AI Governance, Risk & Red Teaming
Strategic · M17 · lesson 17 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
GPAI Code of Practice - Signatory vs Non-Signatory Consequence Workflow
📖
now learning

GPAI Code of Practice - Signatory vs Non-Signatory Consequence Workflow

15 min

The Acme.Foundations LLC board AI subcommittee opens its May 2026 meeting with a single question from the board chair to the Chief AI Officer: "We're nine months from publishing our new foundation model. The Code of Practice has been operating since July 2025. Do we sign it, yes or no, and what is the consequence either way?" The CAIO begins to answer, "Signing gives us presumption of compliance with Article 53(1) and Article 55", and the chair interrupts: "I don't want the slogan. I want the ten ways our life is different if we sign, the ten ways it is different if we don't, and the eight-step decision you walked through to reach your recommendation. Because if we sign and we can't operationally meet the commitments, that's a worse posture than not signing. And if we don't sign and the buyers we're trying to land in 2027 are requiring signatory status in their procurement DDQs, that's a commercial loss the board didn't ratify. Walk us through." This lesson is the L4 leadership-tier framework for the Code-of-Practice signatory-versus-non-signatory consequence workflow: the regulatory architecture under Articles 53, 55, and 56; the ten-dimension consequence taxonomy; the eight-step AIGC decision workflow; the 12-section signatory-readiness checklist; and the Acme.Foundations worked example showing the CAIO's recommendation to sign Transparency and Copyright now and defer Safety & Security until the next training run crosses the Article 51 systemic-risk threshold.

Articles 53, 55, 56 - The Regulatory Architecture and the Code of Practice

The General-Purpose AI (GPAI) provider regime under the EU AI Act sits in three primary articles. Article 53(1) imposes baseline obligations on every GPAI provider regardless of systemic-risk status: maintain up-to-date technical documentation (Article 53(1)(a) referencing Annex XI), provide downstream-deployer information (Article 53(1)(b) referencing Annex XII), implement a copyright-compliance policy that respects Article 4(3) of the Copyright Directive text-and-data-mining opt-outs (Article 53(1)(c)), and publish a sufficiently detailed summary of training content according to an AI Office template (Article 53(1)(d)). Article 53(2) carves out an open-source exemption for non-systemic-risk GPAI models whose parameters and architecture are publicly released under a free-and-open-source license: such providers may opt out of Article 53(1)(a) and 53(1)(b) but retain the copyright and training-content-summary obligations. Article 55 imposes additional obligations on systemic-risk GPAI providers. Those designated under Article 51 via either the FLOPs threshold (10^25 cumulative compute) or Commission designation per Annex XIII: model evaluation (Article 55(1)(a)), systemic-risk assessment and mitigation (Article 55(1)(b)), serious-incident tracking and reporting (Article 55(1)(c)), and cybersecurity protection for the model and its physical infrastructure (Article 55(1)(d)).

The enforcement timeline cuts the population in two. For GPAI models placed on the Union market on or after August 2, 2025, Article 53 and Article 55 obligations are live and supervisable by the AI Office under Article 88. For legacy GPAI models placed on the market before August 2, 2025, the obligations apply from August 2, 2026, and Omnibus VII left that August 2, 2026 deadline intact; only the high-risk Annex III deployer timeline shifted. The dual-population reality means in May 2026 the AI Office is supervising the August 2025 cohort under live obligations while the legacy cohort runs out a 12-week countdown to its own go-live. Acme.Foundations, training a brand-new foundation model with planned release in Q1 2027, falls firmly in the August-2025-onward cohort and has no transitional buffer to lean on.

Into this regulatory architecture, Article 56 introduced the Code of Practice, a voluntary, AI-Office-coordinated instrument that translates the statutory Article 53(1) and Article 55 obligations into concrete operational commitments. The European Commission, acting through the AI Office, convened working groups composed of GPAI providers, downstream deployers, civil society, rightsholders, and independent experts. The Code was finalized in July 2025 and adopted in three chapters: a Transparency chapter operationalizing Article 53(1)(a)-(b)-(d), a Copyright chapter operationalizing Article 53(1)(c), and a Safety & Security chapter operationalizing Article 55, the third chapter binding only on signatories who are also Article 51 systemic-risk providers. Each chapter contains "commitments" structured as "measures" with "sub-measures" and "key performance indicators (KPIs)" that signatories agree to implement and to evidence on AI Office inquiry. The Code is voluntary; non-signatory status is fully permissible under Article 56(7) so long as the provider demonstrates compliance with the underlying statutory obligations on its own evidence.

