Insights · General-purpose AI
EU AI Act GPAI Obligations: Provider and Buyer Guide
GPAI model obligations under the EU AI Act: documentation, copyright policy, systemic risk, and what downstream deployers should verify.
General-purpose AI models (GPAI) — often called foundation models in industry speech — are trained with a large amount of data using self-supervision at scale and display significant generality. Chapter V of the EU AI Act sets obligations for GPAI model providers, including technical documentation, information for downstream providers, and — for systemic-risk models — additional evaluation, risk, incident, and cybersecurity measures.
What downstream deployers should demand in procurement
Even if your application is narrow, you inherit integration risk: prompts, tools, RAG corpora, and fine-tunes change behaviour. Contractual clauses should reference EU AI Act conformity for the use case, model version pinning, incident notification, and documentation handover for your own Annex IV or transparency duties.
Systemic risk and public capability
Models with high impact capabilities may be classified as posing systemic risk after designation — triggering stricter evaluation, tracking, and reporting. ML leads should monitor Commission decisions and technical standards as they stabilise.
Agent Mai in the GPAI context
Use Agent Mai to document how a GPAI is constrained in your product: guardrails, retrieval boundaries, human review gates, and logging — so your technical file tells a coherent story from base model to deployed behaviour.
Separate the GPAI model from the downstream AI system
A GPAI model is a reusable model with significant generality; the product built with it is an AI system with a specific intended purpose. The model provider documents model-level capabilities and limitations, while a downstream provider must govern the application layer: prompts, retrieval, tools, fine-tuning, user interface, access controls, human review, monitoring, and the decisions the system supports. This distinction is essential for contracts and evidence ownership.
Core GPAI provider obligations
- Maintain technical documentation about training, testing, evaluation, capabilities, limitations, and other information required by the Act and its annexes.
- Provide downstream AI-system providers with information and documentation that enables them to understand capabilities and limitations and comply with their own duties.
- Put in place a policy to comply with EU copyright law, including the reservation of rights expressed under the Copyright in the Digital Single Market framework.
- Publish a sufficiently detailed summary of the content used to train the model using the Commission template.
- Where established outside the Union, appoint an authorised representative unless a statutory exception applies.
Additional controls for systemic-risk GPAI
Providers of GPAI models with systemic risk must perform model evaluations using standardised protocols and tools, assess and mitigate possible systemic risks at Union level, track and report serious incidents and corrective measures, and maintain an adequate level of cybersecurity for the model and physical infrastructure. Evidence should connect evaluation findings to mitigations and show how risks are monitored after release.
Open-source GPAI is not a blanket exemption
The Act provides targeted treatment for certain GPAI models released under a free and open-source licence with public access to parameters, architecture, and usage information. The exception does not remove the copyright-policy and training-content-summary duties, and it does not cover GPAI models with systemic risk. Downstream teams should avoid using an open licence as a substitute for role analysis, security review, model documentation, or controls for the deployed AI system.
GPAI dates and legacy models
GPAI obligations began applying on 2 August 2025 for relevant new models. The Act includes a later compliance point for GPAI models placed on the market before that date, while Commission enforcement powers apply from August 2026. Because release dates, fine-tunes, substantial changes, and provider identity can affect the analysis, keep evidence of when each model version entered the market and confirm the current Commission guidance for legacy models.
A downstream GPAI procurement checklist
- Model identity, release channel, version-pinning options, deprecation policy, hosting region, and subprocessors.
- Documented capabilities, known limitations, evaluation coverage, safety controls, rate limits, and prohibited uses.
- Training-data summary, copyright policy context, personal-data handling, retention, and whether customer data is used for training.
- Security documentation, vulnerability handling, incident notification, availability commitments, and material-change notice.
- Rights to retain evidence, audit relevant controls, export logs, switch models, and terminate safely.
Frequently asked questions
Is every generative AI system a GPAI model provider?
No. The Act distinguishes models from systems and provider roles from downstream integration. An organisation using or integrating a third-party model is not automatically the provider of that GPAI model, although it can have obligations for the resulting AI system.
What makes a GPAI model systemic risk?
The Act includes a compute-based presumption and allows Commission designation based on high-impact capabilities. Providers of systemic-risk models face additional evaluation, risk assessment, incident reporting and cybersecurity duties.
What should a downstream buyer request from a GPAI supplier?
Request current technical and integration information, model and version identifiers, acceptable-use and limitation information, security and incident terms, change notification, data handling, copyright-related assurances, and evidence needed for the buyer's own system obligations.
Related articles
- EU AI Act Article 4: AI Literacy RequirementsUnderstand the EU AI Act Article 4 AI literacy requirement, the people in scope, role-based learning, and practical evidence for providers and deployers.
- EU AI Act Article 50: Transparency RequirementsA practical guide to EU AI Act Article 50 transparency obligations for AI interactions, AI-generated content, deepfakes, and the evidence teams should retain.
- EU AI Act Article 5: Prohibited AI PracticesArticle 5 prohibited AI practices: social scoring, manipulative AI, biometric categorisation, facial scraping, and a practical product-and-legal review lens.
Educational content only — not legal advice. Verify obligations with qualified counsel.