GPAI Model Obligations Under the AI Act: What Changed in August 2025

By Jurista.ai Editorial

A New Regulatory Category

The EU AI Act created a regulatory framework unlike anything that came before it: rules specifically designed for general-purpose AI (GPAI) models — the foundational models that power systems like large language models, image generators, and multi-modal AI systems.

On 2 August 2025, the GPAI provisions of the AI Act (Title VIII, Articles 51–55) became applicable. If your organization develops, fine-tunes, or distributes a GPAI model — even if you are not in the EU — these rules now apply to you.

What Counts as a GPAI Model?

The AI Act defines a GPAI model as “an AI model, including where trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications.”

In practice, this captures:

  • Large language models (LLMs) used for text generation, summarization, or analysis
  • Multi-modal models that process text, images, audio, or video
  • Foundation models fine-tuned for specific applications
  • Open-source models that meet the generality threshold (with some exemptions)

A model is GPAI if it is general-purpose — capable of performing a wide range of tasks — regardless of whether it is eventually used for a specific high-risk purpose. If you build a model that can both write poetry and analyze legal contracts, it is a GPAI model. The downstream use in employment screening would additionally trigger high-risk obligations for the deployer.

Two Tiers: GPAI vs. GPAI with Systemic Risk

The Act creates two tiers of obligation:

Tier 1: All GPAI Models (Article 53)

Every GPAI provider — regardless of model size — must:

Publish technical documentation describing:

  • The training and testing process
  • Data sources and data governance
  • Computational resources used
  • Known capabilities and limitations
  • Evaluation results for performance, robustness, and safety

Make information available to downstream providers — those who integrate the GPAI model into their own AI systems. This includes:

  • The conditions under which the model may be used
  • The model’s capabilities and limitations
  • Technical measures that facilitate compliance with the AI Act (e.g., labeling synthetic content)

Establish a copyright policy that:

  • Reflects the state of the art in identifying and respecting rights holders’ reservations
  • Includes a downstream policy for distributors, deployers, and other intermediaries
  • Is proportionate to the model’s size and impact

Publish a training data summary containing:

  • A sufficiently detailed summary of the content used for training
  • Made publicly available (not just to regulators or commercial partners)

Tier 2: GPAI with Systemic Risk (Article 55)

A GPAI model is classified as having systemic risk if:

  • It has high-impact capabilities (e.g., matching or exceeding the capabilities of the most advanced models in the AI Office’s benchmarks), OR
  • The Commission designates it as such based on documented criteria

The quantitative threshold established by the Commission is 10^25 FLOPs (floating point operations) used during training. If your model exceeds this threshold, it is presumed to have systemic risk.

In addition to all Tier 1 obligations, systemic-risk providers must:

Conduct model evaluations including:

  • Adversarial testing (red-teaming)
  • Risk mitigation measures proportional to the identified risks
  • Incident reporting to the AI Office and national authorities

Track and report serious incidents — any serious breach of fundamental rights or safety incidents must be reported without undue delay

Ensure an adequate level of cybersecurity protection proportionate to the model’s capabilities and risk profile

The Code of Practice

On 2 August 2025, the AI Office’s General-Purpose AI Code of Practice also came into effect. The Code provides a voluntary framework for GPAI providers to demonstrate compliance with their obligations. Key aspects:

  • Risk assessment and mitigation: Providers commit to identifying and mitigating systemic risks, including harmful bias, manipulation, and weaponization potential.
  • Governance frameworks: Internal accountability structures, roles, and responsibilities for AI safety.
  • External reporting: Commitments to publish safety frameworks, evaluation results, and incident reports.
  • Information sharing: Mechanisms for downstream providers to receive technical information needed for their own compliance.

Signing the Code of Practice creates a presumption of compliance with Articles 53 and 55 obligations (a “safe harbor”). Providers that do not sign the Code must demonstrate compliance through alternative means, which is more burdensome and subject to greater regulatory scrutiny.

As of August 2025, all major GPAI providers — including OpenAI, Anthropic, Google, and Mistral — have either signed the Code or published alternative compliance frameworks.

What Changed for Your Organization

If you are a GPAI provider:

  1. Technical documentation is now mandatory — not optional, not “nice to have.” The documentation must be maintained and updated.
  2. You must provide downstream information packages to anyone integrating your model into a product or service.
  3. Copyright policy is required. Training data without respect for rights reservations (e.g., websites’ robots.txt or text-and-data-mining opt-outs) creates liability.
  4. If you exceed 10^25 FLOPs, you face the full systemic-risk regime: adversarial testing, incident reporting, enhanced cybersecurity.

If you are a downstream provider (building products on GPAI models):

  1. You are entitled to — and should demand — technical documentation from your GPAI suppliers.
  2. You bear the high-risk compliance burden if your product falls under Annex III.
  3. Lack of transparency from your GPAI supplier does not excuse your compliance failures.

If you are a deployer:

  1. You need to know whether the AI system you deploy incorporates a GPAI model.
  2. You need to understand the model’s limitations, potential biases, and security characteristics.
  3. For high-risk applications, you need documented assurance that the GPAI provider meets its obligations.

Common Questions

Does fine-tuning make me a GPAI provider? Substantial modification — including fine-tuning that creates new capabilities or changes the model’s intended purpose — can make you a GPAI provider with independent obligations. Minor fine-tuning for a specific downstream task may not. The distinction is not always clear-cut; document your analysis.

Are open-source models exempt? GPAI models released under open-source licenses that permit free use, modification, and distribution benefit from reduced transparency obligations under Article 53(3). However, this exemption does not apply if the model has systemic risk, and it does not exempt downstream providers who incorporate the model into high-risk systems.

What about models trained before the Act? The GPAI rules apply to models placed on the market after 2 August 2025. Models already in commercial use before that date are not grandfathered indefinitely — updates, new versions, or new deployments trigger the obligations.

The Enforcement Reality

The AI Office has established a dedicated team for GPAI oversight. National authorities are building capacity to monitor and investigate GPAI providers. And critically, the whistleblowing and reporting mechanisms in the AI Act mean that non-compliance can be flagged by employees, researchers, or civil society organizations.

Fines for GPAI violations follow the standard penalty structure: up to €15 million or 3% of global turnover for failures to meet Article 53–55 obligations. For systemic-risk providers that fail to report incidents or cooperate with authorities, penalties can reach €7.5 million or 1% of global turnover.

Next Steps for Compliance

  1. Inventory your models: Identify every GPAI model you develop, fine-tune, or distribute.
  2. Calculate training FLOPs: Determine whether you cross the systemic-risk threshold.
  3. Prepare documentation: Build technical documentation templates aligned with the AI Office’s requirements.
  4. Review the Code of Practice: Decide whether signing it is the right compliance strategy.
  5. Update supplier contracts: If you use third-party GPAI models, ensure your agreements include information-sharing clauses.
  6. Train your teams: Engineering, legal, and compliance teams need to understand these obligations.

Jurista.ai tracks GPAI regulatory developments, manages technical documentation, and monitors compliance with the Code of Practice. Learn more.