The legal effect of signature is procedural, not substantive. Article 56(1) states that adherence to the Code constitutes a "means by which providers can demonstrate compliance" with Article 53(1) and Article 55. The interpretation that has crystallized in 2025-2026 AI Office practice is a presumption-of-compliance posture: a signatory who has implemented the Code's measures is presumed compliant with the underlying article unless the AI Office presents contrary evidence; a non-signatory bears the burden of demonstrating compliance affirmatively, typically via more extensive own documentation and more frequent Article 89 information-request dialogues. The distinction is not penalty-avoidance, Article 99(3) at €15M / 3% of global turnover applies to Article 53 and Article 55 failures regardless of signatory status, but enforcement-friction reduction. The signatory experiences AI Office engagement as structured dialogue through Code working groups; the non-signatory experiences it as ad-hoc Article 89 information requests, each requiring custom evidentiary response.

The Ten Dimensions of Signatory vs Non-Signatory Consequence

The L4 governance lead's analytical task is to make the signatory-versus-non-signatory question concrete across the ten dimensions where the consequence diverges. The dimensions are orthogonal, a provider may face high impact on some and low on others, and the AIGC decision should be informed by the firm's actual exposure across each:

  • (1) Presumption of compliance. Code adherence creates a presumption of compliance with Article 53(1) (transparency + copyright + downstream documentation) and, for systemic-risk providers, Article 55 (model evaluation + systemic-risk mitigation + incident reporting + cybersecurity). The presumption is procedural, the AI Office may rebut it with contrary evidence, but the rebuttal carries the AI Office's burden, not the provider's. Non-signatories must demonstrate compliance on their own evidence from first principles in every information-request dialogue.
  • (2) Documentation evidentiary burden. The non-signatory typically must produce more extensive own documentation to demonstrate Article 53(1)(a) Annex XI technical documentation, Article 53(1)(b) Annex XII downstream-deployer information, Article 53(1)(c) copyright policy effectiveness, and Article 53(1)(d) training-content summary completeness. The signatory's documentation flows from the Code's template structures (training-data summary template, downstream-deployer information template) and inherits the AI Office's pre-validated form. The differential is roughly 2-3x evidentiary lift for the non-signatory in a contested Article 89 dialogue, per practitioner reports through 2026 Q1.
  • (3) AI Office engagement cadence. Signatories engage the AI Office through structured channels: Code working group meetings, quarterly Code-measure review sessions, and pre-publication consultations on template refinements. Non-signatories engage on an ad-hoc basis through Article 89 information requests, typically triggered by external complaint, downstream-deployer escalation, or AI Office market-monitoring. The signatory's cadence is predictable and consultative; the non-signatory's cadence is reactive and adversarial-tinted.
  • (4) Reputational exposure. The AI Office publishes the list of Code signatories. Publicly listed signatories include the major frontier-model providers; publicly listed non-signatories (or providers absent from the list despite Article 51 designation) face increasing media, civil-society, and downstream-buyer scrutiny. The reputational asymmetry is not statutory but practical: in the 2026 media environment, "did not sign the Code" is treated as a governance flag, particularly for systemic-risk providers.
