What makes a model general-purpose under Article 3(63)
GPAI obligations are not pending. They applied on 2 August 2025, alongside the governance framework and the penalty provisions, and the Digital Omnibus did not touch that date. If you have placed a general-purpose model on the EU market at any point since then, the Article 53 duties were live at placement, not at some future cliff.
The definition is in Art 3(63): a model that displays significant generality and competently performs a wide range of distinct tasks, and that can be integrated into downstream systems and applications. Two things fall out of that wording. The test is about capability, not about how you market the model. And it is about breadth, so a very large model built to do one thing is a different case from a mid-sized model that does forty things adequately.
The 10^23 FLOP line is an indicator, not a definition
Commission guidance offers an indicative threshold above 10^23 FLOPs of training compute. That number is a proxy: models trained at that scale on broad data almost always turn out to be general. It is not a safe harbour. A model below the line that genuinely performs across a wide task range is still a general-purpose AI model, and the regulation, not the guidance, is what an authority applies. The conservative posture is straightforward: if your training compute is anywhere near 10^23 FLOPs, write the Article 3(63) assessment down and date it, whichever way it comes out.
Model, system, and the fine-tuning trap
The Act treats the model and the systems built on it as separate objects with separate accountable parties. Articles 53 to 55 bind the provider of the model. The provider of a system that embeds the model owes its own obligations, which is where the high-risk regime and Article 50 transparency land. One organisation frequently holds both roles at once.
Fine-tuning or substantially modifying a general-purpose model can make you the provider of a new model, with the Article 53 baseline attaching to what you built. The July 2025 guidance offers an indicative one-third-of-original-training-compute threshold for when that happens. Treat it as guidance rather than black-letter law: it has not been tested, and a modification that materially changes the capability profile is the substantive question. If you are working out which hat you are wearing, the guide to provider, deployer and the Article 25 flip walks the role test in order.
The Article 53 baseline: documentation, copyright and the training-data summary
Every provider of a general-purpose AI model owes four things under Art 53, regardless of size, and regardless of whether the model is anywhere near the systemic-risk tier. Two of the four can be lifted by the free and open-source exemption covered below.
- Annex XI technical documentation. Drawn up and kept up to date, covering how the model was trained and tested and what it can do, and provided to the AI Office and national competent authorities on request.
- Annex XII information for downstream providers. The package a system builder needs to understand the capabilities and limitations of your model well enough to meet its own obligations.
- A copyright policy. A documented policy governing how the model respects Union law on copyright and related rights, including at training time.
- A public summary of the training data. This one is public. The other three are supplied on request or under contract, so the training-data summary is the part of your compliance posture that competitors, journalists and rights holders can read.
Annex XI and Annex XII are often conflated. They have different readers, different contents and different failure modes.
| Annex XI technical documentation | Annex XII downstream information | |
|---|---|---|
| Who reads it | The AI Office and national competent authorities, on request | Providers integrating your model into their own AI systems |
| What it is for | Showing a regulator how the model was built, trained and evaluated | Letting the integrator classify and document its own system |
| Published? | No, disclosed to authorities on request | No, supplied to the integrator, typically under contract |
| Free and open-source exemption | Available, unless the model carries systemic risk | Available, unless the model carries systemic risk |
| If you get it wrong | You cannot answer an AI Office request without reconstructing history | Your customers cannot comply, and they will come back to you for it |
The free and open-source exemption, and where it stops
There are two separate open-source carve-outs in the Act and they are routinely merged into one, which is how teams talk themselves out of obligations they still owe.
At system level, Art 2 excludes free and open-source AI systems from the regulation, unless the system is high-risk, is a prohibited practice, or falls under Article 50. That last carve-out from the carve-out is wide: an open-source chatbot or image generator is squarely inside Article 50 regardless of its licence.
At model level, the exemption is narrower still. Article 53 lifts the Annex XI and Annex XII documentation duties for models released under a free and open-source licence that allows access, use, modification and distribution, with parameters including weights and architecture made public. It does not lift the copyright policy and it does not lift the public summary of training data. Those two are owed by every GPAI provider. And the whole exemption falls away the moment the model is classified as carrying systemic risk.
Open weights is not the same as the exemption. The exemption is licence-and-disclosure conditional. Publishing weights while gating real use behind a paid tier, a restricted-field licence or a no-commercial-use clause does not meet it, and neither does releasing weights without the architecture and usage information. If your release would fail a strict reading of the licence conditions, assume you owe the full Article 53 set and build the Annex XI file anyway.
Systemic risk: the 10^25 FLOP presumption and the Article 55 duties
Art 51 presumes that a general-purpose AI model carries systemic risk when the cumulative compute used for its training exceeds 10^25 FLOPs. This is the second tier, and it is additive: everything in Article 53 still applies, with no open-source relief, and Article 55 stacks on top.
The four Article 55 duties are:
- Model evaluation, including adversarial testing. Identify and mitigate systemic risks by evaluating the model against the state of the art.
- Systemic-risk assessment and mitigation. Assess and mitigate possible systemic risks at Union level, including their sources.
- Serious-incident reporting to the AI Office. Track, document and report serious incidents and possible corrective measures without undue delay.
- Cybersecurity protection. An adequate level of protection for the model and its physical infrastructure.
On top of that, a provider must notify the Commission within two weeks of meeting or expecting to meet the threshold.
