GPAI copyright policy: a checklist based on the Code of Practice

Every provider that places a general-purpose AI (GPAI) model on the EU market must have a written GPAI copyright policy, and the copyright chapter of the Commission’s Code of Practice is the most practical template for building one. Since 2 August 2026 the Commission can fine providers that fall short, including companies in Latin America or elsewhere that train outside Europe and launch their models in the EU. This checklist turns the five measures of the code into tasks and the evidence you should keep.

Key takeaways

  • Article 53(1)(c) of the AI Act requires a policy to comply with EU copyright law, including machine-readable opt-outs under Article 4(3) of the DSM Directive.
  • The obligation applies wherever training took place, and the open-source exception does not remove it.
  • The code’s copyright chapter has five measures: one policy document, lawful crawling, respect for opt-outs, output safeguards and a complaints channel.
  • Since 2 August 2026 the Commission can impose fines of up to 3% of worldwide turnover or EUR 15 million, whichever is higher.
  • Signing the code helps demonstrate compliance with the AI Act, but it is not compliance with copyright law in each Member State.

What does the AI Act require, and who has to comply?

The AI Act (Regulation (EU) 2024/1689) obliges providers of GPAI models to “put in place a policy to comply with Union law on copyright and related rights” and to identify and respect, “including through state-of-the-art technologies”, the reservations of rights that rightsholders express under Article 4(3) of Directive (EU) 2019/790 on copyright in the Digital Single Market (DSM Directive). That provision is what allows a rightsholder to opt out of the general text and data mining (TDM) exception. See Article 53 of the AI Act.

Four points decide whether the duty reaches you:

  • Place of training is irrelevant. Recital 106 says the policy applies “regardless of the jurisdiction” where the copyright-relevant acts behind training took place. A model trained in Mexico, Brazil or the United States and offered in the EU is covered.
  • Fine-tuning can make you a provider. The Commission’s GPAI questions and answers give as an indicative criterion a modification using more than a third of the original model’s training compute.
  • Open source is no exemption: Article 53(2) only lifts the documentation duties in points (a) and (b).
  • Non-EU providers need an authorised representative in the Union before placing a model on the market (Article 54), unless the open-source exception applies.

The GPAI obligations have applied since 2 August 2025, but the fining power in Article 101 was deferred to 2 August 2026 (Article 113(b)). Models placed on the market before 2 August 2025 have until 2 August 2027 to comply (Article 111(3)).

The GPAI copyright policy checklist, measure by measure

The General-Purpose AI Code of Practice was published on 10 July 2025 with three chapters: transparency, copyright, and safety and security. The Commission and the AI Board have confirmed it is an adequate voluntary tool. Signatories include Amazon, Anthropic, Google, Microsoft, Mistral AI and OpenAI. The copyright chapter translates into these tasks:

Measure What the policy must cover Evidence to keep
1.1 Single policy document One document covering all GPAI models placed on the EU market, kept up to date, with internal responsibilities assigned. A public summary is encouraged. Approved policy, version history, named owners
1.2 Lawful access when crawling No circumvention of effective technological measures such as paywalls or subscription walls; exclusion of sites recognised by EU or EEA courts or authorities as persistently infringing on a commercial scale. Crawler rules, exclusion lists and the date each was applied
1.3 Respect for opt-outs Crawlers that read and follow robots.txt as specified in IETF RFC 9309, plus other appropriate machine-readable protocols. Public information about your crawlers, with automatic update notifications such as a web feed. Crawler documentation, user-agent list, change log, published feed
1.4 Output safeguards Proportionate technical measures against outputs that reproduce protected training content, and a ban on infringing uses in the acceptable use policy or terms. Open-source releases warn users in the documentation. Test results, filter design, terms of use
1.5 Contact point and complaints An electronic contact point for rightsholders and a mechanism for substantiated complaints, including from collective management organisations, handled diligently and within a reasonable time. Complaint register, response times, outcomes

Robots.txt and other opt-out protocols: where things stand

Robots.txt is the baseline, but it was designed to manage crawler traffic: RFC 9309 (September 2022) itself says its rules “are not a form of access authorization”. The code therefore also requires “other appropriate machine-readable protocols”, for example asset-based or location-based metadata, that are standardised or widely adopted and generally agreed through an EU-level process.

