Updated July 2026 ENFORCEMENT: 2 AUGUST 2026

EU AI Act: GPAI Model Obligations — What Providers Must Do by August 2, 2026

The complete guide to Chapter V obligations for general-purpose AI model providers. Two-tier compliance, the Code of Practice, systemic risk classification, and enforcement penalties — explained in practical terms.

The Bottom Line

If you provide a general-purpose AI model available in the EU, you face two tiers of obligation under the EU AI Act. Tier 1 (all GPAI models): maintain technical documentation, provide information to downstream providers, comply with copyright law, and publish a training data summary. Tier 2 (systemic risk models exceeding 1025 FLOPs): additionally conduct adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity. Obligations have applied since August 2, 2025. The Commission can impose fines of up to €15 million or 3% of global turnover starting August 2, 2026 — 12 days from now. The GPAI Code of Practice (final version: 10 July 2025) provides a presumption of conformity for signatories.

What Is a General-Purpose AI Model?

A general-purpose AI model (GPAI model) is an AI model — including when trained with large amounts of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks, regardless of how it is placed on the market (Article 3(63)).

The defining characteristic is generality. Unlike narrow AI systems designed for one specific task, GPAI models can serve multiple downstream applications. Large language models (GPT-4, Claude, Gemini, Llama), multimodal models, and code generation models all fall under this definition.

A GPAI model becomes a GPAI system when it is integrated into an AI system that can itself serve a variety of purposes (e.g., ChatGPT is a GPAI system based on the GPT-4 GPAI model). The distinction matters: Chapter V obligations apply to model providers, while system-level obligations (including Article 50 transparency) apply to system deployers.

Source: Article 51 — artificialintelligenceact.eu →

The Two-Tier Obligation Framework

Chapter V of the EU AI Act establishes a two-tier regulatory framework for GPAI models. Every GPAI model provider faces Tier 1 obligations. Models classified as having systemic risk face additional Tier 2 obligations.

Tier 1 — All GPAI Models

Core Obligations

Article 53: Technical documentation, downstream provider information, copyright compliance, training data summary. Applies to every GPAI model on the EU market.

Tier 2 — Systemic Risk

Additional Obligations

Article 55: Model evaluation and adversarial testing, systemic risk assessment and mitigation, incident reporting, cybersecurity protection. Applies to models exceeding 1025 FLOPs or designated by the AI Office.

The open-source exemption (Article 53(2)) partially reduces Tier 1 obligations for freely available models — but never applies to Tier 2 systemic risk models. See Section 7 for details.

Tier 1: Four Core Obligations for All GPAI Providers

Article 53(1) imposes four obligations on every provider of a GPAI model placed on the EU market.

1

Technical Documentation

Draw up and keep up to date the technical documentation of the model, including its training and testing process and results. Documentation must follow the requirements set out in Annex XI of the AI Act, covering model architecture, training methodology, data governance, compute resources, evaluation results, and known limitations.

Article 53(1)(a) • Annex XI

2

Downstream Provider Information

Draw up, keep up to date, and make available information and documentation to providers of AI systems who intend to integrate the GPAI model into their systems. This must enable them to have a good understanding of the capabilities and limitations of the model and to comply with their own AI Act obligations.

Article 53(1)(b) • Annex XII

3

Copyright Compliance Policy

Put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with reservations of rights expressed by rightholders pursuant to Article 4(3) of Directive (EU) 2019/790 (the Text and Data Mining opt-out provision).

Article 53(1)(c) • Directive 2019/790

4

Training Data Summary

Draw up and make publicly available a sufficiently detailed summary about the content used for training of the GPAI model, according to a template provided by the AI Office. This summary must be comprehensive enough to facilitate the exercise of copyright-related rights by rightholders.

Article 53(1)(d)

The AI Office has published a template for this summary. Providers must use it.

Systemic Risk Classification: The 1025 FLOP Threshold

Article 51 establishes how GPAI models are classified as having systemic risk. There are two pathways:

Pathway 1: Compute Threshold (Automatic Presumption)

A GPAI model is presumed to have systemic risk when the cumulative amount of computation used for its training, measured in floating-point operations (FLOPs), exceeds 1025. As of mid-2026, approximately 12 models exceed this threshold, including GPT-4 class models, Claude 3 Opus and later versions, Gemini Ultra, and Llama 3 405B.

This presumption can be rebutted. Providers may present arguments and evidence to the AI Office demonstrating that their model does not pose systemic risk despite exceeding the threshold. The burden of proof lies with the provider.