The two-week clock starts before the weights exist. Training compute is budgeted in advance, so a provider usually knows it will cross 10^25 FLOPs weeks or months before the run finishes. Treating the notification as a release-day formality is the wrong reading, and it leaves you standing up the Article 55 evaluation and incident-reporting machinery under time pressure rather than alongside the training run.
Side by side, the two tiers look like this.
| Duty | Every GPAI model (Art 53) | GPAI with systemic risk (Art 51, 55) |
|---|---|---|
| Annex XI technical documentation | Yes · open-source exemption available | Yes · no exemption |
| Annex XII downstream information | Yes · open-source exemption available | Yes · no exemption |
| Copyright policy | Yes · no exemption | Yes · no exemption |
| Public summary of training data | Yes · no exemption | Yes · no exemption |
| Model evaluation and adversarial testing | No | Yes |
| Systemic-risk assessment and mitigation | No | Yes |
| Serious-incident reporting to the AI Office | No | Yes |
| Cybersecurity protection of the model | No | Yes |
| Notify the Commission | No | Yes · within two weeks |
Enforcement for GPAI models sits with the AI Office rather than with national market surveillance authorities, which also covers systems built by the same provider on top of its own model. The exposure is the ordinary penalty arithmetic: most obligations outside the Article 5 prohibitions carry up to 15,000,000 EUR or 3% of total worldwide annual turnover, with companies paying the higher of the two figures and SMEs and start-ups paying the lower. The breakdown of the three penalty tiers and who enforces them sets out how each tier is calculated.
The GPAI Code of Practice and its three chapters
The GPAI Code of Practice was published by the AI Office and the Commission on 10 July 2025 and formally approved on 1 August 2025, the day before the GPAI chapter applied. It was developed through a multistakeholder process with nearly 1,000 participants, and it is the primary route to demonstrate compliance with Articles 53 and 55.
It has three chapters, and they map onto the two-tier structure directly.
- Transparency. The documentation side of the Article 53 baseline: what you record about the model and what you hand to authorities and to downstream providers.
- Copyright. The Article 53 copyright policy, worked into concrete commitments about how training data is sourced and how rights are respected.
- Safety and Security. The Article 55 layer, addressed to the systemic-risk tier: evaluation, risk assessment and mitigation, incident reporting and security.
Adherence is voluntary, and the Code creates no obligation that Articles 53 and 55 do not already create. What it changes is the burden of explanation. A provider following the Code can point at a Commission-approved framework. A provider that declines has to show the AI Office, in a format of its own devising, that its documentation, copyright policy and mitigations are equivalent. For most providers that is a worse trade.
Two codes, two subjects. The GPAI Code of Practice (approved 1 August 2025) is about Articles 53 and 55. The Code of Practice on transparency of AI-generated content, final version published 10 June 2026, is a different instrument covering Article 50 marking. Adhering to one says nothing about the other, and teams that assume the GPAI Code covers their watermarking are reading the wrong document.
What a model provider owes the builders on top
Annex XII is the hinge of the whole regime. A company that integrates your model into a CV screening tool has to classify that system, and if it lands in Annex III it has to build an Annex IV technical file, run a conformity assessment and register. None of that is possible without knowing what the underlying model was trained on, how it was evaluated, where it degrades and what it should not be used for. The Act puts that information transfer on you.
The relationship is asymmetric in a way worth being blunt about. Your downstream providers carry the obligations for the use case, and the two routes that make an AI system high-risk under Article 6 are tested against their product, not your model. But they cannot discharge those obligations on information you have not given them, so gaps in your Annex XII package surface as support tickets, contract renegotiations and, eventually, customer churn long before they surface as an enforcement matter.
In the other direction, Article 25 sets out how a customer can accidentally take over as provider. Modifying the intended purpose of a general-purpose AI system so that it becomes high-risk makes the modifier the provider of a high-risk system, with the full Article 16 obligation set. Putting a name or trademark on a high-risk system already on the market does the same. This is worth saying explicitly in your documentation and in your terms: what your model is intended for, and which downstream changes take the customer outside it.
Where Article 50(2) marking lands on the model provider
Art 50(2) is a provider duty, and it reaches general-purpose systems generating synthetic audio, image, video or text. Outputs have to be marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable. There are exceptions for systems performing an assistive function for standard editing or not substantially altering the input data or its semantics, and for law enforcement.
Two situations follow. If you ship a system as well as a model, an API, an app, a chat product, you owe 50(2) on that system directly, along with the Art 50(1) duty to design an interactive system so people know they are dealing with an AI. If you ship weights only, the duty formally attaches to whoever places the system on the market. In practice watermarking is a model-side capability, so a downstream provider often cannot mark what your model does not support. The conservative posture for weight-only releases is to build and document the marking capability anyway and tell integrators how to use it.
The content transparency Code is voluntary, but it sets the practical bar. It asks for multi-layered marking, at least two layers where a single technique cannot meet the four criteria, with exceptions for generative systems embedded in closed physical products and for free-form text. Watermarking applies to free-form text longer than 200 tokens, and text under 200 tokens is exempt. If you are working out which of the four Article 50 duties attach to you as opposed to your customers, the duty-by-duty breakdown of Article 50 transparency splits 50(1) to 50(4) by provider and deployer. To see which tier and which duties your own model and systems trip, in order, run the free seven-stage triage.