan to deploy AI models in the EU market, start by confirming whether your model falls under GPAI or GPAI with systemic risk, and begin by understanding the obligations described in each chapter of the Code of Practice.

いいなと思ったら応援しよう!