Pathway 2: Commission Designation

The Commission may designate a GPAI model as having systemic risk, by means of a decision, either ex officio or following a qualified alert from the scientific panel, based on criteria including:

  • Number of registered end users and downstream providers
  • High-impact capabilities assessed against benchmarks and indicators
  • Cross-border reach and availability across the EU
  • Degree of autonomy and ability to act without human oversight
  • Access to high-impact resources such as personal data or critical infrastructure

Notification Requirement

Under Article 52, providers must notify the AI Office without delay, and in any event within two weeks, after a GPAI model meets the systemic risk classification criteria. This applies whether the classification is through the compute threshold or the provider’s own assessment of high-impact capabilities.

Source: Article 51 — artificialintelligenceact.eu →

Tier 2: Additional Obligations for Systemic Risk Models

Article 55 adds four obligations on top of the Tier 1 requirements for providers of GPAI models with systemic risk.

1

Model Evaluation and Adversarial Testing

Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model to identify and mitigate systemic risks. The evaluation should cover the model’s behaviour in adversarial conditions and its potential for misuse.

Article 55(1)(a)

2

Systemic Risk Assessment and Mitigation

Assess and mitigate possible systemic risks, including their sources, that may stem from the development, placing on the market, or use of GPAI models with systemic risk at Union level. Mitigation measures must be proportionate to the risks identified and documented throughout the model lifecycle.

Article 55(1)(b)

3

Incident Tracking and Reporting

Keep track of, document, and report serious incidents and possible corrective measures to the AI Office and, where appropriate, to national competent authorities, without undue delay. Incident reports must include the nature of the incident, the corrective measures taken, and the estimated impact.

Article 55(1)(c)

Incidents must be reported to the AI Office. The 15-day reporting window for serious incidents follows the notification without undue delay requirement.

4

Cybersecurity Protection

Ensure an adequate level of cybersecurity protection for the GPAI model with systemic risk and the physical infrastructure of the model. This includes protection against unauthorised access, model poisoning, prompt injection attacks, and other adversarial techniques that could compromise model integrity or safety.

Article 55(1)(d)

Source: Article 55 — artificialintelligenceact.eu →

The GPAI Code of Practice

The Code of Practice for providers of general-purpose AI models was published in its final version on 10 July 2025 by the European AI Office. It provides detailed guidance on how to demonstrate compliance with Articles 53 and 55.

Structure: 3 Chapters, 12 Commitments

ChapterScopeCommitmentsApplies To
1. TransparencyModel documentation via standardised form1All GPAI providers
2. CopyrightCopyright policy + training data summary1All GPAI providers
3. Safety & SecurityRisk governance, evaluation, incident reporting, cybersecurity10Systemic risk providers only

Model Documentation Form

The transparency chapter requires providers to complete a standardised Model Documentation Form covering: model identity and versioning, licensing terms, technical specifications, intended use cases, training datasets and data governance, compute and energy consumption metrics, evaluation results, and known limitations.

Safety and Security Framework

For systemic risk models, the Code requires providers to identify systemic risks, analyse and evaluate them, determine whether risk levels are acceptable, and implement mitigation measures if necessary. This process must be repeated until models achieve an acceptable level of risk across all identified risks. Providers must publish summarised versions of their Security Framework and Model Reports.

Presumption of Conformity

Article 56 establishes that compliance with the Code of Practice creates a presumption of conformity with the obligations in Articles 53 and 55. This presumption applies until harmonised standards are published. Signing the Code is voluntary but provides significant legal protection during enforcement.

The Code of Practice is available at code-of-practice.ai and digital-strategy.ec.europa.eu.

The Open-Source Exemption

Article 53(2) provides a partial exemption for GPAI models released under a free and open-source licence where the model’s parameters, including weights and architecture information, are made publicly available.

What Is Exempted

Open-source GPAI model providers are exempt from:

  • Obligation 1: Technical documentation (Article 53(1)(a))
  • Obligation 2: Downstream provider information (Article 53(1)(b))

What Is Not Exempted

Even with the open-source exemption, providers must still:

  • Obligation 3: Implement a copyright compliance policy (Article 53(1)(c))
  • Obligation 4: Publish a training data summary (Article 53(1)(d))
Critical limitation: The open-source exemption does not apply to GPAI models with systemic risk (Article 53(2), second subparagraph). If an open-source model exceeds the 1025 FLOP threshold, all Tier 1 and Tier 2 obligations apply in full. This affects models like Llama 3 405B.

What the Omnibus Amendment Changed for GPAI

The Digital Omnibus on AI was signed on 8 July 2026 after European Parliament adoption (16 June 2026) and Council approval (29 June 2026). It awaits publication in the Official Journal and enters into force three days after publication.

