If you provide a general-purpose AI model available in the EU, you face two tiers of obligation under the EU AI Act. Tier 1 (all GPAI models): maintain technical documentation, provide information to downstream providers, comply with copyright law, and publish a training data summary. Tier 2 (systemic risk models exceeding 1025 FLOPs): additionally conduct adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity. Obligations have applied since August 2, 2025. The Commission can impose fines of up to €15 million or 3% of global turnover starting August 2, 2026 — 12 days from now. The GPAI Code of Practice (final version: 10 July 2025) provides a presumption of conformity for signatories.
What Is a General-Purpose AI Model?
A general-purpose AI model (GPAI model) is an AI model — including when trained with large amounts of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks, regardless of how it is placed on the market (Article 3(63)).
The defining characteristic is generality. Unlike narrow AI systems designed for one specific task, GPAI models can serve multiple downstream applications. Large language models (GPT-4, Claude, Gemini, Llama), multimodal models, and code generation models all fall under this definition.
A GPAI model becomes a GPAI system when it is integrated into an AI system that can itself serve a variety of purposes (e.g., ChatGPT is a GPAI system based on the GPT-4 GPAI model). The distinction matters: Chapter V obligations apply to model providers, while system-level obligations (including Article 50 transparency) apply to system deployers.
Source: Article 51 — artificialintelligenceact.eu →The Two-Tier Obligation Framework
Chapter V of the EU AI Act establishes a two-tier regulatory framework for GPAI models. Every GPAI model provider faces Tier 1 obligations. Models classified as having systemic risk face additional Tier 2 obligations.
Core Obligations
Article 53: Technical documentation, downstream provider information, copyright compliance, training data summary. Applies to every GPAI model on the EU market.
Additional Obligations
Article 55: Model evaluation and adversarial testing, systemic risk assessment and mitigation, incident reporting, cybersecurity protection. Applies to models exceeding 1025 FLOPs or designated by the AI Office.
Tier 1: Four Core Obligations for All GPAI Providers
Article 53(1) imposes four obligations on every provider of a GPAI model placed on the EU market.
Technical Documentation
Draw up and keep up to date the technical documentation of the model, including its training and testing process and results. Documentation must follow the requirements set out in Annex XI of the AI Act, covering model architecture, training methodology, data governance, compute resources, evaluation results, and known limitations.
Article 53(1)(a) • Annex XI
Downstream Provider Information
Draw up, keep up to date, and make available information and documentation to providers of AI systems who intend to integrate the GPAI model into their systems. This must enable them to have a good understanding of the capabilities and limitations of the model and to comply with their own AI Act obligations.
Article 53(1)(b) • Annex XII
Copyright Compliance Policy
Put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with reservations of rights expressed by rightholders pursuant to Article 4(3) of Directive (EU) 2019/790 (the Text and Data Mining opt-out provision).
Article 53(1)(c) • Directive 2019/790
Training Data Summary
Draw up and make publicly available a sufficiently detailed summary about the content used for training of the GPAI model, according to a template provided by the AI Office. This summary must be comprehensive enough to facilitate the exercise of copyright-related rights by rightholders.
Article 53(1)(d)
The AI Office has published a template for this summary. Providers must use it.
Systemic Risk Classification: The 1025 FLOP Threshold
Article 51 establishes how GPAI models are classified as having systemic risk. There are two pathways:
Pathway 1: Compute Threshold (Automatic Presumption)
A GPAI model is presumed to have systemic risk when the cumulative amount of computation used for its training, measured in floating-point operations (FLOPs), exceeds 1025. As of mid-2026, approximately 12 models exceed this threshold, including GPT-4 class models, Claude 3 Opus and later versions, Gemini Ultra, and Llama 3 405B.
This presumption can be rebutted. Providers may present arguments and evidence to the AI Office demonstrating that their model does not pose systemic risk despite exceeding the threshold. The burden of proof lies with the provider.
Pathway 2: Commission Designation
The Commission may designate a GPAI model as having systemic risk, by means of a decision, either ex officio or following a qualified alert from the scientific panel, based on criteria including:
- Number of registered end users and downstream providers
- High-impact capabilities assessed against benchmarks and indicators
- Cross-border reach and availability across the EU
- Degree of autonomy and ability to act without human oversight
- Access to high-impact resources such as personal data or critical infrastructure
Notification Requirement
Under Article 52, providers must notify the AI Office without delay, and in any event within two weeks, after a GPAI model meets the systemic risk classification criteria. This applies whether the classification is through the compute threshold or the provider’s own assessment of high-impact capabilities.
Source: Article 51 — artificialintelligenceact.eu →Tier 2: Additional Obligations for Systemic Risk Models
Article 55 adds four obligations on top of the Tier 1 requirements for providers of GPAI models with systemic risk.
