COMPLIPATHDOC complipath.io/guides/gpai-obligations-eu-ai-actRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Deadlines ·By Yobel Tzegai ·Updated 22 August 2026

What are the general-purpose AI (GPAI) obligations under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

Providers of general-purpose AI models have had binding duties since 2 August 2025 under Article 113, third paragraph, point (b): technical documentation, downstream information, a copyright policy and a public training-content summary (Article 53) — plus the Article 55 duties above the systemic-risk threshold.

Quick answer

What counts as a general-purpose AI model?

Article 3, point (63) defines a general-purpose AI model as one that "displays significant generality and is capable of competently performing a wide range of distinct tasks" and can be integrated into a variety of downstream systems — including models "trained with a large amount of data using self-supervision at scale". Models used only for research, development or prototyping before market placement are excluded. A general-purpose AI system is different: an AI system based on such a model (Article 3, point (66)). Chapter V binds the model provider — role mechanics live in provider vs deployer.

What does Article 53 require from every GPAI provider?

Article 53(1) sets four duties:

Under Article 53(4), providers may rely on codes of practice (Article 56) to demonstrate compliance until a harmonised standard is published; following neither means demonstrating "alternative adequate means of compliance" to the Commission. The GPAI Code of Practice, finalised July 2025, is that route in practice; non-signatories carry the heavier evidentiary path.

Non-EU providers must appoint an EU-established authorised representative before placing a model on the Union market (Article 54(1)); it verifies the Article 53 duties and keeps the Annex XI documentation for 10 years (Article 54(3)).

Who gets the open-source exception?

Article 53(2) disapplies only points (a) and (b) — the two documentation duties — for models released under a free and open-source licence allowing access, usage, modification and distribution, whose parameters — weights, architecture and usage information — are made publicly available. The copyright policy and training-content summary bind every provider, and "this exception shall not apply to general-purpose AI models with systemic risks". Article 54(6) mirrors the carve-out for the authorised-representative duty. Open weights without an open licence — or the reverse — earn no exception.

When does a model carry systemic risk, and what changes?

A model carries systemic risk if it has high-impact capabilities measured by technical tools and benchmarks (Article 51(1), point (a)) or by Commission designation against the Annex XIII criteria (Article 51(1), point (b)). Article 51(2) supplies the operative presumption: cumulative training computation "greater than 10^25" floating-point operations. The Commission can amend the threshold by delegated act (Article 51(3)); none had at the time of writing.

The procedure is provider-initiated: notify the Commission "without delay and in any event within two weeks" of meeting the condition or knowing it will be met (Article 52(1)), optionally arguing the model exceptionally presents no systemic risk (Article 52(2)). The Commission publishes the list of systemic-risk models (Article 52(6)).

Classification adds the Article 55(1) duties on top of Articles 53 and 54: model evaluation with documented adversarial testing, assessment and mitigation of systemic risks at Union level, keeping track of, documenting and reporting serious incidents and possible corrective measures without undue delay to the AI Office and, as appropriate, to national competent authorities, and adequate cybersecurity for the model and its physical infrastructure.

What exactly started on 2 August 2025 — and what has changed since?

Article 113, third paragraph, point (b) applied Chapter III Section 4 (notified bodies), Chapter V (GPAI), Chapter VII (governance — AI Office and European Artificial Intelligence Board, Articles 64 and 65) and Chapter XII (penalties), plus Article 78 (confidentiality), from 2 August 2025 — "with the exception of Article 101". Member States had to publish their competent authorities' contact details by the same date (Article 70(2)). Codes of practice were due by 2 May 2025 (Article 56(9)); if none was finalised by 2 August 2025, the Commission could impose common rules.

Two things changed since. Article 101 — the GPAI fining power — fell to the Act's default application date and has applied since 2 August 2026 (Article 113), closing the first year's fines-free window. And Article 111(3) keeps running: models placed on the market before 2 August 2025 must comply by 2 August 2027. Every surrounding date is in the EU AI Act timeline.

Does building on a GPAI model make your product high-risk?

No — not automatically. High-risk classification attaches to AI systems by use case under Article 6(2) and Annex III, not to the model underneath. An integrator is a "downstream provider" (Article 3, point (68)); what matters is what the resulting system does — classify the system, not the model. Fine-tuning or rebranding can flip you into provider duties: see when a deployer becomes a provider.

What this means for you

If you're a provider of a GPAI model: audit in this order: (1) each model checked against the Article 3, point (63) definition, reasoning recorded; (2) the systemic-risk presumption checked, the Article 52(1) notification made if it bit; (3) Annex XI and XII documentation current, copyright policy in force, training summary on the template; (4) authorised representative if you're outside the EU; (5) evidence of Code of Practice adherence or alternative means. Complipath's register and guided risk classification keeps each system, its classification and the evidence in one place.

If you're a deployer or downstream provider: Chapter V does not bind you for using someone else's model — your exposure sits at system level. Classify what you built on top: the Annex III high-risk obligations apply from 2 December 2027, and the Article 6(1) product route from 2 August 2028 (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744) — later than your model-level duties, not sooner. Use Article 53(1), point (b): your model vendor owes you the Annex XII information — raw material for your own documentation.

Does Chapter V reach what you build?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

When did GPAI obligations start applying? 2 August 2025. Article 113, third paragraph, point (b) applied Chapter V — the GPAI rules — along with the notified-body, governance and penalties chapters. Models already on the market before that date have until 2 August 2027 to comply (Article 111(3)).

What is the 10^25 FLOP threshold? Article 51(2) presumes high-impact capabilities — and so systemic risk — when cumulative training compute exceeds 10^25 floating-point operations. The provider must notify the Commission within two weeks (Article 52(1)) and may argue the model nonetheless presents no systemic risk (Article 52(2)).

Are open-source GPAI models exempt? Only partially. Article 53(2) lifts the technical-documentation and downstream-information duties for models under a free and open-source licence with publicly available weights, architecture and usage information. The copyright policy and training-content summary still apply — and systemic-risk models get no exception at all.

What fines do GPAI providers face? The Commission may fine providers up to 3% of total worldwide annual turnover or €15 million, whichever is higher, for intentional or negligent infringement (Article 101(1)). Excluded from the 2025 start, Article 101 has applied since 2 August 2026 — the fining power is now live.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 51–56, 70, 101, 111 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex). What the 2026 amendment did not touch, and this guide therefore still states unchanged: the 2 August 2025 date for Chapter V and the other point (b) chapters (Article 113, third paragraph, point (b)), the Article 111(3) deadline of 2 August 2027 for models placed on the market before 2 August 2025, the Article 51(2) threshold, and Article 101, which still falls to the general application date of 2 August 2026. What it did move is the high-risk regime, cited above at its new dates. The Code of Practice's July 2025 finalisation, the unamended Article 51(2) threshold, and the absence of harmonised standards under Article 53(4) are observations at the time of writing, not statements of the Regulation — verify before relying on them.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.