What Did Not Change

  • August 2, 2026 enforcement date for GPAI obligations remains intact
  • Article 53 and 55 obligations are unchanged
  • Article 101 penalty framework for GPAI providers is unchanged
  • The 1025 FLOP systemic risk threshold is unchanged

What Changed

ChangeOldNewGPAI Impact
Annex III high-risk deadline2 Aug 20262 Dec 2027Indirect — downstream deployers of high-risk AI systems using GPAI models have more time
AI Office supervisory scopeGPAI models onlyGPAI models + AI systems from same providerDirect — if you build both the model and the system (e.g., OpenAI/ChatGPT), the AI Office can supervise both
New prohibitions (Art. 5)8 categories10 categories (+ non-consensual intimate AI + CSAM)Applies to GPAI systems from Dec 2, 2026
Source: Gibson Dunn — EU AI Act Omnibus Agreement →

Enforcement and Penalties

From August 2, 2026, the European Commission through its AI Office can enforce GPAI obligations with financial penalties.

€15M
Maximum fine, or 3% of total worldwide annual turnover — whichever is higher (Article 101)
3%
Of global annual turnover for intentional or negligent infringement of GPAI obligations

What Can Be Fined

  • Infringement of GPAI model obligations under Articles 51–56
  • Supplying incorrect, incomplete, or misleading information to the AI Office
  • Failing to comply with the AI Office’s requests for documentation or measures
  • Failing to make a model available for evaluation when requested

AI Office Enforcement Powers

The AI Office (established under Article 64 within the European Commission) is the exclusive enforcer for GPAI obligations. It can:

  • Request documentation and technical information from providers
  • Conduct technical evaluations of GPAI models
  • Demand compliance and risk-mitigation measures
  • Restrict or withdraw a model from the EU market
  • Impose fines under Article 101

SME and Startup Considerations

For SMEs (including startups), the lower of the two penalty amounts applies (€15M or 3% of turnover). The Commission must also take into account the proportionality principle, the size and market share of the provider, and documented compliance efforts when determining fine amounts.

Violation CategoryMaximum FineArticle
Prohibited AI practices€35M or 7% of global turnoverArt. 99
GPAI model obligations€15M or 3% of global turnoverArt. 101
Incorrect information supplied€7.5M or 1% of global turnoverArt. 101(2)
Source: Article 101 — artificialintelligenceact.eu →

Comparison: GPAI Obligations vs Article 50 vs High-Risk AI

The EU AI Act creates three distinct obligation frameworks. Understanding which applies to your organisation is essential.

AspectGPAI (Ch. V)Art. 50 TransparencyHigh-Risk (Ch. III)
Who is obligatedModel providersSystem providers & deployersSystem providers & deployers
Enforcement bodyAI Office (EU level)National authoritiesNational authorities
Obligations applied since2 Aug 20252 Aug 20262 Dec 2027 (Omnibus)
Penalty enforcement from2 Aug 20262 Aug 20262 Dec 2027
Maximum fine€15M / 3%€15M / 3%€15M / 3%
Documentation Model documentation Technical documentation
Risk assessment Systemic risk only All high-risk
Conformity assessment
Incident reporting Systemic risk only
Open-source exemptionPartial (Tier 1 only)N/AN/A

Five-Step GPAI Compliance Checklist

Follow these steps to prepare for GPAI enforcement by August 2, 2026.

1

Classify Your Model

Determine whether your GPAI model exceeds the 1025 FLOP threshold. If it does, you are presumed to have systemic risk unless you successfully rebut the presumption. Also assess whether the AI Office may designate your model based on user reach, capabilities, or autonomy.

2

Complete Model Documentation

Fill out the standardised Model Documentation Form from the Code of Practice. Cover: model identity and versioning, licensing, technical specifications, intended use cases, training data governance, compute and energy metrics, evaluation results, and known limitations. Keep this documentation up to date.

3

Implement Copyright Policy and Training Data Summary

Establish a formal policy for copyright compliance, including respect for TDM opt-out rights under Directive 2019/790. Publish a sufficiently detailed summary of the training data content using the AI Office’s template.

4

Address Systemic Risk Obligations (If Applicable)

If classified as systemic risk: conduct adversarial testing per standardised protocols, establish an incident reporting process (report to AI Office without undue delay), implement cybersecurity measures for model and infrastructure, and assess and mitigate systemic risks at EU level. Publish summarised Security Framework and Model Reports.