That process is under way. The Commission ran a consultation on TDM opt-out protocols from 1 December 2025 to 23 January 2026 and has said it will publish a list of generally agreed solutions, reviewed at least every two years. On 13 July 2026 it published a feasibility study on an EU-level opt-out registry, which concluded that a registry “could be a useful complementary instrument”. In practice, your policy should name the protocols you honour today and commit to adding new ones as they are recognised, rather than stopping at robots.txt.

Output safeguards and the complaints channel

The output duty applies whether you build the model into your own product or license it to another company. At the Signatory Taskforce meeting of 13 March 2026, the AI Office reported a range of technical and organisational practices against infringing outputs and early experience with complaint handling. A channel without a register, response targets and escalation will be hard to defend.

Signing the code or not: what changes?

Signing is voluntary. Signatories can rely on the code to demonstrate compliance with Article 53, although adherence “does not constitute conclusive evidence” of it. Non-signatories must, according to the Commission, adopt alternative adequate measures and justify them. Either way, the chapter is not compliance with copyright law: providers must check each Member State’s transposition of Article 4(3) before acting there.

Spain is a good example. Article 67 of Royal Decree-law 24/2021 transposed the TDM exception and disapplies it where rightsholders have expressly reserved use through machine-readable means or other appropriate means. A reservation in website terms, not only in robots.txt, may therefore matter.

What this means for your business

  1. Confirm your role: are you a provider of a GPAI model, a downstream modifier that may become one, or a deployer only?
  2. Write the single policy document, map each of the five measures to an owner and keep it versioned.
  3. Audit your crawlers and datasets: robots.txt compliance, other opt-out signals, paywalls, excluded sites and third-party datasets bought or licensed.
  4. Align your terms of use, acceptable use policy and model documentation with Measure 1.4.
  5. Open the contact point and complaints channel, and record every complaint and response.
  6. If you are established outside the EU, appoint the authorised representative before launch.

If your model is moving from Latin America into the EU, our team for AI copyright compliance and digital asset protection can review the policy against the code and the Member States where you will operate. The wider AI Act obligations are covered within the same META Channel group.

Where providers get the copyright policy wrong

  • Treating robots.txt as the whole answer. Opt-outs expressed by other appropriate means, including metadata or terms, can still count under national law.
  • Ignoring third-party datasets. Content scraped by others and used for training remains subject to copyright law.
  • Writing a policy nobody operates. Measure 1.1 requires assigned owners and updates.
  • Forgetting the training-content summary. The copyright policy and the public summary under Article 53(1)(d) must tell a consistent story.
  • Splitting the work. When the licensing, enforcement and regulatory pieces sit with different advisers in different countries, gaps appear; our IP licensing and dispute team handles the rights side alongside the policy.

Frequently asked questions

Does a GPAI copyright policy have to be published?

The AI Act requires the policy to exist and be applied, not to be published in full. The Code of Practice encourages signatories to make a summary publicly available and requires public information about their web crawlers and the contact point for rightsholders. The training-content summary under Article 53(1)(d) must be published, using the Commission’s template.

Does the obligation apply if we train our model outside the EU?

Yes. Recital 106 of the AI Act states that the copyright policy obligation applies to any provider placing a GPAI model on the EU market, regardless of the jurisdiction in which the training took place. A Latin American provider launching a model in Europe must comply and, if established outside the Union, appoint an authorised representative there.

What are the fines for a missing or inadequate copyright policy?

Under Article 101 of the AI Act, the Commission may fine GPAI providers up to 3% of their total worldwide annual turnover in the preceding financial year or EUR 15 million, whichever is higher. This power has applied since 2 August 2026. Models already on the market before 2 August 2025 have until 2 August 2027 to comply.

Can IP Global Guard draft our copyright policy and complaints process?

Yes. We review your crawling, datasets and terms, draft the policy document and the rightsholder complaints procedure against the code’s five measures, and check the transposition of the opt-out rules in the Member States that matter to you, coordinating local advisers where needed through a single point of contact.

Get your copyright policy ready with IP Global Guard

A GPAI copyright policy is judged on what it shows: who owns it, which opt-outs your crawlers honour, how outputs are filtered and how complaints are handled. IP Global Guard, the IP services line of META Channel Corporation Limited, combines copyright, licensing and AI regulatory work with one strategy and one billing relationship across more than 25 jurisdictions in Europe, Latin America and Africa.

Send us your current policy or crawler documentation, the models you offer in the EU and your launch timeline. We will tell you where the gaps are against the code and coordinate the fixes from one point of contact. Contact our AI and copyright team.

This article is general information, not legal advice, and reflects the position on its publication date.

Sources

Share