Skip to content
Beyond Prompt AI Studio
The EU AI Act in Practice

If You Deploy or Provide Models Yourself: GPAI Obligations

This module only affects most companies indirectly – and that's the most important takeaway. General-purpose AI (GPAI) obligations apply to the model providers themselves, not to those building on top of their APIs. There is, however, one specific case where you become a GPAI provider yourself.

Four practical cases – worth remembering

Try it yourself: regular model vs. systemic risk model

Tap a dimension to compare both sides.

Regular GPAI model

Regular GPAI model: technical documentation, transparency info, comply with copyright policy.

Systemic risk model

Systemic risk model: the same base obligations apply on top.

What GPAI providers generally have to do

Providers of general-purpose AI models (models with broad capability, not tailored to a narrow purpose) must provide technical documentation, inform downstream users about capabilities and limits, comply with a copyright policy, and publish a summary of training data. In July 2025, the European Commission published a final “Code of Practice” for this – a voluntary but practical tool with three chapters: transparency, copyright, safety (the last one only for models with systemic risk). These obligations have applied since 2 August 2025 for newly placed models; for models already on the market before that, there's a transition period until 2 August 2027.

The systemic risk threshold: 10^25 FLOPs

An additional, heavier tier of obligations (Art. 55) kicks in for models with “systemic risk” – presumed above a cumulative training compute of 10^25 FLOP (floating-point operations). That's a rebuttable presumption, not a rigid cutoff, and currently affects only a handful of the largest models worldwide. Additional obligations for these models: systematic model evaluation including adversarial testing, systemic risk assessment and mitigation, serious incident reporting to the EU AI Office, and heightened cybersecurity requirements.

When does this actually affect you as an SME?

For the vast majority of companies: practically never, directly. Anyone building an application on top of GPT, Claude, Gemini, or an open model like Llama – via API or a ready-made interface – is a user of a GPAI model, not its provider. The GPAI obligations under Art. 53–55 apply to the handful of companies that develop and release these foundation models themselves. The one relevant exception: if you substantially fine-tune an existing general-purpose model and release it under your own name such that it becomes a distinct model, you can slide into the provider obligations yourself – the same mechanism as the “provider through fine-tuning” trap from the module “Provider or Deployer?”.

Practice section: what's actually worth checking

For the overwhelming majority – companies using a model via API or a ready-made interface – building your own GPAI compliance program isn't worth it; a short vendor check is. Is the model provider a signatory of the Code of Practice? Do they provide the required transparency information? That belongs in normal vendor due diligence, not a dedicated compliance project. Only if you release your own, substantially fine-tuned model publicly under your own name should you have the full GPAI obligations reviewed. This classification doesn't replace case-by-case legal advice.

The key points

  • GPAI obligations (Art. 51–55) apply to the model providers themselves – practically never directly relevant for companies accessing a model via API or a ready-made interface.
  • The Code of Practice (finalised July 2025) structures the base obligations into three chapters: transparency, copyright, safety (only for systemic risk).
  • The systemic risk threshold sits at 10^25 FLOP of cumulative training compute – a rebuttable presumption currently affecting only a handful of the largest models worldwide.
  • The relevant exception for SMEs: substantially fine-tuning and releasing a model under your own name can itself trigger provider obligations.
  • For most companies, a short vendor check (the model provider's Code of Practice status) is enough – this classification doesn't replace case-by-case legal advice.

The EU AI Act: what companies really need to know – and what's just panic

Quick check: did it sink in?

1 / 3

Who do the GPAI obligations under Art. 51–55 primarily apply to?

Building your own application on top of an AI model and want to make sure the provider chain is clean?