  • (5) Auditor pre-approval friction. ISO 42001 certification auditors (BSI, Schellman, A-LIGN) and SOC 2+AI auditors are increasingly treating Code signatory status as a positive control in the AIMS audit. Signatory status maps directly to ISO 42001 Annex A.5 (resources and competence to operate the AIMS) and A.7 (planning of changes to the AIMS), and to Clause 5 (leadership commitment). Non-signatories are not excluded from certification but must produce additional evidence to satisfy the same control objectives, increasing audit hours and findings risk.
  • (6) Buyer/deployer procurement preference. The 2026 enterprise procurement DDQ (vendor due diligence questionnaire), covered in lesson 070 of this program, now routinely weights Code signatory status as a Tier-A factor for foundation-model selection. Regulated-sector buyers (financial services under SR 11-7 + PRA SS1/23, healthcare under EU MDR, employment under NYC LL 144) face downstream compliance pressure to demonstrate they sourced from compliant providers; signatory status is the cleanest evidence. A non-signatory provider may lose 15-30% of regulated-sector procurement opportunities in 2026 absent a compelling alternative-evidence narrative.
  • (7) Article 99(3) penalty multiplier risk. Article 99(3) penalties for Article 53 and 55 failures cap at €15M or 3% of global turnover, whichever is higher. The cap applies regardless of signatory status. But Article 99(7) directs supervisory authorities to consider proportionality in setting the penalty, including the provider's good-faith compliance efforts. Practitioner expectation, validated in early 2026 AI Office guidance, is that Code adherence will be a factor in proportionality assessment, pushing signatory penalties toward the lower bound of the range and non-signatory penalties toward the upper bound for equivalent underlying conduct.
  • (8) Insurance underwriting. The AI-tail insurance market emerged in 2025-2026 to cover AI-specific liability: model failures, output-driven harms, regulatory exposure beyond the underlying enterprise E&O policy. AI-tail underwriters (Lloyd's syndicates, Munich Re, AIG) are increasingly requesting Code signatory attestation as part of underwriting submissions for GPAI providers. Signatory status reduces premium loadings; non-signatory status either increases premiums or restricts coverage scope. The differential is material on policy limits in the €25M+ range.
  • (9) Open-source carve-out interplay. Article 53(2) exempts non-systemic-risk open-source GPAI providers from Article 53(1)(a) and 53(1)(b), the Annex XI technical documentation and Annex XII downstream-deployer information obligations, but retains the copyright (53(1)(c)) and training-content-summary (53(1)(d)) obligations. A Code signatory who releases an open-source model must clarify, in its Code submission, the OSS posture and the scope of the carve-out it invokes. A non-signatory OSS provider relies entirely on the statutory exemption without Code-signatory positioning. The interplay matters for hybrid releases (model weights open-source, fine-tuning data proprietary) and for foundation-model providers maintaining both open and closed product lines.
  • (10) Downstream deployer evidence production. Annex XII requires the GPAI provider to supply downstream deployers with sufficient information for the deployer to understand the model's capabilities, limitations, intended uses, and integration parameters. Signatory providers produce this information via Code-template flows that downstream deployers have learned to consume, the template structure has become a de-facto interoperability layer for 2026 deployer documentation. Non-signatory providers must produce equivalent information in custom formats, increasing friction for downstream deployers conducting Article 26 deployer due diligence, FRIA preparation under Article 27, and DPIA-FRIA integration under GDPR Article 35.

