General-Purpose AI and Foundation Models — What the GPAI Rules Actually Require

Published 30 April 2026 · 1 min read

The EU AI Act creates a separate compliance track for providers of large language models, multimodal models, and other foundation models — what the regulation calls general-purpose AI (GPAI) models. If you build or release one, obligations apply from 2 August 2025, a full year before the main AI Act enforcement date. If you use one via an API, you are not a GPAI provider — but you still have four things to check.

What counts as a GPAI model

Under Article 3(63), a GPAI model is trained on large amounts of data using self-supervision at scale, displays significant generality, and can perform a wide range of distinct tasks. GPT-4, Claude 3 Opus, Gemini Ultra, LLaMA 3, and Mistral Large all meet the definition. A narrow, single-task model trained in-house does not. The key is generality: a model that can write, summarise, translate, code, and reason across domains is a GPAI model. One that predicts customer churn from spreadsheet data is not.

Two tiers of obligation

Every GPAI model falls into one of two tiers. Standard GPAI models (Articles 52–54) must: draw up and maintain technical documentation per Annex XI, make model information available to downstream providers, implement a copyright compliance policy, and publish a public summary of training data. Open-source GPAI models below the systemic-risk threshold are exempt from the documentation and downstream information requirements, but the copyright policy and training data summary apply regardless of licence.

GPAI models trained with more than 1025 floating point operations (FLOPs) are classified as systemic risk and face additional obligations under Articles 55–56: perform adversarial testing (red-teaming) documented per Annex XI, Section 2, assess and mitigate systemic risks at EU level, report serious incidents to the AI Office, and implement cybersecurity protections. The open-source exemption does not apply to systemic-risk models.

The AI Office and the Code of Practice

The European AI Office (Article 64) supervises GPAI compliance. It can classify models as systemic risk, request model access and documentation, and conduct its own evaluations. A GPAI Code of Practice — developed with industry and civil society — provides structured compliance pathways. Under Article 53(4), providers may rely on the code to demonstrate compliance until a harmonised standard is published; the presumption of conformity itself comes only from compliance with harmonised standards. The first draft was published in November 2024; providers are expected to document their position relative to it.

If you use a GPAI API, you are not a GPAI provider — but check four things

Calling the OpenAI, Anthropic, or Google Gemini API does not make you a GPAI provider. The Articles 51–56 obligations rest with the model developer. However: (1) if your application is high-risk, you have deployer obligations under Chapter III regardless of which model powers it; (2) you can request model information from your GPAI provider under Article 53(1)(b) to satisfy your own documentation requirements; (3) if you fine-tune an open-source model and release it on the EU market, you may become a GPAI provider yourself; and (4) check your GPAI provider’s acceptable use policy — deploying the model in prohibited or high-risk ways that violate those terms also exposes you to AI Act liability.

What’s in the full chapter

The full chapter covers the complete Article 3(63) definition of GPAI models, a breakdown of all Articles 52–56 obligations with the Annex XI and Annex XII documentation requirements, the open-source exception and its limits, how systemic risk is assessed and who decides, the AI Office’s supervisory powers, practical implications for deployers using third-party GPAI APIs, and an 8-item self-check covering both GPAI providers and downstream deployers.

Read the Full Chapter

Get the complete Chapter 11 with obligation tables, open-source exception limits, and the 8-item self-check for GPAI providers and deployers.

Read the Full Chapter Check Your AI Risk Level — Free