GPAI Obligations Under the EU AI Act: A Plain-English Guide for Model Providers and Downstream Developers

If your organisation develops, releases, or integrates a general-purpose AI model - a large language model, a multimodal foundation model, a text-to-image system - the EU AI Act's Chapter V is now live law. GPAI obligations under Chapter V (Articles 51-56) became applicable on 2 August 2025. There is no grace period for new models placed on the market from that date onward. The question is no longer whether you need to comply, but how.
This guide walks through every layer of the regime: what counts as a GPAI model, the baseline obligations every provider must meet, the heavier duties that attach to systemic-risk models, how the voluntary Code of Practice reduces friction, the three key dates on the compliance calendar, what downstream developers need to know, and the penalties for getting it wrong.
What Counts as a GPAI Model?
Under the AI Act, "general-purpose AI models" are defined as models that display significant generality and are capable of competently performing a wide range of distinct tasks and that can be integrated into a variety of downstream systems or applications. The definition is intentionally broad - it captures large language models, multimodal systems, and foundation models regardless of how they are released.
As an indicative criterion, the GPAI Guidelines suggest that models trained on more than 10²³ FLOPs that can generate language, text-to-image, or text-to-video output are to be considered GPAI. The release mode - open weights, API, or otherwise - does not affect whether the definition applies.
One important carve-out: providers of GPAI models released under a free and open-source licence are exempt from the documentation and transparency obligations under Article 53(1)(a) and (b). That exemption does not extend to copyright compliance or, critically, to systemic-risk obligations.
Chapter V regulates GPAI models as a separate regime from AI systems. The obligations sit at the model level, address the GPAI model provider, and are independent of the Article 6 high-risk classification that governs AI systems. In other words, even if your model is never used in a high-risk application, GPAI obligations still apply.
Baseline Obligations for All GPAI Providers (Article 53)
The regulatory approach creates two tiers of obligations. Tier 1 covers all GPAI models: core transparency and documentation obligations that apply to every GPAI model placed on the EU market under Articles 53-54.
Every GPAI provider - regardless of model size or risk profile - must meet four baseline duties:
1. Technical documentation Providers must maintain up-to-date technical documentation covering the model's architecture, training methodology, capabilities, and limitations. This documentation is required under Annex XI and must be made available to the AI Office and national competent authorities.
2. Information for downstream providers Providers must supply relevant information to downstream providers that seek to integrate models into their AI or GPAI systems - for example, capabilities and limitations. This is the supply-chain transparency mechanism: the upstream provider's disclosure obligations flow directly to the developers building on top of the model.
3. EU copyright policy GPAI providers must comply with Union copyright law in training and make available a sufficiently detailed summary of training data content. The copyright chapter of the Code of Practice operationalises this through internal policies and public-facing summaries, stopping short of requiring disclosure of exact training datasets.
4. Training-data summary Completing the training-data summary template is mandatory for all GPAI model providers, and all information must be made public. It covers general model information - quantity and types of data used - a list of data sources including public or private datasets and web-scraped data, and measures implemented to remove illegal content and respect copyrights.
Open-source partial exemption. Providers releasing models under a free and open-source licence are exempt from the Article 53(1)(a) and (b) documentation duties — but NOT from the copyright policy obligation or from any systemic-risk obligations if the model crosses the 10²⁵ FLOP threshold.
Extra Obligations for Systemic-Risk Models (Article 55)
GPAI models trained using more than 10²⁵ floating point operations (FLOPs) are presumed to carry systemic risk. Models exceeding this computational threshold - or designated by the AI Office - face additional obligations including adversarial testing, incident reporting, and cybersecurity measures. An estimated 5-15 companies worldwide currently qualify.
Providers of GPAI models with systemic risk must comply with Article 53 as well as Article 55. The latter entails conducting model evaluations, adversarial testing, tracking and reporting serious incidents, and ensuring cybersecurity protections.
The five systemic-risk obligations in detail:
| Obligation | What it requires |
|---|---|
| Model evaluations | State-of-the-art evaluations before and after market placement |
| Adversarial testing | Red-teaming and structured testing to surface dangerous capabilities |
| Systemic-risk assessment & mitigation | Documented risk governance framework covering the full model lifecycle |
| Incident reporting | Providers must notify the AI Office of serious incidents within two to fifteen days, depending on severity. |
| Cybersecurity | Adequate cybersecurity measures for models and physical infrastructure, covering the entire model lifecycle to protect against unauthorized release, access, or model theft. |
Signatories to the Code of Practice must develop a cutting-edge Safety and Security Framework before model release, outlining evaluation triggers, risk categories, mitigation strategies, forecasting methods, and organisational responsibilities. This framework must be regularly updated in response to new risks, incidents, or significant changes in the model or its environment.
Providers must also notify the Commission when they foresee or reach the systemic-risk threshold. Providers must notify the Commission within two weeks of reasonably foreseeing or reaching the 10²⁵ FLOP threshold under Article 52(1).
The Voluntary Code of Practice: Why It Matters
The European Commission published the final General-Purpose AI Code of Practice on 10 July 2025. It was developed by 13 independent experts, with input from over 1,000 stakeholders, including model providers, small and medium-sized enterprises, academics, AI safety experts, rightsholders, and civil society organisations.