Model Evaluation and Adversarial Testing
Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model to identify and mitigate systemic risks. The evaluation should cover the model’s behaviour in adversarial conditions and its potential for misuse.
Article 55(1)(a)
Systemic Risk Assessment and Mitigation
Assess and mitigate possible systemic risks, including their sources, that may stem from the development, placing on the market, or use of GPAI models with systemic risk at Union level. Mitigation measures must be proportionate to the risks identified and documented throughout the model lifecycle.
Article 55(1)(b)
Incident Tracking and Reporting
Keep track of, document, and report serious incidents and possible corrective measures to the AI Office and, where appropriate, to national competent authorities, without undue delay. Incident reports must include the nature of the incident, the corrective measures taken, and the estimated impact.
Article 55(1)(c)
Incidents must be reported to the AI Office. The 15-day reporting window for serious incidents follows the notification without undue delay requirement.
Cybersecurity Protection
Ensure an adequate level of cybersecurity protection for the GPAI model with systemic risk and the physical infrastructure of the model. This includes protection against unauthorised access, model poisoning, prompt injection attacks, and other adversarial techniques that could compromise model integrity or safety.
Article 55(1)(d)
The GPAI Code of Practice
The Code of Practice for providers of general-purpose AI models was published in its final version on 10 July 2025 by the European AI Office. It provides detailed guidance on how to demonstrate compliance with Articles 53 and 55.
Structure: 3 Chapters, 12 Commitments
| Chapter | Scope | Commitments | Applies To |
|---|---|---|---|
| 1. Transparency | Model documentation via standardised form | 1 | All GPAI providers |
| 2. Copyright | Copyright policy + training data summary | 1 | All GPAI providers |
| 3. Safety & Security | Risk governance, evaluation, incident reporting, cybersecurity | 10 | Systemic risk providers only |
Model Documentation Form
The transparency chapter requires providers to complete a standardised Model Documentation Form covering: model identity and versioning, licensing terms, technical specifications, intended use cases, training datasets and data governance, compute and energy consumption metrics, evaluation results, and known limitations.
Safety and Security Framework
For systemic risk models, the Code requires providers to identify systemic risks, analyse and evaluate them, determine whether risk levels are acceptable, and implement mitigation measures if necessary. This process must be repeated until models achieve an acceptable level of risk across all identified risks. Providers must publish summarised versions of their Security Framework and Model Reports.
Presumption of Conformity
Article 56 establishes that compliance with the Code of Practice creates a presumption of conformity with the obligations in Articles 53 and 55. This presumption applies until harmonised standards are published. Signing the Code is voluntary but provides significant legal protection during enforcement.
The Open-Source Exemption
Article 53(2) provides a partial exemption for GPAI models released under a free and open-source licence where the model’s parameters, including weights and architecture information, are made publicly available.
What Is Exempted
Open-source GPAI model providers are exempt from:
- Obligation 1: Technical documentation (Article 53(1)(a))
- Obligation 2: Downstream provider information (Article 53(1)(b))
What Is Not Exempted
Even with the open-source exemption, providers must still:
- Obligation 3: Implement a copyright compliance policy (Article 53(1)(c))
- Obligation 4: Publish a training data summary (Article 53(1)(d))
What the Omnibus Amendment Changed for GPAI
The Digital Omnibus on AI was signed on 8 July 2026 after European Parliament adoption (16 June 2026) and Council approval (29 June 2026). It awaits publication in the Official Journal and enters into force three days after publication.
What Did Not Change
- August 2, 2026 enforcement date for GPAI obligations remains intact
- Article 53 and 55 obligations are unchanged
- Article 101 penalty framework for GPAI providers is unchanged
- The 1025 FLOP systemic risk threshold is unchanged
What Changed
| Change | Old | New | GPAI Impact |
|---|---|---|---|
| Annex III high-risk deadline | 2 Aug 2026 | 2 Dec 2027 | Indirect — downstream deployers of high-risk AI systems using GPAI models have more time |
| AI Office supervisory scope | GPAI models only | GPAI models + AI systems from same provider | Direct — if you build both the model and the system (e.g., OpenAI/ChatGPT), the AI Office can supervise both |
| New prohibitions (Art. 5) | 8 categories | 10 categories (+ non-consensual intimate AI + CSAM) | Applies to GPAI systems from Dec 2, 2026 |
Enforcement and Penalties
From August 2, 2026, the European Commission through its AI Office can enforce GPAI obligations with financial penalties.
