Skip to content

Main Insight

Read our response to the Safety and Security chapter of the final Code of Practice for governing general-purpose AI, published by the European AI Office after a nine-month process involving more than 1,400 stakeholders.

The Future Society’s Response to the EU’s Code of Practice for General-Purpose AI

July 10, 2025

Today, the EU AI Office published the Code of Practice for governing general-purpose AI (GPAI). The Code makes it simpler to comply with the EU AI Act and serves as a starting point for a much-needed regime to govern the most powerful and hazardous AI models.

The publication concludes a nine-month drafting process, in which The Future Society was honored to have participated. The process involved more than 1,400 stakeholders from industry, academia, and civil society, across four working groups that were spearheaded by 13 leading scientists. At its start, this multi-stakeholder approach showed that it was possible to inclusively and efficiently establish governance for GPAI—a significant achievement by the European Union.

Unfortunately, the process’s end failed to deliver on its promise. Once the official drafting process concluded in May, a small number of leading U.S. tech providers gained exclusive access to a fourth drafting round and secured significant changes to the text through intensive lobbying efforts. This weakened Code comes at the cost of European citizens and businesses, as well as misses opportunities to advance safety and accountability for AI worldwide. It also undermines all the other stakeholders who have seen their engagement and efforts to serve the public interest brushed aside due to corporate lobbying. 

The published Code is available here. However, it will likely need to be revised next year, if not earlier, in case of a major accident or new technological breakthroughs. As it stands, there are four aspects of the Safety and Security chapter that we consider a priority for future monitoring and revisions:

  1. The AI Office will receive key information only once a model is released on the EU market. Providers must share their Model Report containing essential information, such as the risk associated with a model only after deployment. This perpetuates providers’ “deploy first, question later” mentality, which means that potentially dangerous models get to European users without receiving any meaningful scrutiny from the AI Office. Subsequently, when a provider fails to comply, the AI Office will have to request its withdrawal from the market, which could fuel unjustified anti-innovation rhetoric. We believe reporting mechanisms should form a constructive dialogue between the AI Office and providers throughout development, ensuring that an interim Model Report and other key information are shared at least eight weeks prior to release.
  2. No more meaningful protection for whistleblowers. Whistleblowers and informants are a key source of information for authorities in industries with intense capital and market forces. In a world where AI companies can know everything about us, and we know almost nothing about them, foregoing insider information significantly hampers the ability of the authorities to learn about reckless behavior among some AI companies. All the more true given the very providers in scope have had worrisome practices already with respect to whistleblowers, amidst a culture of risk and retaliation. The AI Office must commit to being a safe haven for whistleblowers, applying the same standard that the Whistleblower Protection Directive requires of EU Member States. This is both for intel-gathering and monitoring functions, but also for cost-effective and proper prioritization of enforcement. 
  3. Providers don’t have to ensure emergency preparedness anymore. Even though the development of plans and procedures to contain damage in case of emergencies is standard practice in other high-risk industries, providers of general-purpose AI models with systemic risk no longer have to develop such protocols. Given the far-reaching adoption of these models, harm can diffuse at unprecedented speed throughout society. To contain the damage, for example, when a model suffers from a security breach or a hazardous malfunction, it is essential for providers to plan ahead and identify emergency mitigations in advance.
  4. Providers got what they wanted: unilateral discretion over the most fundamental aspects of risk management. Their lobbying to change the Code has resulted in predominantly outcome-based rules, relying on the good will of providers to comply instead of defining the steps needed for effective risk management. Providers are now ultimately responsible for identifying systemic risks, setting thresholds for unacceptable risk, and determining milestones for continuous model assessment. Given such discretion, they now have to show the world they deserve this trust.

Going forward, we urge the European Commission, the AI Board, and GPAI providers to ensure that Europeans receive the AI rules they want and pressingly need.

  1. We urge the European Commission to institutionalize the involvement of independent academia and civil society when designing the Code’s review and update mechanism. Let’s continue the momentum and effectiveness of true multi-stakeholder dialogue.
  2. The AI Board must ensure that timelines for imposing GPAI rules are met, starting in August 2025, as was agreed upon in the EU AI Act.
  3. Lastly, we call on GPAI model providers. If they are serious about serving the public interest, they must work hard to achieve the safety outcomes they defined in the Code. It is time for their engineers to roll up their sleeves, to ensure comprehensive and constructive compliance, and not their lawyers, to find loopholes and avoid good governance. Now, they must live up to their words.

Team members

Related resources

2021 Edition of the Athens Roundtable on Artificial Intelligence and the Rule of Law

2021 Edition of the Athens Roundtable on Artificial Intelligence and the Rule of Law

An international, cross-organizational dialogue on how to uphold the rule of law in the age of AI.

Digital Insights into Modern Slavery Reporting: Challenges and opportunities of machine readability

Digital Insights into Modern Slavery Reporting: Challenges and opportunities of machine readability

In our Artificial Intelligence Against Modern Slavery (AIMS) project, Walk Free in collaboration with The Future Society, WikiRate, and the Business & Human Rights Resource Centre have published a paper on digital insights into modern slavery reporting, which discusses the challenges and opportunities of machine readability.

Project launch: Independent Auditing & Certification Ecosystem Design

Project launch: Independent Auditing & Certification Ecosystem Design

The scattershot development of independent auditing and certification for AI systems and organizations has jeopardized precisely what these schemes intended to ensure: confidence and trust. It is time to consider what a unified “end-state” ecosystem might look like, and build support across key players towards this vision.

Project AIMS (Artificial Intelligence against Modern Slavery)

Project AIMS (Artificial Intelligence against Modern Slavery)

AIMS built the first exploration of the application of machine learning to automate the analysis of statements produced by businesses under the UK Modern Slavery Act to boost compliance and help combat and eradicate modern slavery. Project AIMS is now open source on GitHub!

CAIAC Alliance Launch

CAIAC Alliance Launch

CAIAC is a decision-making support platform designed to dynamically map and advance our common knowledge of Covid-19 and its cascading effects. Its motto is one: better decisions faster. It presents comprehensive, authoritative, and up-to-date insights and solutions to decision makers along the full intervention lifecycle holistically across health, social and...

Global Governance of AI Forum (GGAF)

Global Governance of AI Forum (GGAF)

AI technologies are evolving rapidly across sectors, ushering in enormous potential for good but also the risks to fundamental human values, including human dignity and privacy.