Vigilis
EU AI Act

General-purpose AI model obligations (Articles 51–56)

Sourced from Regulation (EU) 2024/1689 (the EU AI Act), Chapter V, Articles 51–56

In short

Chapter V is a distinct regime for general-purpose AI (GPAI) models themselves, not the systems built on them, it applies to organisations that place a GPAI model on the market, not those that merely use one. Baseline duties (Art. 53) for every GPAI model provider: technical documentation, downstream information, an EU copyright policy, and a public training-content summary. Models with systemic risk (training compute above 10^25 FLOP, or Commission-designated) carry extra Article 55 duties, evaluation and adversarial testing, systemic-risk mitigation, incident reporting, and cybersecurity. Open-source models get a narrower exemption that doesn’t extend to systemic-risk models. These obligations applied from 2 August 2025.

Chapter V is a distinct, specialised regime that sits alongside the rest of the Act, it regulates general-purpose AI (GPAI) models themselves, not the specific AI systems built on top of them. It applies to organisations that place a GPAI model on the market, not to organisations that merely use one. These obligations applied from 2 August 2025.

Who is a GPAI model provider, and who isn't

A GPAI model is one trained on a large scale of data, displaying significant generality, and capable of competently performing a wide range of distinct tasks. You are a GPAI model provider only if you develop or place such a model on the market for others to use or build on, fine-tuning a third-party foundation model solely for your own internal use does not make you a GPAI model provider. This is a narrower and distinct category from being a provider of an AI system that happens to use a GPAI model underneath it.

Baseline obligations for every GPAI model provider (Article 53)

  • Draw up and keep up to date technical documentation covering the model’s training and testing process and evaluation results.
  • Provide information and documentation to downstream providers who integrate the model into their own AI systems, sufficient for them to understand its capabilities and limitations.
  • Put in place a policy to comply with EU copyright law, including identifying and respecting rights reservations.
  • Publish a sufficiently detailed summary of the content used to train the model, following a template the AI Office provides.

Additional obligations for models with systemic risk (Article 55)

A GPAI model is presumed to carry systemic risk if the cumulative compute used for its training exceeds a threshold set in the Act (10^25 floating point operations), or if the Commission designates it as such. Providers of these models carry additional duties: conducting model evaluation including adversarial testing, assessing and mitigating systemic risks at the EU level, tracking and reporting serious incidents, and ensuring an adequate level of cybersecurity protection for the model and its physical infrastructure.

A narrower exemption for open-source models

Article 53(2) exempts open-source GPAI models released under a free and open licence from some of the baseline transparency obligations, but this exemption does not extend to models presenting systemic risk, which carry the Article 55 obligations regardless of licensing.

Codes of practice

Article 56 provides for codes of practice, developed with the AI Office and stakeholders, that GPAI model providers can rely on to demonstrate compliance until harmonised standards are published, adherence to an approved code is treated as a presumption of conformity with the corresponding obligations.

If your organisation only uses a GPAI model (through an API, a licensed integration, or a fine-tuned internal deployment) Chapter V is not your obligation set; your compliance question is whether the specific AI system you built or deployed on top of it is itself high-risk, limited-risk, or minimal-risk under the rest of the Act.

Frequently asked questions

Who counts as a GPAI model provider?
An organisation that develops or places on the market a general-purpose AI model (one trained on large-scale data, displaying significant generality, and able to perform a wide range of tasks) for others to use or build on. Fine-tuning a third-party model solely for your own internal use does not make you a GPAI model provider.
What are the baseline GPAI model obligations?
Under Article 53: draw up and maintain technical documentation of training and testing; provide information to downstream providers integrating the model; put in place a policy to comply with EU copyright law; and publish a sufficiently detailed summary of the training content using the AI Office's template.
What extra rules apply to GPAI models with systemic risk?
A model is presumed to carry systemic risk if training compute exceeds 10^25 floating-point operations or the Commission designates it. Article 55 then adds model evaluation including adversarial testing, EU-level systemic-risk assessment and mitigation, serious-incident tracking and reporting, and adequate cybersecurity, and open-source status does not remove these.

Related guides

Not sure where your company stands?

Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.

Start the free check