GPAI Code of Practice vs EU AI Act Annex IV: What Providers Must File
EU AI Act Annex IV is the statutory technical documentation baseline for general-purpose AI model providers. It requires current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections. The GPAI Code of Practice is different: it is a voluntary compliance tool under the AI Act that helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security. Providers should treat Annex IV as the required documentation structure and the Code as an evidence-mapping framework that can organize governance records, security controls, audit trails, and operational compliance practices.
The distinction compliance teams need to preserve
For GPAI providers, Annex IV and the GPAI Code of Practice serve related but different compliance functions. Annex IV is the required technical documentation baseline. It is the structure providers must be prepared to maintain and file, with current information about the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections.
The GPAI Code of Practice is not the same document. It is a voluntary conformity-support framework under the AI Act. Its role is to help providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security.
The practical takeaway is straightforward: treat Annex IV as the documentation structure, and use the Code as an evidence-mapping framework. That mapping can organize governance records, security controls, audit trails, and operational compliance practices around the obligations they support.
GPAI Code of Practice vs EU AI Act Annex IV
The comparison below separates the mandatory documentation baseline from the voluntary operating framework and the runtime evidence that can support compliance operations.
| Artifact | Role for providers | Evidence focus |
|---|---|---|
| Annex IV | Mandatory technical documentation covering model description, training, testing, evaluation, limitations, and cybersecurity protections. | Current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections. |
| GPAI Code of Practice | Voluntary conformity-support framework organized around transparency, copyright, and safety and security commitments. | Evidence that helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security. |
| Operational evidence | Runtime policies, access controls, audit logs, incident records, and evaluation artifacts can help support documentation and regulator responses. | Governance records, security controls, audit trails, and operational compliance practices mapped to Annex IV fields and Code commitments. |
What Annex IV expects providers to document
Annex IV is the statutory technical documentation baseline for general-purpose AI model providers. It requires current documentation describing the model, development and training process, testing and evaluation results, limitations, and cybersecurity protections.
Because Annex IV documentation is the filing baseline, compliance teams should keep it distinct from broader governance programs. Governance materials can support Annex IV, but the Annex IV package should remain structured around the required documentation categories.
How the Code changes the operating model
The GPAI Code of Practice is a voluntary compliance tool under the AI Act. It helps providers demonstrate how they meet GPAI obligations across transparency, copyright, and, for systemic-risk models, safety and security.
In practice, the Code can function as an evidence-mapping framework. It can help teams connect Annex IV documentation to governance records, security controls, audit trails, and operational compliance practices. That connection matters because regulator requests and internal assurance reviews often require both the formal documentation baseline and the evidence showing how governance works in deployed environments.
What changes for GPAI providers
Annex IV
Mandatory technical documentation covering model description, training, testing, evaluation, limitations, and cybersecurity protections.
GPAI Code of Practice
Voluntary conformity-support framework organized around transparency, copyright, and safety and security commitments.
Operational evidence
Runtime policies, access controls, audit logs, incident records, and evaluation artifacts can help support documentation and regulator responses.
Evidence architecture for GPAI compliance operations
A defensible evidence architecture should make regulator requests and internal assurance reviews retrieval problems, not reconstruction exercises. Runtime governance evidence does not replace Annex IV documentation, but it can support claims about deployed controls, security, monitoring, downstream-use restrictions, and incident handling.
-
Versioned evidence repository
Maintain a release-level repository that maps each model version to Annex IV fields, Code commitments, evaluation reports, security controls, and downstream documentation.
-
Model and data lineage
Capture model lineage, dataset references, training configuration, data governance records, evaluation runs, benchmark results, and approval history in auditable systems.
-
Runtime policy evidence
Use policy enforcement records to show how model access, tool use, privileged actions, human approvals, and prohibited behaviors are controlled in deployed environments.
-
Agent and tool auditability
For agentic systems, preserve agent identity, permissions, tool-call logs, and approval workflows so runtime behavior can be reviewed against governance policy.
-
Security and incident records
Connect cybersecurity controls, access logs, monitoring outputs, serious-incident workflows, and risk assessments to the relevant model and system version.
-
Disclosure separation
Separate public artifacts, such as training-content summaries, from confidential technical documentation containing proprietary architecture, data, or security details.
Strengthen the runtime evidence behind AI governance
Trussed AI helps enterprises govern and secure AI agents with runtime controls, policy enforcement, agent identity, permissions, tool approval workflows, and audit logging that can support AI compliance operations.
Request a Demo