Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

EU Unveils AI Code of Practice to Help Businesses Comply With Bloc’s Rules

The EU code is voluntary and complements the EU’s AI Act, a comprehensive set of regulations that was approved last year and is taking effect in phases.

Ray CVE-2023-48022 ShadowRay

The European Union on Thursday released a code of practice on general purpose artificial intelligence to help thousands of businesses in the 27-nation bloc using the technology comply with the bloc’s landmark AI rule book.

The EU code is voluntary and complements the EU’s AI Act, a comprehensive set of regulations that was approved last year and is taking effect in phases.

The code focuses on three areas: transparency requirements for providers of AI models that are looking to integrate them into their products; copyright protections; and safety and security of the most advanced AI systems.

The AI Act’s rules on general purpose artificial intelligence are set to take force on Aug. 2. The bloc’s AI Office, under its executive Commission, won’t start enforcing them for at least a year.

General purpose AI, exemplified by chatbots like OpenAI’s ChatGPT, can do many different tasks and underpin many of the AI systems that companies are using across the EU.

Under the AI Act, uses of artificial intelligence face different levels of scrutiny depending on the level of risk they pose, with some uses deemed unacceptable banned entirely. Violations could draw fines of up to 35 million euros ($41 million), or 7% of a company’s global revenue.

Advertisement. Scroll to continue reading.

Some Big Tech companies such as Meta have resisted the regulations, saying they’re unworkable, and U.S. Vice President JD Vance, speaking at a Paris summit in February, criticized “excessive regulation” of AI, warning it could kill “a transformative industry just as it’s taking off.”

More recently, more than 40 European companies, including Airbus, Mercedes-Benz, Philips and French AI startup Mistral, urged the bloc in an open letter to postpone the regulations for two years. They say more time is needed to simplify “unclear, overlapping and increasingly complex EU regulations” that put the continent’s competitiveness in the global AI race at risk.

There was no sign that Brussels was prepared to stop the clock.

“Today’s publication of the final version of the Code of Practice for general-purpose AI marks an important step in making the most advanced AI models available in Europe not only innovative but also safe and transparent,” the commission’s executive vice president for tech sovereignty, security and democracy, Henna Virkkunen, said in a news release.

Learn More About Securing AI at SecurityWeek’s AI Risk Summit – August 19-20, 2025 at the Ritz-Carlton, Half Moon Bay

RelatedThe Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore

Related: What Can Businesses Do About Ethical Dilemmas Posed by AI?

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.