The dimensions are weighted by firm profile. A non-systemic-risk closed-source GPAI provider serving primarily enterprise buyers in regulated sectors faces highest exposure on dimensions 1, 2, 6, 7, and 10. A systemic-risk frontier-model provider serving global consumer markets faces highest exposure on dimensions 1, 3, 4, 7, and 8. An open-source non-systemic-risk provider faces highest exposure on dimensions 4, 9, and 10. The AIGC's task is to map the firm's profile against the ten dimensions and to recommend a signatory posture calibrated to that exposure pattern, not to a generic "sign / don't sign" default.

The Eight-Step AIGC Decision Workflow

The mature 2026 AIGC decision workflow for the signatory question proceeds through eight ordered steps. Each step produces a documented output that the AIGC ratifies before progressing; the cumulative documentation becomes the audit trail for the board AI subcommittee's eventual ratification of the signatory posture:

  • Step 1 - Establish provider status. The first question is whether the firm is a GPAI provider at all under Article 3(63). If the firm is a pure deployer that consumes upstream GPAI models without training or substantial fine-tuning, the Code question is moot, the firm has no signatory option because it has no GPAI to bring to the Code. If the firm has done substantial fine-tuning under Article 25(1)(b) that would make it a provider of a fine-tuned model, the analysis proceeds. If the firm has trained a foundation model from base parameters, the analysis proceeds with priority. Output: documented provider-status determination signed by the General Counsel and Chief AI Officer.
  • Step 2 - Test systemic-risk designation. The second question is whether the firm's GPAI model meets the Article 51 systemic-risk threshold. The two pathways: Article 51(1), cumulative training compute equal to or greater than 10^25 floating-point operations (FLOPs); or Article 51(2) / Annex XIII, Commission designation based on additional criteria (number of parameters, dataset size, registered business users, modality, market reach). The firm computes its training-compute estimate against the 10^25 threshold and forecasts the same for the planned next training run. Output: documented systemic-risk determination with FLOPs estimate, parameter count, dataset size, and forward-looking forecast for the next 24 months of training plans.
  • Step 3 - Map current posture against the three Code chapters. The third question is the firm's current operational maturity against the Code's three chapters. The Transparency chapter measures map to training-data summary publication, Annex XI technical documentation completeness, Annex XII downstream-deployer information templates, and AI Office template adoption. The Copyright chapter measures map to TDM opt-out detection capability, robots.txt and meta-tag honoring, machine-readable opt-out signals (TDMRep), rightsholder engagement channels, and audit-trail retention. The Safety & Security chapter measures (only if systemic-risk) map to model evaluation methodology, red-team capability, systemic-risk identification framework, post-deployment monitoring, and serious-incident reporting infrastructure. Output: a chapter-by-chapter maturity scorecard rating each measure as operating, partial, or gap.
  • Step 4 - Gap-assess for new operational lift. The fourth question is which Code commitments would require new operational lift if the firm signed. A "gap" rating in Step 3 translates to a remediation plan with named owner, timeline, and budget. A "partial" rating translates to a hardening plan. An "operating" rating translates to evidence-collection only. The gap inventory drives the cost side of the cost-benefit analysis in Step 5. Output: remediation plan with FTE estimate, dollar estimate, and timeline against the firm's existing roadmap.
  • Step 5 - Cost-benefit analysis. The fifth question is the net benefit of signature. The benefit side: presumption of compliance value (lower Article 89 friction, lower Article 99(3) penalty exposure), audit cost reduction (ISO 42001 + SOC 2+AI hours), procurement win-rate improvement (regulated-sector buyer preference), reputational positioning, insurance premium reduction. The cost side: implementation cost from Step 4, ongoing measurement and reporting cost, AI Office working-group participation cost. The CFO and CRO co-own this analysis with the CAIO. Output: signed cost-benefit memo with three-year NPV estimate.
  • Step 6 - Strategic positioning evaluation. The sixth question is the strategic positioning beyond the cost-benefit math. Buyer signaling, does the firm's go-to-market strategy depend on regulated-sector buyers who weight signatory status? Regulator engagement, does the firm want a structured-dialogue channel with the AI Office for forward-looking influence on Code refinements? Open-source posture, does the firm's OSS strategy benefit from explicit Code-signatory clarification of the Article 53(2) carve-out? Competitive positioning, what posture have peer GPAI providers taken, and is the firm's posture aligned with or differentiated from peers? Output: positioning memo from the Chief Strategy Officer with CAIO co-signature.
  • Step 7 - Governance ratification. The seventh step is the AIGC's formal recommendation to the board AI subcommittee. The recommendation packages Steps 1-6 into a decision memo with three options: sign all three chapters, sign Transparency + Copyright (defer Safety & Security pending systemic-risk threshold), or do not sign (with a written compensating-evidence plan). The board AI subcommittee ratifies the recommendation and the full board records it at the next quarterly review. Output: board-ratified signatory posture documented in the AIGC charter and the AI Risk Appetite Statement (AIRA).
  • Step 8 - Periodic reassessment. The eighth step is the annual reassessment cadence. The AIGC re-runs Steps 1-6 annually or on trigger events: a new training run crossing the 10^25 FLOPs threshold, a Commission designation under Annex XIII, a Code revision adopted by the AI Office, a material change in the firm's product portfolio (closed-to-open transition, new modality, geographic expansion), or a regulatory enforcement action against a peer. The reassessment may upgrade, downgrade, or maintain the signatory posture. Output: annual signatory-posture reassessment memo with board ratification.

The eight steps are sequential because each informs the next. Skipping Step 1 (establishing provider status) risks the firm investing AIGC bandwidth in a Code question that does not apply to its actual legal position. Skipping Step 2 (testing systemic-risk) risks signing the Safety & Security chapter without the underlying obligation, increasing operational burden without regulatory benefit. Skipping Step 3 (mapping posture) risks committing to Code measures the firm cannot operationally meet, exposing it to Article 56(8) AI Office concerns about Code-commitment non-fulfillment that the AI Office may treat more severely than a non-signatory's transparent absence from the Code. The discipline of the workflow is the discipline of a decision that defends to the regulator, the board, and the auditor.

