GPAI Code of Practice list becomes the default AI procurement shortlist
How the AI Office signatory register became the first cut of every regulated model tender in Europe and the UK.

By 31 July 2026 the AI Office had published a live register of signatories to the General-Purpose AI Code of Practice. Regulated procurement teams in finance, health, defence and central government are using it as the first cut of any model tender. Providers outside the register must prove Code alignment themselves, item by item, in every submission.
Why the register turned into a procurement shortlist overnight
The Code sits under Articles 53 and 55 of the EU AI Act and covers general-purpose model providers on transparency, copyright and systemic-risk safety. The underlying obligations became applicable on 2 August 2025, and from 2 August 2026 the AI Office begins exercising its enforcement powers. The Code itself is voluntary, but signing it creates a presumption of conformity that supervisory authorities and buyers are entitled to rely on. A supplier that has signed can point to a chapter of the Code and say the assessment has already been done. A supplier that has not signed has to write the equivalent evidence into every response, and defend it in every clarification round.
For a regulated buyer running a framework award or a public tender under the Procurement Act 2023, that is a decisive procedural advantage. Evaluation teams do not have the legal or technical budget to reconstruct a Code chapter's worth of controls for a supplier they have never worked with. Cutting the field down to signatories on day one saves weeks of drafting and moves the risk conversation off transparency and onto deployment.
What signing actually commits a provider to
The Code has three chapters: transparency, copyright and safety and security. Each maps to a specific set of published measures. A signatory commits to publish a model documentation form, disclose training data domains and web-crawl behaviour, respect opt-outs including the TDM reservation regime, and for models above the systemic-risk threshold, run and publish evaluations against a defined risk model, plus incident reporting to the AI Office.
| Chapter | What the Code obliges a signatory to publish | Where non-signatories have to build the equivalent |
|---|---|---|
| Transparency | Model documentation form covering training, capabilities and limits | From scratch in every RFP response |
| Copyright | TDM opt-out policy, crawler transparency, complaints channel | In every clarification round on IP and training data |
| Safety and security | Systemic-risk assessment, evaluations, incident reporting to the AI Office | In a bespoke risk file per procurement |
How UK regulated buyers are already reading the register
The UK is not bound by the EU AI Act but its supervisory settlement is convergent by design. The Digital Regulation Cooperation Forum, the PRA under SS1/23 on model risk management, the MHRA on software as a medical device, and the National Cyber Security Centre on AI supply chain, all point to the same evidence base. A model provider that meets AI Office transparency and evaluation standards clears most of the UK bar in one document. That is why UK Crown Commercial Service call-offs, NHS England AI shortlists and MOD digital pathways are all quietly filtering to signatories first.
Where the register still leaves a gap
Being on the list does not mean the model is safe for a specific regulated deployment. It means the provider has published enough for a supervisory authority to have a conversation. Two questions the register does not answer:
- Where the model actually runs. A Code signatory hosting inference in a public cloud outside the buyer's jurisdiction still creates a data residency and lawful basis problem for a UK finance or health workload.
- What happens after the prompt. The Code covers the model artefact. It says nothing about the operating environment: the audit surface, the identity system, the human-in-the-loop control plane, the containment perimeter.
For finance, health, defence and critical infrastructure, those two questions are the deployment. Getting the model past the AI Office is the entry ticket. Standing up a defensible operating environment around it is the actual project.
The MICKAI position on the shortlist
We are a Sovereign Intelligence Operating System vendor, not a model vendor. MICKAI does not train frontier general-purpose models and does not seek a place on the signatory register. Our job is the substrate a signatory model runs on inside a regulated customer's estate: on hardware the customer owns, on premise or in an air-gapped enclave, with no data egress, and every consequential action written into an Open Audit Record that an outside party can verify offline in a browser with no network and no trust in us.
That posture is compatible with any signatory model a buyer chooses. If the buyer picks a signatory whose weights are available for on-premise execution, we host it inside the customer's estate. If the buyer picks a signatory whose weights are only available through an API, we contain and audit that call at the operating-system layer so the boundary between the buyer's data and the vendor's infrastructure is a signed, verifiable event, not a promise.
What to write into the RFP now
Three lines every regulated procurement team should have in a model tender from 2 August 2026 onwards:
- The provider must be listed on the AI Office signatory register at award, and must notify the buyer within five working days of any change to that status.
- The provider must publish the Code Chapter I model documentation form and provide a mapping to the buyer's own model risk framework, including any equivalent to PRA SS1/23 for financial services.
- Where inference runs outside the buyer's own estate, the provider must specify the containment architecture, the jurisdiction of processing, the audit surface and the retention windows in the response, not in a later clarification.
Signatory status is a filter, not a finish line. It buys the buyer time to run the harder assessment: where the workload actually executes, what the audit trail looks like, and who holds the keys.
Is the GPAI Code of Practice legally binding?
The Code itself is voluntary, but the underlying GPAI obligations in the EU AI Act are legal duties that became applicable on 2 August 2025. Signing the Code creates a presumption of conformity with those duties. From 2 August 2026 the AI Office begins exercising its enforcement powers, and the register becomes the practical evidence of compliance.
Does the UK recognise the AI Office signatory register?
The UK has not adopted the EU AI Act, but UK supervisors including the FCA, MHRA and NCSC accept AI Office transparency and evaluation output as high-quality evidence. Buyers running UK regulated procurements are treating signatory status as a strong indicator, not a legal requirement.
What if a buyer needs a non-signatory model for a technical reason?
The buyer keeps the option, but has to construct Code-equivalent evidence themselves. That means a bespoke model documentation form, a copyright and training data disclosure, and a systemic-risk assessment scoped to the deployment. In practice this doubles the length of the RFP response and moves the compliance risk onto the buyer.
Should a regulated buyer restrict AI model procurement to GPAI Code of Practice signatories only?
For default general-purpose workloads, yes, from 2 August 2026 onwards. Signatory status is the cheapest and quickest way to clear the transparency and safety bar the AI Office now enforces. For narrow or specialist models, keep the exception open, but require Code-equivalent evidence up front and hold the operating environment to the same standard regardless of who trained the weights.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System. It runs 63 studios on one operating system, with 10 production-ready at launch and 53 in development, on hardware the customer owns, on premise and air gapped, with no data egress. Every consequential action is written into the Open Audit Record, a post-quantum, tamper-evident ledger any outside party can verify offline. Mickai LTD holds 104 filed UK patent applications across 2,340 claims and 13 families.