5

Sign the Code of Practice

Consider signing the GPAI Code of Practice (final version: 10 July 2025). Signing creates a presumption of conformity with Articles 53 and 55 obligations until harmonised standards are published. This provides significant legal protection during the enforcement period. Monitor code-of-practice.ai for updates.

Complete GPAI Compliance Timeline

1 Aug 2024
EU AI Act enters into force (Regulation 2024/1689 published in OJ) Active
2 Feb 2025
Prohibited AI practices (Article 5) become enforceable Active
2 Aug 2025
GPAI obligations (Articles 51–56) start to apply. Providers must begin complying with Tier 1 and Tier 2 obligations Active
10 Jul 2025
Final version of the GPAI Code of Practice published by the AI Office Active
8 Jul 2026
Omnibus amendment signed (Annex III deferred to Dec 2027; GPAI dates unchanged) Active
2 Aug 2026
GPAI enforcement begins. Commission can impose fines under Article 101. Article 50 transparency obligations also activate. National market surveillance authorities fully operational 12 days
2 Dec 2026
New prohibited practices (non-consensual intimate AI, CSAM) effective. Art. 50(2) legacy system marking transition period ends Future
2 Aug 2027
GPAI models placed on market before Aug 2, 2025 must comply with all obligations Future
2 Dec 2027
High-risk AI system obligations (Annex III) become enforceable (deferred by Omnibus) Future
Source: Implementation Timeline — artificialintelligenceact.eu →