Twelve-Section Signatory-Readiness Checklist

Before the AIGC recommends signature, the firm should complete the twelve-section signatory-readiness checklist. The checklist mirrors the structure of the three Code chapters and adds the governance and evidence-collection scaffolding that operates the Code's measures in production:

  • (1) Provider-status and systemic-risk determinations documented. Step 1 and Step 2 outputs filed, signed by General Counsel and CAIO, refreshed annually or on trigger.
  • (2) Article 53(1)(a) Annex XI technical documentation complete and AI-Office-template-aligned. Training process, evaluation results, capabilities, limitations, intended uses, integration requirements documented per the Annex XI structure; reviewed by Internal Audit; refreshed on each training run.
  • (3) Article 53(1)(b) Annex XII downstream-deployer information published. Capabilities, limitations, intended uses, prohibited uses, integration parameters, energy consumption, technical means for downstream integration documented in the Annex XII structure; available to downstream deployers via the firm's developer portal or model card.
  • (4) Article 53(1)(c) copyright policy published. Policy describes Article 4(3) Copyright Directive TDM opt-out compliance, robots.txt and meta-tag honoring, machine-readable opt-out signal (TDMRep, Tdm-Reservation header) detection, rightsholder engagement channel, internal audit trail of crawler exclusion decisions; refreshed on opt-out-convention evolution.
  • (5) Article 53(1)(d) training-content summary published per AI Office template. Categories of training content (web data, licensed data, user-generated, synthetic), proportions, language coverage, key dataset names where releasable, exclusion rationale for non-released datasets; available on the firm's website and registered with the AI Office.
  • (6) Article 55(1)(a) model evaluation operating (systemic-risk only). Capability evaluation methodology, benchmark suite, red-team protocol, adversarial robustness assessment, dual-use risk assessment, downstream-impact evaluation; results retained per audit policy.
  • (7) Article 55(1)(b) systemic-risk assessment and mitigation operating (systemic-risk only). Identified systemic risks (CBRN, cyber, election integrity, child safety, market manipulation, autonomous-replication), mitigation measures per risk, residual-risk acceptance documented, AIGC ratification.
  • (8) Article 55(1)(c) serious-incident tracking and reporting (systemic-risk only). Incident definition aligned to Article 73, internal reporting workflow, AI Office notification template, post-incident review, public-disclosure decision framework.
  • (9) Article 55(1)(d) cybersecurity protection (systemic-risk only). Model weights and physical infrastructure security controls, third-party penetration testing cadence, supply-chain security for training pipeline, ISO 27001 or equivalent attestation.
  • (10) AI Office engagement protocol. Named primary contact, Article 89 information-request response workflow, Code working-group participation cadence, escalation protocol for AI Office concerns.
  • (11) Internal evidence-collection infrastructure. Document management system tagged to each Code measure, KPI dashboard for Code-measure operating effectiveness, quarterly AIGC review, annual board AI subcommittee report.
  • (12) Public-facing signatory disclosure. Signatory status reflected in firm's sustainability/governance report, model card, terms of service, and procurement DDQ responses; refreshed annually or on Code revision.

The checklist is the operational predicate to signature. A firm that signs without items 1-5 (or items 1-9 for systemic-risk providers) operationally in place exposes itself to Article 56(8) AI Office concerns about non-fulfillment of Code commitments, a posture that the AI Office is empowered to address through Article 88 supervisory action up to and including Article 99(3) penalty escalation. The mature 2026 posture is to complete the checklist before signing, signal intent to sign during the implementation window, and execute signature only when items 1-5 (or 1-9) are evidenced as operating. The checklist also becomes the steady-state operating cadence post-signature: the AIGC reviews each item quarterly, the Second Line of Defense tests evidence of effectiveness, the Third Line audits adherence annually, and the board AI subcommittee receives a signatory-posture report semi-annually.

