What GPAI providers generally have to do
Providers of general-purpose AI models (models with broad capability, not tailored to a narrow purpose) must provide technical documentation, inform downstream users about capabilities and limits, comply with a copyright policy, and publish a summary of training data. In July 2025, the European Commission published a final “Code of Practice” for this – a voluntary but practical tool with three chapters: transparency, copyright, safety (the last one only for models with systemic risk). These obligations have applied since 2 August 2025 for newly placed models; for models already on the market before that, there's a transition period until 2 August 2027.
The systemic risk threshold: 10^25 FLOPs
An additional, heavier tier of obligations (Art. 55) kicks in for models with “systemic risk” – presumed above a cumulative training compute of 10^25 FLOP (floating-point operations). That's a rebuttable presumption, not a rigid cutoff, and currently affects only a handful of the largest models worldwide. Additional obligations for these models: systematic model evaluation including adversarial testing, systemic risk assessment and mitigation, serious incident reporting to the EU AI Office, and heightened cybersecurity requirements.
When does this actually affect you as an SME?
For the vast majority of companies: practically never, directly. Anyone building an application on top of GPT, Claude, Gemini, or an open model like Llama – via API or a ready-made interface – is a user of a GPAI model, not its provider. The GPAI obligations under Art. 53–55 apply to the handful of companies that develop and release these foundation models themselves. The one relevant exception: if you substantially fine-tune an existing general-purpose model and release it under your own name such that it becomes a distinct model, you can slide into the provider obligations yourself – the same mechanism as the “provider through fine-tuning” trap from the module “Provider or Deployer?”.
Practice section: what's actually worth checking
For the overwhelming majority – companies using a model via API or a ready-made interface – building your own GPAI compliance program isn't worth it; a short vendor check is. Is the model provider a signatory of the Code of Practice? Do they provide the required transparency information? That belongs in normal vendor due diligence, not a dedicated compliance project. Only if you release your own, substantially fine-tuned model publicly under your own name should you have the full GPAI obligations reviewed. This classification doesn't replace case-by-case legal advice.