What Can Be Fined
- Infringement of GPAI model obligations under Articles 51–56
- Supplying incorrect, incomplete, or misleading information to the AI Office
- Failing to comply with the AI Office’s requests for documentation or measures
- Failing to make a model available for evaluation when requested
AI Office Enforcement Powers
The AI Office (established under Article 64 within the European Commission) is the exclusive enforcer for GPAI obligations. It can:
- Request documentation and technical information from providers
- Conduct technical evaluations of GPAI models
- Demand compliance and risk-mitigation measures
- Restrict or withdraw a model from the EU market
- Impose fines under Article 101
SME and Startup Considerations
For SMEs (including startups), the lower of the two penalty amounts applies (€15M or 3% of turnover). The Commission must also take into account the proportionality principle, the size and market share of the provider, and documented compliance efforts when determining fine amounts.
| Violation Category | Maximum Fine | Article |
|---|---|---|
| Prohibited AI practices | €35M or 7% of global turnover | Art. 99 |
| GPAI model obligations | €15M or 3% of global turnover | Art. 101 |
| Incorrect information supplied | €7.5M or 1% of global turnover | Art. 101(2) |
Comparison: GPAI Obligations vs Article 50 vs High-Risk AI
The EU AI Act creates three distinct obligation frameworks. Understanding which applies to your organisation is essential.
| Aspect | GPAI (Ch. V) | Art. 50 Transparency | High-Risk (Ch. III) |
|---|---|---|---|
| Who is obligated | Model providers | System providers & deployers | System providers & deployers |
| Enforcement body | AI Office (EU level) | National authorities | National authorities |
| Obligations applied since | 2 Aug 2025 | 2 Aug 2026 | 2 Dec 2027 (Omnibus) |
| Penalty enforcement from | 2 Aug 2026 | 2 Aug 2026 | 2 Dec 2027 |
| Maximum fine | €15M / 3% | €15M / 3% | €15M / 3% |
| Documentation | ✓ Model documentation | ✗ | ✓ Technical documentation |
| Risk assessment | ✓ Systemic risk only | ✗ | ✓ All high-risk |
| Conformity assessment | ✗ | ✗ | ✓ |
| Incident reporting | ✓ Systemic risk only | ✗ | ✓ |
| Open-source exemption | Partial (Tier 1 only) | N/A | N/A |
Five-Step GPAI Compliance Checklist
Follow these steps to prepare for GPAI enforcement by August 2, 2026.
Classify Your Model
Determine whether your GPAI model exceeds the 1025 FLOP threshold. If it does, you are presumed to have systemic risk unless you successfully rebut the presumption. Also assess whether the AI Office may designate your model based on user reach, capabilities, or autonomy.
Complete Model Documentation
Fill out the standardised Model Documentation Form from the Code of Practice. Cover: model identity and versioning, licensing, technical specifications, intended use cases, training data governance, compute and energy metrics, evaluation results, and known limitations. Keep this documentation up to date.
Implement Copyright Policy and Training Data Summary
Establish a formal policy for copyright compliance, including respect for TDM opt-out rights under Directive 2019/790. Publish a sufficiently detailed summary of the training data content using the AI Office’s template.
Address Systemic Risk Obligations (If Applicable)
If classified as systemic risk: conduct adversarial testing per standardised protocols, establish an incident reporting process (report to AI Office without undue delay), implement cybersecurity measures for model and infrastructure, and assess and mitigate systemic risks at EU level. Publish summarised Security Framework and Model Reports.
Sign the Code of Practice
Consider signing the GPAI Code of Practice (final version: 10 July 2025). Signing creates a presumption of conformity with Articles 53 and 55 obligations until harmonised standards are published. This provides significant legal protection during the enforcement period. Monitor code-of-practice.ai for updates.
Complete GPAI Compliance Timeline
Frequently Asked Questions
Pre-Compliance Readiness Checklist
Use this checklist to assess your organisation's readiness for GPAI enforcement on August 2, 2026.
| # | Item | Tier | Status |
|---|---|---|---|
| 1 | GPAI model inventory completed (all models identified) | Both | □ |
| 2 | Compute (FLOP) calculation performed for each model | Both | □ |
| 3 | Systemic risk classification determined (Tier 1 or Tier 2) | Both | □ |
| 4 | Model Documentation Form completed per Code of Practice | Tier 1 | □ |
| 5 | Downstream provider documentation package prepared | Tier 1 | □ |
| 6 | Copyright compliance policy documented and implemented | Tier 1 | □ |
| 7 | Training data summary published using AI Office template | Tier 1 | □ |
| 8 | Adversarial testing conducted per standardised protocols | Tier 2 | □ |
| 9 | Systemic risk assessment completed at EU level | Tier 2 | □ |
| 10 | Incident reporting process established (AI Office contact) | Tier 2 | □ |
| 11 | Cybersecurity measures for model and infrastructure verified | Tier 2 | □ |
| 12 | Security Framework summary prepared for publication | Tier 2 | □ |
| 13 | Model Report summary prepared for publication | Tier 2 | □ |
| 14 | Code of Practice reviewed and signing decision made | Both | □ |
| 15 | EU authorised representative designated (if non-EU provider) | Both | □ |
Is Your AI Compliance Ready?
Take the free AI Act readiness diagnosis. Get a personalised compliance score in 2 minutes.