Acme.Foundations LLC - Worked Example: The CAIO's Recommendation

Acme.Foundations LLC is a Delaware-incorporated foundation-model development company with EU operations through an Irish subsidiary. The firm has trained three generations of in-house foundation models since 2023; the current production model (released October 2025) used approximately 8.4 × 10^24 FLOPs of training compute, below the Article 51(1) systemic-risk threshold of 10^25. The planned next-generation model, in training as of May 2026 with public release targeted for Q1 2027, is projected at 2.1 × 10^25 FLOPs, comfortably above the systemic-risk threshold. The firm sells to enterprise customers in financial services, healthcare, and government; revenue runs 64% North America, 28% EU, 8% UK; ARR is €420M growing 78% year-over-year.

The CAIO walks the AIGC through the eight-step decision:

  • Step 1 - Provider status. Acme.Foundations is a GPAI provider under Article 3(63); the current model is on the EU market via the Irish subsidiary and the AI Office is the supervisory authority. Determination signed by GC and CAIO on May 4, 2026.
  • Step 2 - Systemic-risk designation. Current model: 8.4 × 10^24 FLOPs, non-systemic-risk under Article 51(1). Planned Q1 2027 model: 2.1 × 10^25 FLOPs, projected systemic-risk under Article 51(1); the firm anticipates Commission notification under Article 52 within 14 days of crossing the threshold (expected mid-Q4 2026 based on the training schedule).
  • Step 3 - Posture map against the three Code chapters. Transparency chapter: 4 of 5 measures operating, 1 measure (training-data summary publication) partial (the firm has an internal draft using the AI Office template but has not yet published). Copyright chapter: 4 of 5 measures operating, 1 measure (rightsholder engagement channel) partial (an inbound email address exists but no SLA or workflow). Safety & Security chapter: 2 of 6 measures operating, 2 partial, 2 gap, the firm has model-evaluation methodology and incident-tracking but lacks formal systemic-risk identification framework and dedicated cybersecurity attestation.
  • Step 4 - Gap assessment. Transparency: 4 weeks of compliance-engineering effort to publish the training-data summary and refresh quarterly. Copyright: 6 weeks to stand up the rightsholder engagement workflow with SLAs and named owner. Safety & Security: 6 months of effort across model-evaluation expansion, systemic-risk framework formalization, ISO 27001 readiness, third-party penetration testing, total estimated cost €2.1M FTE plus €350K external consulting.
  • Step 5 - Cost-benefit. Transparency + Copyright signature: implementation cost €280K; presumption-of-compliance value €1.2-2.1M three-year NPV (lower Article 89 friction, lower audit cost, procurement win-rate +12% in regulated-sector EU pipeline); net positive €920K-1.82M. Safety & Security signature now: implementation cost €2.45M; presumption-of-compliance value €600K-1.1M (lower because the firm is not yet systemic-risk; the value is forward-looking, not current); net negative €1.35-1.85M. Cost-benefit clearly favors Transparency + Copyright signature now and Safety & Security signature timed to the Q4 2026 systemic-risk threshold crossing.
  • Step 6 - Strategic positioning. Buyer signaling: 64% of EU financial-services pipeline DDQs in Q1 2026 explicitly asked Code-signatory status; a "no" answer is reducing win-rate. Regulator engagement: the firm wants a Code working-group seat to influence the next Transparency chapter revision targeting Q1 2027. OSS posture: the firm releases small-model open-source under Apache 2.0; Article 53(2) carve-out clarification benefits from Code-signatory positioning. Competitive: three of the five frontier-model providers are full signatories; two are Transparency+Copyright signatories deferring Safety & Security - Acme's recommended posture aligns with the two-chapter peers.
  • Step 7 - Governance ratification. CAIO recommends to the AIGC: sign Transparency and Copyright chapters effective June 1, 2026; defer Safety & Security signature to Q4 2026 contingent on the systemic-risk-threshold-crossing milestone and completion of the 6-month gap remediation; integrate the signatory posture into the AIRA and the AIGC charter. AIGC ratifies May 14, 2026; board AI subcommittee ratifies May 22, 2026; full board records at June 12, 2026 quarterly meeting.
  • Step 8 - Periodic reassessment. Annual reassessment scheduled May 2027; trigger-based reassessment on the Q4 2026 systemic-risk threshold crossing (will upgrade the posture to full three-chapter signatory if the readiness checklist items 6-9 are operating); trigger-based reassessment on any Code revision or peer-competitor posture change.

