What Is a General Purpose AI Model?
The EU AI Act introduces a specific regulatory framework for General Purpose AI (GPAI) models in Chapter V (Articles 51–56). A GPAI model is an AI model that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of how it is placed on the market, and that can be integrated into a variety of downstream systems or applications.
This definition captures large language models (LLMs), multimodal foundation models, large image generation models, and similar AI systems trained on broad datasets for general-purpose use. The key distinguishing characteristic is generality: the model can be applied across diverse domains without being retrained for each one.
Baseline Obligations for All GPAI Models
Article 53 establishes baseline obligations that apply to all GPAI model providers, regardless of whether the model poses systemic risk. These baseline obligations cover technical documentation, transparency to downstream providers, copyright compliance, and publication of model summaries.
Providers must draw up technical documentation sufficient for the EU AI Office to assess compliance. They must make available to downstream providers information about the model's capabilities and limitations relevant to their intended use. They must implement a policy for compliance with EU copyright law, particularly the text and data mining exceptions. And they must publish a sufficiently detailed summary of the training data used.
Systemic Risk: Enhanced Obligations
GPAI models with systemic risk face significantly enhanced obligations under Article 55. A GPAI model is presumed to have systemic risk if the training compute exceeds 10^25 floating point operations (FLOPs), or if the EU AI Office designates it as having systemic risk based on other factors including its market reach, the extent of its integration into downstream systems, and its potential to cause serious adverse impacts.
For GPAI models with systemic risk, providers must conduct model evaluations, including adversarial testing, before and after market placement. They must assess and mitigate systemic risks, including those arising from misuse. They must report serious incidents to the EU AI Office. They must ensure cybersecurity protection adequate to the risks posed by the model.
Obligations When Your GPAI Model Is Used Downstream
A key feature of the GPAI model framework is the interaction between GPAI model providers and the downstream providers who integrate their models into AI systems or other AI models. Article 53(1)(b) establishes a flow-down obligation: GPAI model providers must ensure downstream providers have the information they need to comply with their own EU AI Act obligations.
This creates a supply chain compliance obligation. If a downstream provider builds a high-risk AI system using your GPAI model, they need sufficient information about your model's capabilities, limitations, and training data to satisfy their own Annex IV technical documentation requirements.
- Free obligation checkWhich provider duties reach your system, from its tier and behaviour.
- EU AI Act guideRoles, risk tiers, the dates, penalties and the six-phase path.
- Article 50 guideThe transparency duties in force, with a free notice generator.
- Free handbook (PDF)Sixteen chapters and six working tools in one document.
- Help centreTask-based articles on the product and the regulation.
- Frameworks explainedThe EU AI Act next to the GDPR, ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF.