See what Trussed catches that Annex IV misses, live in your stack

    No migration, no commitment, just a direct comparison in your environment.

    Set up a technical evaluation
    AI Compliance Comparison

    GPAI Code of Practice vs EU AI Act Annex IV: What Providers Must File

    EU AI Act Annex IV is the statutory technical documentation baseline for general-purpose AI model providers. It requires current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections. The GPAI Code of Practice is different: it is a voluntary compliance tool under the AI Act that helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security. Providers should treat Annex IV as the required documentation structure and the Code as an evidence-mapping framework that can organize governance records, security controls, audit trails, and operational compliance practices.

    The distinction compliance teams need to preserve

    For GPAI providers, Annex IV and the GPAI Code of Practice serve related but different compliance functions. Annex IV is the required technical documentation baseline. It is the structure providers must be prepared to maintain and file, with current information about the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections.

    The GPAI Code of Practice is not the same document. It is a voluntary conformity-support framework under the AI Act. Its role is to help providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security.

    The practical takeaway is straightforward: treat Annex IV as the documentation structure, and use the Code as an evidence-mapping framework. That mapping can organize governance records, security controls, audit trails, and operational compliance practices around the obligations they support.

    GPAI Code of Practice vs EU AI Act Annex IV

    The comparison below separates the mandatory documentation baseline from the voluntary operating framework and the runtime evidence that can support compliance operations.

    How the main compliance artifacts relate
    Artifact Role for providers Evidence focus
    Annex IV Mandatory technical documentation covering model description, training, testing, evaluation, limitations, and cybersecurity protections. Current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections.
    GPAI Code of Practice Voluntary conformity-support framework organized around transparency, copyright, and safety and security commitments. Evidence that helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security.
    Operational evidence Runtime policies, access controls, audit logs, incident records, and evaluation artifacts can help support documentation and regulator responses. Governance records, security controls, audit trails, and operational compliance practices mapped to Annex IV fields and Code commitments.

    What Annex IV expects providers to document

    Annex IV is the statutory technical documentation baseline for general-purpose AI model providers. It requires current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections.

    Because Annex IV documentation is the filing baseline, compliance teams should keep it distinct from broader governance programs. Governance materials can support Annex IV, but the Annex IV package should remain structured around the required documentation categories.

    How the Code changes the operating model

    The GPAI Code of Practice is a voluntary compliance tool under the AI Act. It helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security.

    In practice, the Code can function as an evidence-mapping framework. It can help teams connect Annex IV documentation to governance records, security controls, audit trails, and operational compliance practices. That connection matters because regulator requests and internal assurance reviews often require both the formal documentation baseline and the evidence showing how governance works in deployed environments.

    What changes for GPAI providers

    Annex IV

    Mandatory technical documentation covering model description, training, testing, evaluation, limitations, and cybersecurity protections.

    GPAI Code of Practice

    Voluntary conformity-support framework organized around transparency, copyright, and safety and security commitments.

    Operational evidence

    Runtime policies, access controls, audit logs, incident records, and evaluation artifacts can help support documentation and regulator responses.

    Evidence architecture for GPAI compliance operations

    A defensible evidence architecture should make regulator requests and internal assurance reviews retrieval problems, not reconstruction exercises. Runtime governance evidence does not replace Annex IV documentation, but it can support claims about deployed controls, security, monitoring, downstream-use restrictions, and incident handling.

    1. Versioned evidence repository

      Maintain a release-level repository that maps each model version to Annex IV fields, Code commitments, evaluation reports, security controls, and downstream documentation.

    2. Model and data lineage

      Capture model lineage, dataset references, training configuration, data governance records, evaluation runs, benchmark results, and approval history in auditable systems.

    3. Runtime policy evidence

      Use policy enforcement records to show how model access, tool use, privileged actions, human approvals, and prohibited behaviors are controlled in deployed environments.

    4. Agent and tool auditability

      For agentic systems, preserve agent identity, permissions, tool-call logs, and approval workflows so runtime behavior can be reviewed against governance policy.

    5. Security and incident records

      Connect cybersecurity controls, access logs, monitoring outputs, serious-incident workflows, and risk assessments to the relevant model and system version.

    6. Disclosure separation

      Separate public artifacts, such as training-content summaries, from confidential technical documentation containing proprietary architecture, data, or security details.

    Strengthen the runtime evidence behind AI governance

    Trussed AI helps enterprises govern and secure AI agents with runtime controls, policy enforcement, agent identity, permissions, tool approval workflows, and audit logging that can support AI compliance operations.

    Request a Demo