The decision was documented as a four-page memo to the board AI subcommittee with the eight-step rationale, the cost-benefit math, the readiness checklist current state, the implementation timeline, and the public-disclosure plan. The board AI subcommittee minutes recorded the ratification with named-director vote; the AIRA was updated from v2026.Q1 to v2026.Q2 with the new signatory-posture section; the AIGC charter was updated to include the Code-engagement standing item. The CAIO's public statement on June 1, 2026 announced the Transparency + Copyright signature with explicit framing of the Safety & Security deferral as "timed to our Article 51 systemic-risk crossing in Q4 2026, at which point we will execute the third chapter signature in coordination with the AI Office." The framing converted a partial-signature posture into a credible compliance trajectory, the AI Office Code-engagement team responded with a working-group invitation within 18 days.

Cross-Walks, Penalty Exposure, and the 2026-2027 Outlook

The signatory question intersects multiple regulatory and standards frameworks. The L4 governance lead's cross-walk for any AIGC decision memo includes:

  • EU AI Act. Article 53(1) (baseline GPAI obligations); Article 53(2) (open-source carve-out for non-systemic-risk); Article 53(4) (downstream-provider obligations on substantial modification); Article 55 (systemic-risk obligations); Article 56 (Code of Practice voluntary instrument); Article 88 (AI Office supervisory authority); Article 89 (information requests); Article 99(3) (€15M / 3% penalty cap for Article 53 + 55 failures); Article 99(7) (proportionality factors). Annex XI (technical documentation contents); Annex XII (downstream-deployer information contents); Annex XIII (systemic-risk designation criteria).
  • ISO/IEC 42001:2023. Annex A.5 (resources and competence to operate the AIMS - Code-signatory infrastructure is positive evidence); Annex A.7 (planning of changes to the AIMS, Code revision response cadence); Clause 5 (leadership commitment, board-ratified signatory posture); Clause 9 (performance evaluation, KPI dashboard for Code measures).
  • NIST AI RMF. Govern 1.1 (legal and regulatory requirements documented, signatory posture is documentation evidence); Govern 2.1 (roles and responsibilities, Code-engagement contact named); Map 1.1 (context understood, buyer/regulator/competitor signaling); Manage 4.1 (post-deployment monitoring, incident-reporting cadence). Govern 5.1 (external engagement, Code working-group participation).
  • CycloneDX 1.7 ML-BoM. Where the GPAI provider's model is downstream-consumed, the ML-BoM identifies the model component; signatory status can be an attribute of the model component, communicating the compliance posture to downstream consumers.
  • OECD AI Principles. Principle 1 (responsible stewardship of trustworthy AI, signatory status is public stewardship evidence); Principle 5 (accountability, Code commitments are accountability commitments).

Penalty exposure. Article 99(3) at €15M / 3% applies to Article 53 and 55 failures regardless of signatory status. The signatory-versus-non-signatory differential operates at three levers: (a) Article 99(7) proportionality factors, where good-faith Code compliance pulls penalties toward the lower bound; (b) probability of enforcement, where signatory providers experience predictable Code working-group dialogue and non-signatory providers experience ad-hoc Article 89 escalations that more frequently progress to formal enforcement; (c) Article 56(8) AI Office concerns about Code-commitment non-fulfillment, which apply only to signatories who fail to operate their committed measures, meaning a signatory who signs without the readiness checklist operating exposes itself to a regulatory friction the non-signatory does not face. The implication is that signature is not a costless reputational signal; it is a binding commitment that the firm must operationally deliver. Signing without delivering is worse than not signing.

The Article 86 right-to-explanation downstream effect deserves explicit treatment. Article 86 entitles a deployer's affected natural person to an explanation of the role of the AI system in a decision producing legal or similarly significant effect. The deployer's ability to provide that explanation depends on the upstream GPAI provider's Annex XII downstream-deployer information being sufficiently detailed. A signatory provider's Code-template-aligned Annex XII output supports downstream Article 86 explanations efficiently; a non-signatory provider's custom-format Annex XII output may require deployer-side translation work to support Article 86, increasing the deployer's operational burden and the GPAI provider's commercial friction with regulated-sector deployers.

