General-purpose AI models
GPAI obligations under the EU AI Act are already in application.
Since 2 August 2025, providers placing general-purpose AI models on the EU market must comply with the AI Act's GPAI framework. Providers of GPAI models with systemic risk face additional risk, incident and cybersecurity duties.
Updated and legally reviewed: 26 September 2026.
Core obligations
All GPAI model providers have baseline duties.
Technical documentation
Providers must draw up and maintain technical documentation about the model and its development process, available to the AI Office when required.
Downstream information
Provide information and documentation needed by downstream AI-system providers to understand capabilities and limitations and meet their own obligations.
Copyright policy
Implement a policy to comply with Union copyright law and related rights, including relevant rights reservations.
Training-content summary
Publish a sufficiently detailed summary of content used to train the model using the Commission's required framework/template.
EU representative
A GPAI provider established outside the EU may need an authorised representative in the Union before placing the model on the EU market, subject to the Act's rules and exceptions.
Systemic risk
The most advanced GPAI models face additional obligations.
For GPAI models classified as posing systemic risk, the framework adds duties around model evaluation, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity protection.
Notification
Relevant providers must notify the Commission/AI Office as required for models with systemic risk.
Risk evaluation
Assess and mitigate systemic risks, including through appropriate model evaluation and testing.
Incident reporting
Track and report serious incidents in accordance with the applicable GPAI regime.
Cybersecurity
Maintain an adequate cybersecurity protection level for the model and its physical infrastructure.
Commission evaluation powers
Regulation (EU) 2026/1755 now governs how the Commission can evaluate GPAI models.
In force since 10 August 2026, the Implementing Regulation sets detailed procedures under Articles 92 and 101. Commission evaluation access can include APIs, internal access, source code, model weights and hosting infrastructure where appropriate to the evaluation objective, alongside procedural safeguards for possible fine proceedings.
GPAI Code of Practice
A voluntary compliance pathway, not a substitute for the law.
The Commission and Member States recognise the GPAI Code of Practice as an adequate voluntary tool to help providers demonstrate compliance. It includes Transparency, Copyright, and Safety & Security components; the Safety & Security chapter is relevant to providers of GPAI models with systemic risk.
For downstream companies
Using a GPAI model does not automatically make you the GPAI provider.
Downstream companies need to distinguish model-provider obligations from their own provider/deployer duties for the AI system built on top of the model. Significant modifications, rebranding, intended purpose and the commercial structure can change the analysis.
Official sources