Module 4 of the AI Act GPAI certification: what adherence to a code of practice demonstrates, what it does not, and how to work while harmonised standards do not yet exist.
Chapter V arrived before the technical instruments that would make it operational. Art. 56 is the bridge, and understanding exactly what it does — and does not — do is worth more than knowing its text.
The problem Art. 56 solves
Most of the AI Act's requirements are outcome-stated: adequate cybersecurity, sufficiently detailed summary, state-of-the-art technologies, appropriate level. In the ordinary EU product-safety architecture, harmonised standards convert outcome statements into testable specifications, and compliance with a published standard buys a presumption of conformity.
For general-purpose AI models, those standards did not exist when the obligations applied on 2 August 2025, and the standardisation work is still running. The absence of harmonised standards was also among the reasons cited for the Digital Omnibus deferring the high-risk system dates in July 2026 — the same gap, in a different chapter.
A code of practice fills the interval.
What Art. 56 provides
The AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to contribute to the proper application of the Regulation, taking into account international approaches.
The AI Office and the Board shall aim to ensure that codes of practice cover at least the obligations provided for in Art. 53 and Art. 55, including:
- the means to ensure that the information referred to in Art. 53(1)(a) and (b) is kept up to date in light of market and technological developments;
- the adequate level of detail for the summary about the content used for training;
- the identification of the type and nature of the systemic risks at Union level, including their sources where appropriate;
- the measures, procedures and modalities for the assessment and management of systemic risks at Union level, including their documentation, proportionate to the risks, considering their severity and probability and taking into account the specific challenges of tackling those risks in light of the possible ways in which they may emerge and materialise along the AI value chain.
The AI Office may invite all providers of general-purpose AI models, as well as relevant national competent authorities, to participate in drawing them up. Civil society organisations, industry, academia and other stakeholders such as downstream providers and independent experts may support the process.
The Commission may, by implementing act, approve a code of practice and give it general validity within the Union. Where a code cannot be finalised, or the AI Office deems it not adequate, the Commission may provide common rules for the implementation of the Chapter V obligations by implementing act.
What adherence buys, and what it does not
It buys a demonstrated route. Providers may rely on a code of practice to demonstrate compliance with the Art. 53 and Art. 55 obligations until a harmonised standard is published. Compliance with a European harmonised standard, once published, gives the presumption of conformity to the extent the standard covers the obligations.
It does not convert the code into the obligation. The obligations are in Art. 53 and Art. 55. A code describes a way of meeting them that the AI Office has facilitated and the Commission may have approved. Following it well is strong evidence; following it does not substitute for the article if the article demands something the code does not address.
It is not the only route. Providers of general-purpose AI models who do not adhere to an approved code of practice, or do not comply with a European harmonised standard, shall demonstrate alternative adequate means of compliance for assessment by the Commission. That is a real alternative, and it is more expensive — you carry both the substance and the burden of showing your route is adequate.
Working in the gap
For a provider in this period, three practical positions.
Adhere, and say so. If a code covering your obligations exists and has been approved, adherence is the cheapest demonstrable route and the one the Commission is best equipped to assess.
Map anyway. Whether you adhere or not, produce an internal mapping from each Art. 53 and Art. 55 obligation to the specific artefact, process or control that satisfies it. If a code is approved later, that mapping becomes a gap analysis in an afternoon. Without it you start from the article.
Watch the standards. When a harmonised standard's references are published in the Official Journal, the presumption of conformity becomes available, and the calculus changes. The transition from code to standard is the moment to re-examine positions built on the code.
The same mechanism in Chapter III
For completeness, because organisations frequently do both: Art. 40 provides the equivalent presumption for high-risk systems. Where a provider applies a harmonised standard whose references are published in the Official Journal, it is presumed to conform with the Chapter III Section 2 requirements the standard covers. Where standards do not exist or are insufficient, the Commission may adopt common specifications by implementing act, and providers who do not apply them must adopt technical solutions meeting the requirements at least equivalently.
The pattern is identical in both chapters: an outcome-stated obligation, a voluntary instrument that demonstrates compliance, and a burden that shifts to the provider who takes another route.
Check yourself
- We adhere to the code of practice, so we are compliant. — Adherence is a means of demonstrating compliance with Art. 53 and Art. 55, not a substitute for them.
- We prefer not to adhere. — Then you must demonstrate alternative adequate means of compliance for assessment by the Commission — a real route, with the burden on you.
- Do notified bodies certify GPAI models? — No. There is no notified body role for models; enforcement is centralised at the Commission through the AI Office.
- A harmonised standard has just been published covering part of Art. 53. — Compliance with it gives a presumption of conformity for what it covers, and it is time to re-examine positions built on the code.
Previous: Module 3 — Systemic risk (Art. 51, 52 and 55) Next: Module 5 — Becoming a model provider →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
An instrument the AI Office encourages and facilitates at Union level, contributing to the proper application of the Chapter V obligations. Providers of general-purpose AI models may rely on a code of practice to demonstrate compliance with the Art. 53 and Art. 55 obligations until a harmonised standard is published. Adherence is voluntary; the obligations are not.
No. It is a means of demonstrating compliance, and the Commission may approve a code by implementing act giving it general validity within the Union. A provider that does not adhere must demonstrate compliance by other adequate means, subject to Commission assessment. Neither route converts the code into the law.
Providers who comply with a harmonised standard, or parts of it, whose references are published in the Official Journal enjoy a presumption of conformity with the requirements the standard covers. That is the same mechanism Art. 40 provides for high-risk systems, and it is the cheapest compliance route once it exists.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.