What counts as GPAI, and what you must do
General-purpose AI models carry their own obligations under Chapter V — who is a GPAI model provider, what Art. 53 asks, when Art. 55 adds systemic-risk duties, and what Veritome generates.
A general-purpose AI model (Art. 3(63)) is a model trained on broad data at scale, that displays significant generality and can competently perform a wide range of distinct tasks, and that can be integrated into many downstream systems. Chapter V regulates it as a model, separately from any AI system built on it — a chatbot built on a licensed model is an AI system with its own tier and duties, while the model underneath has Chapter V duties that belong to whoever provides it.
Who is a GPAI model provider
- If you train a GPAI model and place it on the market — including under your own name after fine-tuning someone else's, where that makes you its provider — you are a GPAI model provider.
- If you merely use a third-party model through an API or a licence, you are the provider or deployer of the downstream system. The model provider's Chapter V duties are theirs, not yours; you inherit the downstream information they must give you (Art. 53(1)(b)) and may still owe Art. 50 transparency on the system you build.
Veritome distinguishes "uses a GPAI model" from "is a GPAI model provider" during registration, and records systemic risk separately, so you only get the duties that are actually yours.
Art. 53 — every GPAI model provider
- Art. 53(1)(a) — draw up and keep up to date the model's technical documentation per Annex XI, for the AI Office and national authorities on request.
- Art. 53(1)(b) — make information and documentation available to downstream providers integrating the model, per Annex XII, so they can meet their own obligations.
- Art. 53(1)(c) — put in place a policy to comply with Union copyright law, including the text-and-data-mining opt-outs rights-holders reserve.
- Art. 53(1)(d) — draw up and make public a sufficiently detailed summary of the content used to train the model.
A model released under a free and open-source licence, with its parameters and architecture public, is exempt from the first two of those duties unless it carries systemic risk (Art. 53(2)); the copyright policy and the training summary apply regardless. Providers cooperate with the Commission and national authorities (Art. 53(3)), and a non-EU provider appoints an EU authorised representative before placing a model on the market (Art. 54).
Art. 51 and 55 — systemic risk
A model is presumed to carry systemic risk when the compute used to train it exceeds 10²⁵ floating-point operations, or when the Commission designates it (Art. 51). The provider notifies the Commission within two weeks of meeting the threshold (Art. 52(1)). Systemic risk adds four duties (Art. 55(1)):
- (a) model evaluation with state-of-the-art tools, including adversarial testing;
- (b) assessing and mitigating possible systemic risks at Union level, including their sources;
- (c) tracking, documenting and reporting serious incidents and corrective measures to the AI Office and authorities;
- (d) an adequate level of cybersecurity for the model and its physical infrastructure.
When it applies
The Chapter V duties have applied since 2 August 2025. A model placed on the market before that date has until 2 August 2027 to conform. Adherence to a code of practice under Art. 56 is one way to show compliance until a harmonised standard exists.
In Veritome
A system flagged as a GPAI model gets the Art. 53 rows — and, where systemic risk is recorded, the Art. 55 rows — in its Obligations, and the GPAI module workspace rolls them up across the register. Documents carries the model's paperwork: the Annex XI model documentation and the public training-content summary are prescribed documents with a fixed field set; the Annex XII downstream information is a structured record; the copyright compliance policy is one of the organisation-wide policies you write, approve and issue. See GPAI disclosures for the workspace itself.