AI & Privacy · guide
GPAI Provider Obligations Under the EU AI Act and the Code of Practice
Updated
The EU AI Act (Regulation (EU) 2024/1689) is the first binding law that regulates general-purpose AI models directly, not only the systems built on top of them. If you develop a foundation model, fine-tune one at scale, or place one on the EU market under your own name, Chapter V of the Act applies to you regardless of where your company sits. This guide explains what the obligations are, when they bite, and how the Code of Practice and the AI Office fit in. Dates and figures are correct at time of writing (September 2026).
What counts as a general-purpose AI model
Article 3(63) defines a general-purpose AI model as an AI model, including one trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks. The definition is about the model, not the product: a chatbot built on the model is a general-purpose AI system, defined separately in Article 3(66).
The Commission's guidelines on GPAI providers, published 18 July 2025, add an indicative criterion: a model trained with more than 10^23 FLOP that can generate language, text-to-image or text-to-video output is treated as a GPAI model unless it clearly lacks real generality. The guidelines also say a downstream modifier generally becomes a provider only when the modification uses more than one third of the original model's training compute.
Article 53: obligations for every GPAI provider
Article 53 sets four core duties:
| Duty | What it means in practice |
|---|---|
| Technical documentation, 53(1)(a) | Keep current documentation of training, testing and evaluation with at least the Annex XI content, available to the AI Office and national authorities on request |
| Downstream information, 53(1)(b) | Give providers who integrate the model enough information (Annex XII minimum) to understand its capabilities and limits and meet their own obligations |
| Copyright policy, 53(1)(c) | Maintain a policy to comply with EU copyright law, including honouring machine-readable rights reservations under Article 4(3) of Directive (EU) 2019/790 |
| Training-content summary, 53(1)(d) | Publish a sufficiently detailed summary of training content using the AI Office template, published 24 July 2025 |
Providers established outside the EU must also appoint an authorised representative in the Union. Models released under a free and open-source licence with public weights and architecture are exempt from the documentation duties in (a) and (b), but not from the copyright policy or the training summary, and the exemption never applies to models with systemic risk (Article 53(2)).
Articles 51 and 55: systemic risk
Article 51 classifies a model as having systemic risk when it has high-impact capabilities, or when the Commission designates it under the Annex XIII criteria. A model is presumed to have high-impact capabilities when cumulative training compute exceeds 10^25 FLOP. Providers whose models meet that threshold must notify the Commission without delay and within two weeks, and may argue that the model nonetheless does not present systemic risk.
Article 55 adds four obligations on top of Article 53: standardised model evaluation including documented adversarial testing; assessment and mitigation of possible systemic risks at Union level; tracking and reporting serious incidents and corrective measures to the AI Office and national authorities; and an adequate level of cybersecurity for the model and its physical infrastructure.
The timeline
| Date | Event |
|---|---|
| 2 August 2025 | Chapter V obligations for GPAI providers apply (Article 113(b)) |
| 2 August 2026 | Commission enforcement powers, including Article 101 fines, apply |
| 2 August 2027 | Deadline for models placed on the market before 2 August 2025 to comply (Article 111(3)) |
Article 113(b) carves Article 101 out of the 2025 start date, which is why the AI Office spent its first year monitoring and engaging rather than fining. The guidelines describe that period as one in which good-faith work by Code signatories would not be treated as a violation. Since 2 August 2026 the Commission can request documentation (Article 91), conduct evaluations (Article 92), require corrective measures up to restricting or withdrawing a model (Article 93), and fine providers up to 3 percent of worldwide annual turnover or EUR 15 million, whichever is higher.
The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) deferred several high-risk deadlines and gave the AI Office exclusive supervision of AI systems built on a GPAI model by the same provider or group, but did not move the GPAI dates above, according to the Commission's AI Act overview.
The Code of Practice
The General-Purpose AI Code of Practice, published 10 July 2025, is a voluntary instrument with three chapters. Transparency (built around a Model Documentation Form) and Copyright apply to all GPAI providers; Safety and Security applies only to providers of models with systemic risk. The Commission and the AI Board found the Code an adequate tool for demonstrating compliance. Signing is not mandatory, but adherents gain a presumption of conformity until harmonised standards exist, while non-signatories must show the Commission an alternative adequate means of compliance. At time of writing the Commission lists more than twenty signatories, including most large model developers.
The AI Office
The European AI Office, inside the Commission, is the supervisor of GPAI models. It drafts codes and guidelines, develops evaluation benchmarks, classifies systemic-risk models, and runs the enforcement steps above. National authorities remain responsible for AI systems, but can ask the AI Office to act where a GPAI model is the source of a problem.
Practical checklist
- Decide whether you are a provider, a downstream modifier, or a deployer, using the compute and generality criteria.
- Build the Annex XI and XII documentation now; a request can arrive at any time.
- Publish the training-content summary using the official template.
- Track cumulative training compute and diarise the two-week notification duty at 10^25 FLOP.
- If you are a signatory, map each Code commitment to a named owner.
RegPing's AI and privacy bot delivers AI Office and Commission notices like these into Discord as they are published.
Where to verify
- Regulation (EU) 2024/1689 on EUR-Lex
- Article 53 text
- Article 55 text
- GPAI Code of Practice
- Commission GPAI guidelines
- European AI Office
- Digital Omnibus on AI, Regulation (EU) 2026/1744
This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.
Questions people ask
When did the EU AI Act's GPAI obligations start to apply?
Article 53 and 55 obligations have applied since 2 August 2025. The Commission's power to fine GPAI providers under Article 101 applies from 2 August 2026, and models placed on the market before 2 August 2025 have until 2 August 2027 to comply.
What is the systemic-risk compute threshold?
Article 51(2) presumes a model has high-impact capabilities, and therefore systemic risk, when cumulative training compute exceeds 10^25 floating point operations. Providers must notify the Commission within two weeks of meeting it.
Is signing the GPAI Code of Practice mandatory?
No. The Code is voluntary, but signatories can use it to demonstrate compliance and reduce administrative burden, while non-signatories must show the Commission an alternative adequate means of complying.