Frequently Asked Questions

A general-purpose AI model (GPAI model) is an AI model — including when trained with large amounts of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks, regardless of how it is placed on the market. This definition captures large language models (LLMs), multimodal foundation models, and other general-purpose systems. The key characteristic is generality: the model can serve multiple downstream applications rather than one narrow task. Examples include GPT-4, Claude, Gemini, and Llama.
GPAI obligations under Articles 51-56 have applied since August 2, 2025 — twelve months after the AI Act entered into force. However, the European Commission's enforcement powers, including the ability to impose fines, become applicable on August 2, 2026. This means providers have been legally required to comply since August 2025, but enforcement with financial penalties begins August 2, 2026. The Omnibus amendment did not change these dates.
Article 51(2) establishes a computational threshold: any GPAI model trained using cumulative compute exceeding 10²⁵ floating-point operations (FLOPs) is presumed to have systemic risk. This threshold captures the most capable models. As of mid-2026, approximately 12 models exceed this threshold, including GPT-4 class models, Claude 3 Opus and later, Gemini Ultra, and Llama 3 405B. The Commission can update this threshold through delegated acts as compute capabilities evolve.
Yes. Article 51(2) allows providers to present arguments and evidence to the AI Office demonstrating that, despite exceeding the 10²⁵ FLOP threshold, their model does not pose systemic risk due to its specific characteristics. However, the burden of proof lies with the provider. The AI Office evaluates the evidence and may still designate the model as systemic risk based on other criteria, including the number of registered end users, cross-border reach, or degree of autonomy.
Under Article 53(1), all GPAI model providers must: (a) Draw up and keep up to date technical documentation of the model and its training and testing process, following Annex XI requirements; (b) Provide information and documentation to downstream providers integrating the model into AI systems; (c) Put in place a policy to comply with EU copyright and related rights law; (d) Draw up and make publicly available a sufficiently detailed summary of the training data content. These four obligations apply regardless of model size or risk classification.
No. Article 53(2) provides a partial exemption for models released under a free and open-source licence where model parameters including weights and architecture information are publicly available. However, this exemption only applies to obligations (a) and (b) — technical documentation and downstream provider information. Open-source providers must still comply with copyright policy and training data summary obligations. Critically, this exemption does not apply to models with systemic risk, regardless of their licence.
Article 55 adds four obligations for GPAI models with systemic risk: (1) Perform model evaluation in accordance with standardised protocols and tools, including adversarial testing; (2) Assess and mitigate possible systemic risks at EU level; (3) Keep track of, document, and report serious incidents and possible corrective measures to the AI Office and relevant national authorities without undue delay; (4) Ensure an adequate level of cybersecurity protection for the model and its physical infrastructure.
The Code of Practice for providers of general-purpose AI models was published in its final version on 10 July 2025 by the European AI Office. It contains 12 commitments across three chapters: Transparency (1 commitment covering model documentation), Copyright (1 commitment on copyright policy and training data summaries), and Safety and Security (10 commitments for systemic risk models). Providers can sign the Code to demonstrate compliance with Article 53 and 55 obligations until harmonised standards are published. The Code serves as a presumption of conformity.
The transparency chapter requires providers to complete a standardised Model Documentation Form covering: model identity and versioning, licensing terms, technical specifications, intended use cases, training datasets and data governance, compute and energy consumption metrics, evaluation results, and known limitations. This documentation must be kept up to date and provided to the AI Office, national supervisory authorities, and downstream providers who integrate the model into their AI systems.
Article 101 empowers the Commission to fine GPAI model providers up to €15 million or 3% of their total worldwide annual turnover in the preceding financial year, whichever is higher. This applies to intentional or negligent infringement of GPAI obligations, supplying incorrect or misleading information to the AI Office, and failing to comply with requests or evaluations. For SMEs and startups, the lower of the two amounts applies. This is distinct from the €35M/7% tier for prohibited practices under Article 99.
The Digital Omnibus (signed July 8, 2026) did not defer GPAI enforcement. August 2, 2026 remains the date when the Commission gains penalty enforcement powers over GPAI providers. The Omnibus did extend the AI Office's supervisory scope to cover AI systems based on GPAI models developed within the same undertaking as the model provider. It also deferred Annex III high-risk obligations from August 2, 2026 to December 2, 2027 — but this deferral does not apply to GPAI model obligations.
GPAI model obligations are enforced exclusively at the EU level by the European Commission through its AI Office, established under Article 64. This is different from other AI Act provisions, which are enforced by national market surveillance authorities. The AI Office can request documentation, conduct technical evaluations, demand compliance and risk-mitigation measures, restrict or withdraw a model from the EU market, and issue fines. National authorities play a supporting role by providing information and cooperating with the AI Office.
Yes. Under Article 2, the AI Act applies to providers placing GPAI models on the EU market, regardless of where they are established. If your model is made available or used within the EU — whether directly or through downstream integration — you are subject to GPAI obligations. This extraterritorial reach means US, Chinese, and other non-EU model providers must comply if their models reach EU markets. An authorised representative in the EU may be required.
A GPAI model is the underlying AI model with general capabilities (e.g., GPT-4, Claude). A general-purpose AI system is an AI system based on a GPAI model that can serve a variety of purposes (e.g., ChatGPT, Claude.ai). The distinction matters because Chapter V obligations (Articles 51-56) apply to model providers, while Article 50 transparency obligations and other system-level requirements apply to system deployers. A company can be both a model provider and a system deployer if it develops the model and also deploys a consumer-facing application.
Downstream providers who integrate a GPAI model into their AI systems must receive sufficient information from the model provider to comply with their own obligations under the AI Act. This includes understanding the model's capabilities, limitations, foreseeable risks, and the data used for training. If the downstream provider deploys a high-risk AI system, this documentation becomes critical for their conformity assessment. The Code of Practice's Model Documentation Form standardizes this information exchange.
Five essential steps: (1) Classify your model — determine whether it exceeds the 10²⁵ FLOP threshold or may be designated as systemic risk by the AI Office; (2) Complete the Model Documentation Form as specified in the Code of Practice; (3) Implement a copyright compliance policy and publish a training data summary; (4) If systemic risk applies, conduct adversarial testing, establish an incident reporting process, and verify cybersecurity measures; (5) Consider signing the Code of Practice to benefit from the presumption of conformity.

Pre-Compliance Readiness Checklist

Use this checklist to assess your organisation's readiness for GPAI enforcement on August 2, 2026.

#ItemTierStatus
1GPAI model inventory completed (all models identified)Both
2Compute (FLOP) calculation performed for each modelBoth
3Systemic risk classification determined (Tier 1 or Tier 2)Both
4Model Documentation Form completed per Code of PracticeTier 1
5Downstream provider documentation package preparedTier 1
6Copyright compliance policy documented and implementedTier 1
7Training data summary published using AI Office templateTier 1
8Adversarial testing conducted per standardised protocolsTier 2
9Systemic risk assessment completed at EU levelTier 2
10Incident reporting process established (AI Office contact)Tier 2
11Cybersecurity measures for model and infrastructure verifiedTier 2
12Security Framework summary prepared for publicationTier 2
13Model Report summary prepared for publicationTier 2
14Code of Practice reviewed and signing decision madeBoth
15EU authorised representative designated (if non-EU provider)Both
TS

Takayuki Sawai

Gyoseishoshi (Certified Administrative Scrivener). AI compliance researcher covering EU AI Act, drone aviation law, and food safety regulations across 14 countries. Over 20 years at Hiroshima Prefectural Government.

Read more →

Is Your AI Compliance Ready?

Take the free AI Act readiness diagnosis. Get a personalised compliance score in 2 minutes.