⚡ Quick Summary
This is the Safety and Security Chapter of the Code of Practice for General-Purpose AI Models, a voluntary instrument addressed to providers of general-purpose AI models with systemic risk under the EU AI Act. The cover names the chairs and vice-chairs of Working Groups 2, 3 and 4; no publisher, publication date or version marking is printed in the extracted text.
Its stated objectives are to serve as a guiding document for demonstrating compliance with the obligations in Articles 53 and 55 AI Act, while recognising that "adherence to the Code does not constitute conclusive evidence of compliance", and to enable the European AI Office to assess compliance of providers who choose to rely on the Code.
The chapter is built on ten Commitments, each with Measures, covering the creation, implementation, updating and notification of a state-of-the-art Safety and Security Framework; systemic risk identification, analysis and acceptance determination; safety and security mitigations; Safety and Security Model Reports to the AI Office; allocation of systemic risk responsibilities; serious incident reporting; and additional documentation and public transparency. Four Appendices define the specified systemic risks (CBRN, loss of control, cyber offence, harmful manipulation), the "similarly safe or safer model" concept, model evaluation requirements and security mitigation objectives.
🧩 What’s Covered
The chapter moves from interpretation principles through ten Commitments to four Appendices and a Glossary.
- Recitals and principles: ten principles for interpretation, including Appropriate Lifecycle Management, Contextual Risk Assessment and Mitigation, Proportionality to Systemic Risks, Integration with Existing Laws, Cooperation, Innovation in AI Safety and Security, the Precautionary Principle, and simplified compliance for SMEs and SMCs.
- Commitment 1 – Safety and Security Framework: three steps (create, implement, update) plus notification of the AI Office; the Framework must describe trigger points for lighter-touch model evaluations, systemic risk acceptance criteria and tiers, responsibility allocation and its own update process, and be confirmed no later than four weeks after notifying the Commission and two weeks before placing the model on the market.
- Commitments 2 to 4 – identification, analysis and acceptance: a structured identification process against five types of risk (public health, safety, public security, fundamental rights, society), systemic risk scenarios, five analysis elements (model-independent information, model evaluations, risk modelling, risk estimation, post-market monitoring), and acceptance criteria with a safety margin.
- Commitments 5 and 6 – mitigations: eight example safety mitigations (data filtering, input/output monitoring, refusal training, staged access, agent-ecosystem techniques) and a Security Goal plus measures against unauthorised release, unauthorised access and model theft, with a stated exemption where a model is inferior to a publicly downloadable one.
- Commitment 7 – Model Report: content requirements in Measures 7.1 to 7.5, update triggers in Measure 7.6 including a six-month refresh for the most capable models, and notification to the AI Office with a possible 15-business-day delay.
- Commitments 8 to 10 – governance, incidents and transparency: allocation of systemic risk oversight, ownership, support and monitoring, and assurance; serious incident reporting with 2, 5, 10 and 15-day timelines, four-weekly intermediate reports and a 60-day final report; ten-year documentation retention and summarised public versions of Framework and Model Reports.
- Glossary and Appendices: definitions such as "state of the art", "deception", "model elicitation" and "non-state external threats", plus Appendices 1 to 4 on specified systemic risks, similarly safe or safer models, model evaluations and security mitigation objectives 4.1 to 4.5.
💡 Why it matters?
The chapter gives providers of general-purpose AI models with systemic risk an operational route through the AI Act's Article 55 obligations: what to assess, how to record acceptance decisions, which mitigations to implement and what to send to the AI Office, with concrete deadlines and retention periods. For assessors and auditors it supplies checkable artefacts: Frameworks, Model Reports, serious incident reports, security mitigation objectives and independent external evaluation requirements. The document itself links the regime to outside instruments, allowing reliance on international standards to the extent they cover the chapter and citing the International Network of AI Safety Institutes and the RAND model-weights work.
❓ What’s Missing
The extracted text carries no publisher, publication date, version number or reference identifier, so the specific published version cannot be confirmed from the document alone. Quantitative thresholds are largely absent: systemic risk tiers, acceptance criteria and safety margins are to be defined by Signatories, and the chapter offers principles rather than fixed values. Simplified compliance for SMEs and SMCs is repeatedly acknowledged but not specified in operational detail. The chapter applies only to general-purpose AI models with systemic risk, not to AI systems, and it defers key interpretations to AI Act definitions and AI Office guidance rather than restating them.
👥 Best For
Compliance and legal teams at providers of general-purpose AI models with systemic risk who must build a Safety and Security Framework and Model Report; internal audit, risk and assurance functions allocating systemic risk responsibilities; safety, security and evaluation engineers designing model evaluations, post-market monitoring and mitigation programmes; and third-party reviewers or regulators assessing whether a provider's reported processes meet the chapter's expectations.
📄 Source Details
Full title: Code of Practice for General-Purpose AI Models Safety and Security Chapter. No publisher, place of publication, publication year, version or reference number is printed in the extracted text. The cover names nine working group chairs and vice-chairs: Matthias Samwald, Yoshua Bengio, Marietje Schaake, Marta Ziosi, Daniel Privitera, Anka Reuel, Alexander Zacherl, Nitarshan Rajkumar and Markus Anderljung. The document is in English and runs to 43 pages; the text extraction covers all 43 pages. No URL is printed.