2.1 · The EU AI Act — Operational Compliance Essentials

General-Purpose AI Models — The Obligations Most Businesses Miss

10 minCourse 02

The four risk tiers cover AI *systems* — software with a defined purpose. But the Act also regulates something one level further upstream: general-purpose AI (GPAI) *models*, the large foundation models (GPT, Claude, Gemini, Llama and their peers) that thousands of downstream systems are built on. These obligations have been in force since 2 August 2025, and they change what you should be asking your AI vendors.

What GPAI Providers Must Do

Since August 2025, any provider placing a general-purpose AI model on the EU market must:

  • Maintain technical documentation covering the model's training, testing, and evaluation
  • Provide documentation to downstream providers — the businesses building systems on the model — sufficient for them to meet their own AI Act obligations
  • Put in place a copyright policy, including honouring machine-readable opt-outs from text and data mining
  • Publish a summary of the content used to train the model, using the AI Office's template

Models classified as carrying *systemic risk* — presumed when training compute exceeds 10^25 floating-point operations, which captures today's frontier models — face additional duties: state-of-the-art model evaluations including adversarial testing, assessment and mitigation of systemic risks, serious-incident reporting to the AI Office, and adequate cybersecurity protection.

A GPAI Code of Practice, published in 2025 and signed by most major model providers, is the main route to demonstrating compliance. Enforcement sits with the European Commission's AI Office, with fines for GPAI providers of up to 3% of global turnover or €15 million. Models already on the market before August 2025 have until August 2027 to come into full compliance.

Why This Matters If You Buy Rather Than Build

Most organisations will never be GPAI providers — you are a downstream deployer, and your own obligations come from the system risk tiers. But your compliance now depends partly on your vendor's. If you deploy a high-risk system built on a third-party model, you need the documentation that the GPAI rules oblige the provider to give you. Add two questions to the vendor due diligence list from Course 1: has this provider published its training-content summary, and will it supply the downstream documentation your own AI Act compliance requires?

One Change to Make Today

Add a column to your AI Register (built in Section 2.3): "Upstream model & GPAI status". For every system that sits on a foundation model, record which model, who provides it, and whether their GPAI documentation is available to you. When the high-risk regime bites in August 2026, that column will save you weeks.