The Code is a voluntary tool, prepared by independent experts and intended to help providers of GPAI models demonstrate compliance with their obligations under the EU AI Act. It includes three chapters: (1) Transparency, (2) Copyright, and (3) Safety and Security. The first two chapters apply to all providers of GPAI models, while the third addresses obligations for providers of GPAI models with systemic risk.
Why sign it?
The Commission and the AI Board have confirmed that the Code is an adequate voluntary tool for providers of GPAI models to demonstrate compliance with the AI Act. AI model providers who voluntarily sign it can show they comply with the AI Act by adhering to the Code. This will reduce their administrative burden and give them more legal certainty and trust than if they proved compliance through other methods.
Adherence to the Code is voluntary, but providers who decide not to comply with it may face heightened scrutiny from regulators, as they will be expected to demonstrate AI Act compliance through alternative means. In practice, that means building a bespoke compliance framework from scratch - a significantly heavier lift.
Until 2 August 2026, for signatories that do not fully implement all commitments immediately after signing the Code, the AI Office will not consider them to have broken their commitments under the Code and will not reproach them for violating the AI Act. This grace period makes early sign-up a low-risk, high-reward decision.
The Compliance Timeline: Three Dates to Know
The three dates in plain English:
- 2 August 2025 - All GPAI models placed on the EU market from 2 August 2025 must comply with Chapter V obligations. The Code of Practice is available as the primary compliance pathway.
- 2 August 2026 - The Commission's enforcement powers for GPAI - including requests for information, model access, and recalls - begin on 2 August 2026. While providers have been subject to these obligations since 2 August 2025, they are given an adjustment period of one year before the Commission may start exercising its supervision and enforcement powers against them.
- 2 August 2027 - GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to come into full compliance. The Code of Practice is a crucial tool for ensuring compliance in the interim period between when GPAI model provider obligations came into effect and the adoption of harmonised standards.
What Downstream Developers Need to Know
If you fine-tune, modify, or integrate a third-party GPAI model, your obligations depend on how deeply you change the underlying model.
Integrators (API users, embedders) A downstream actor that integrates a GPAI model into its AI system will not generally be considered the provider of that GPAI model - although it will need to comply with other obligations under the AI Act in relation to that AI system. Your primary duty is to obtain the Article 53 technical documentation from the upstream provider and factor known model limitations into your own risk management.
Fine-tuners and modifiers A downstream modifier only becomes a provider of a new GPAI model "if the modification leads to a significant change in the model's generality, capabilities, or systemic risk." The indicative criterion for such a significant change is that the training compute used for the modification is greater than a third of the training compute used to train the original model.
In practice, companies' fine-tuning or modification will rarely meet this threshold. Standard domain-specific fine-tuning - adapting a model for legal document review or customer service - almost certainly does not trigger full GPAI provider status.
What fine-tuners who do become providers must do In the case of a fine-tuning or other modification of a GPAI model, where the modifier becomes the provider of the modified model, their commitments under the Transparency Chapter of the Code should be limited to that modification or fine-tuning, to comply with the principle of proportionality.
The information-flow obligation runs upstream to downstream. Even if you are not a GPAI provider yourself, you are entitled — and in some cases required — to receive technical documentation, capability disclosures, and limitation notices from the upstream GPAI provider whose model you integrate. If your upstream provider is not supplying this information, that is a compliance gap on their side that you should flag contractually.
Penalties
Penalties for GPAI provider infringements can reach up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The Commission may impose fines not exceeding 3% of annual total worldwide turnover or €15,000,000, whichever is higher, when it finds that the provider intentionally or negligently infringed the relevant provisions, failed to comply with a request for documents or information, failed to comply with a requested measure, or failed to make the model available for evaluation.
Three points compliance teams often miss:
- The "higher of" structure is not a cap - it is a floor. For a large model provider with €10 billion in global revenue, 3% means €300 million. The €15 million figure is only relevant for smaller organisations.
- Global turnover, not EU turnover. The calculation does not look at the revenue generated by the specific AI product in question, nor does it look exclusively at European revenue. It assesses the preceding financial year's total worldwide annual turnover of the offending corporate entity.
- SME relief is conditional. The AI Act includes proportionality provisions for SMEs and startups. For smaller companies, the fine is capped at the lower of the two amounts - percentage of turnover versus fixed amount.
The European AI Office has direct enforcement authority only for GPAI model rules under Chapter V. National market surveillance authorities handle the rest of the Act.
Practical Next Steps
The GPAI regime is now in force, the Code of Practice is finalised, and the Commission's enforcement clock starts ticking in August 2026. Here is where to focus:
- Determine whether you are a GPAI provider. Apply the 10²³ FLOP indicative threshold and the generality test. If in doubt, the Commission's GPAI Guidelines published in July 2025 provide the most authoritative scoping guidance.
- Assess systemic-risk status. If your model was trained above 10²⁵ FLOPs, or if the AI Office could designate it on capability grounds, Article 55 obligations apply now.
- Decide on the Code of Practice. Signing it is the lowest-friction path to demonstrating compliance and benefits from the AI Office's good-faith grace period until August 2026.
- Audit your downstream information flows. Ensure your technical documentation, capability disclosures, and copyright policy are ready to share with downstream integrators.
- If you are a downstream developer, request Article 53 documentation from your upstream GPAI provider and document that you have done so.
The window between now and August 2026 is the practical compliance runway. Use it.
Use the GPAI Obligations Checker on AI Act Navigator to map which Article 53 and Article 55 duties apply to your specific model - and get a plain-English checklist you can share with your legal and engineering teams.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.