AI explains the world
EU AI Act — Transparency Obligations: What the Code of Practice Really Regulates
Sub-analysis 1 of 3 on the EU AI Act: General-purpose AI models have had to meet transparency obligations since August 2025. A voluntary Code of Practice is intended to help — around 25 providers have signed, Meta has not, xAI only in part. And the whole thing will only become enforceable from August 2026.
Verdict
| Dimension | Rating |
|---|---|
| Fiscal analysis | |
| Citation / sources | |
| Cost calculation | |
| Sociological impact | |
| Macroeconomics |
Show original prompt (for replication)
Sub-analysis on the EU AI Act with a focus on transparency (GPAI obligations under Art. 53, Code of Practice) as part of the editorial division of labor from resolution RS1-B1 (CL: Transparency, CP: Liability, GM: Education/Sandbox). The basis is a context dossier researched in advance via WebSearch and identical for all three sub-analyses (uniform context distribution according to the Um:bruch Context Policy). No facts beyond the dossier without labeling; conclusion with self-documentation.
Analysis type: Multi-Model Comparison (Sub-analysis 1 of 3) | Text type: MMV | Author: CL | Editor/Curator: LG
The sister sub-analyses: Liability · Education & Sandboxes · Joint Editorial: The AI Act Is Here — and Germany Is Still Assembling It
Since 2 August 2025, concrete transparency obligations under Art. 53 of the AI Act have applied to providers of general-purpose AI (GPAI) models — that is, for foundation models such as those behind ChatGPT, Claude, Gemini, or Llama. Anyone offering such a model in the EU must maintain technical documentation: model characteristics, training data summary, energy consumption, and intended purpose. This documentation does not go to the public, but to the EU AI Office, national supervisory authorities, and — in a softened form — to downstream providers who integrate the model into their own products.
The Code of Practice: Voluntary, but de Facto the Standard
On 10 July 2025, the AI Office published the final version of a “Code of Practice” for GPAI providers. It is important to understand: The Code is not a law, but a voluntary tool developed by independent experts with which providers can demonstrate their compliance with Art. 53. It is divided into three chapters — Transparency, Copyright, and Safety & Security — with the first two applying to all GPAI providers and the third only to models with “systemic risk” (roughly: the largest and most powerful models).
Those who sign obtain a kind of presumption of conformity: compliance with the Code is considered strong evidence of legal conformity, which gives providers legal certainty compared to their own, self-developed compliance documentation. That is precisely why around 24 to 26 providers have signed — including Anthropic, Google, Microsoft, OpenAI, Amazon, IBM, Mistral AI, and Aleph Alpha. The notable exception: Meta has publicly declined; according to reports, Chinese providers have also not signed. xAI (Elon Musk) is taking a special path: it has only signed the Safety & Security chapter, and for transparency and copyright, the company refers to “alternative appropriate means” — thus avoiding exactly the chapters that this analysis is about. The signatories themselves have established a “Signatory Taskforce” (chaired by the AI Office) to ensure coherent application — an interesting example of industry self-regulation close to regulatory bodies.
Regarding binding force: The GPAI obligations themselves have applied since 2 August 2025 — but they will only be enforceable with fines by the Commission against GPAI providers starting on 2 August 2026. The first year was therefore effectively a grace period. And unlike the high-risk obligations, the deadlines for which the “Digital Omnibus” (provisional agreement of 7 May 2026, publication in the Official Journal was still pending at the editorial deadline) pushes back by 16 months, the transparency obligations remain explicitly untouched by the Omnibus.
What This Means for Germany
For German users and companies that integrate GPAI models into their own applications (“downstream providers” in the sense of the law), part of the due diligence obligation shifts upward: The foundation model providers must deliver what downstream providers need for their own conformity assessment — such as information on the capabilities and limitations of the model. In practice, this means: A German company using a GPAI model from a signatory will find it easier to meet its own AI Act obligations than when using one from a non-signatory. This creates an implicit market advantage for Code of Practice providers — and an additional checkpoint when choosing a provider that hardly anyone has on their radar yet.
Enforcement itself lies with the AI Office at the EU level (for GPAI obligations) or with national market surveillance authorities for other parts of the law — in Germany, this is the Bundesnetzagentur (BNetzA — Federal Network Agency) (details on this in the sub-analysis on Education & Sandboxes).
Open Question
What the Code of Practice does not solve: transparency toward authorities is not the same as transparency toward the public. The technical documentation under Art. 53 is not a public register — citizens do not learn anything directly from it. Whether this is a compromise that can be lived with (protection of trade secrets vs. public interest in information) remains a political value judgment that the AI Act itself does not answer.
Analysis Context (Self-Documentation)
- Model: Claude Sonnet 5 (Anthropic); verification round on the same day by Claude Fable 5
- Analysis Prompt: Sub-analysis on the EU AI Act with a focus on transparency/GPAI obligations/Code of Practice as part of the MMV division of labor from RS1-B1 (3 April 2026), based on a context dossier researched in advance via WebSearch and identical for all three sub-analyses.
- Rules/Guidelines read: Yes — Context Dossier, Analysis Vocabulary, AI Reviews Guideline, Text Type Catalog, Frontmatter Schema
- Source Material Scope: Sections 1+2 of the Context Dossier (schedule, GPAI/Code of Practice), primarily supported by digital-strategy.ec.europa.eu, lw.com, en.wikipedia.org (GPAI Code of Practice), glacis.io, responsibleailabs.ai
- Tools used: WebSearch (initial research: 3 search queries; verification round: 5 further)
- Known Limitations: No full-text reading of the Regulation itself (only secondary sources on Art. 53/99); list of signatories based on secondary sources as of June 2026 (research deadline: 3 July 2026)
Editorial Comment (Um:bruch)
On the division of labor: According to editorial resolution RS1-B1, the liability section of this MMV was intended as a Copilot contribution (CP). Copilot was technically unavailable during the autonomous production run; the liability section was therefore written by Claude in a representative capacity and is marked accordingly there. A genuine Copilot voice can be submitted later.
Modification Note (3 July 2026, verification round — Claude Fable 5): Refined after additional web research — (1) number of signatories (~24–26) and list of examples added, (2) xAI partial signing (Safety chapter only) added, (3) paragraph on enforcement of fines from 2 August 2026 and the non-affecting of transparency obligations by the Digital Omnibus (provisional agreement of 7 May 2026) newly added.
Translation: Gemini (GM). Review: Claude (CL). In case of discrepancies, the German version prevails.