The 2026-2027 outlook centers on three convergent dynamics. First, the August 2, 2026 legacy GPAI go-live: the 12 weeks remaining as of mid-May 2026 are bringing late-mover firms to the signatory question under time pressure. Second, the Code's Transparency chapter revision expected Q1 2027: the revision will incorporate two years of operating experience and is likely to formalize KPI structures around training-data summary content and downstream-deployer information templates; current signatories will have working-group input on the revision, non-signatories will inherit the result without input. Third, the AI Office's enforcement posture maturation: the Office through Q1 2026 has emphasized cooperative dialogue with the signatory cohort and information-request escalation with the non-signatory cohort; practitioner expectation is that 2026-2027 will see the first Article 99(3) penalty proceedings against non-signatory providers with material Article 53 documentation gaps, establishing a published enforcement record that further weights the signatory question for late-decider firms. The Acme.Foundations posture, Transparency + Copyright signed in May 2026, Safety & Security committed for Q4 2026 contingent on the systemic-risk threshold crossing, represents the mature 2026 frontier-model decision for non-systemic-risk providers approaching the threshold; the framework adapts to firms at different points in the GPAI provider lifecycle, but the eight-step workflow remains the AIGC's defensible analytical path.

Key Takeaways

  • Articles 53 and 55 set the GPAI provider obligations (baseline transparency + copyright + downstream documentation for all; systemic-risk additions of model evaluation + mitigation + incident reporting + cybersecurity for Article 51-designated providers); Article 56 introduces the voluntary Code of Practice in three chapters (Transparency, Copyright, Safety & Security) that translates the statutory obligations into operational commitments, Omnibus VII left the August 2, 2026 legacy-GPAI go-live unchanged.
  • Code signature creates a procedural presumption of compliance with Article 53(1) and (for systemic-risk providers) Article 55; non-signatories bear the affirmative burden of demonstrating compliance on their own evidence in Article 89 information-request dialogues, the differential is enforcement friction, not penalty avoidance.
  • Ten dimensions of signatory-vs-non-signatory consequence: presumption of compliance, documentation evidentiary burden, AI Office engagement cadence, reputational exposure, auditor pre-approval friction, buyer/deployer procurement preference, Article 99(3) penalty multiplier risk, insurance underwriting, open-source carve-out interplay (Article 53(2)), and downstream deployer evidence production via Annex XII.
  • The eight-step AIGC decision workflow: establish provider status (Article 3(63)); test systemic-risk designation (Article 51 + Annex XIII); map current posture against the three Code chapters; gap-assess for new operational lift; cost-benefit analyze; evaluate strategic positioning; ratify in AIGC + board AI subcommittee; reassess annually or on trigger.
  • The 12-section signatory-readiness checklist operationalizes the decision: provider-status + systemic-risk determinations, Annex XI technical documentation, Annex XII downstream-deployer information, Article 53(1)(c) copyright policy, Article 53(1)(d) training-content summary, the four Article 55 measures (model evaluation, systemic-risk assessment, serious-incident tracking, cybersecurity), AI Office engagement protocol, internal evidence infrastructure, and public-facing signatory disclosure.
  • Signing without operating delivery is worse than not signing: Article 56(8) AI Office concerns about Code-commitment non-fulfillment apply only to signatories who fail their committed measures, exposing the firm to Article 99(3) escalation that a transparent non-signatory does not face, complete the readiness checklist before signing.
  • The Acme.Foundations worked example: non-systemic-risk now (8.4 × 10^24 FLOPs) crossing systemic-risk in Q4 2026 (2.1 × 10^25 FLOPs); AIGC recommends Transparency + Copyright signature now and Safety & Security deferred to Q4 2026, €280K implementation cost, €1.2-2.1M three-year NPV benefit, 64% of EU financial-services pipeline DDQs explicitly weight signatory status.
  • Cross-walks: EU AI Act Articles 53/55/56/88/89/99(3)/99(7), Annexes XI/XII/XIII; ISO 42001 Annex A.5 + A.7 + Clause 5 + Clause 9; NIST AI RMF Govern 1.1 + 2.1 + Map 1.1 + Manage 4.1 + Govern 5.1; CycloneDX 1.7 ML-BoM as the downstream-communication layer; OECD AI Principles 1 + 5; Article 86 right-to-explanation downstream effect.