EU AI Act · July 2026

GPAI Model Obligations: What Foundation Model Providers Must Do Now

8 min readTarget keyword: GPAI general purpose AI model EU AI Act obligations

While most enterprise compliance attention has focused on the December 2027 deadline for high-risk AI systems, a separate set of obligations is already in force — and affects a different class of organisation entirely: the providers of General-Purpose AI models.

If your organisation develops, fine-tunes, or makes available a large language model, multimodal system, or foundation model — GPAI obligations are not a future concern. They are a present legal requirement.


What Qualifies as a GPAI Model?

The EU AI Act defines a General-Purpose AI model as an AI model trained on large amounts of data using self-supervision at scale, that displays significant generality and is capable of performing a wide range of distinct tasks. In practical terms, this captures large language models, vision-language models, code generation models, and multimodal foundation models.

The definition explicitly does not cover AI systems that are developed and put into service exclusively for research, development, and prototyping purposes. But once a GPAI model is made available to any downstream provider or deployer — including through an API — GPAI obligations apply.

The critical threshold is not the model's capability. It is whether the model is made available to others — even internally within an enterprise group.


Baseline GPAI Obligations (All Providers)

Every provider of a GPAI model, regardless of scale, must meet four baseline obligations:

1. Technical Documentation

GPAI providers must prepare and maintain technical documentation before the model is placed on the market. This documentation must be kept up to date and provided to national competent authorities and the European AI Office on request. It must include: a general description of the model architecture, training methodology, training data characteristics, intended purposes, and known limitations.

2. Information for Downstream Providers

When a GPAI model is integrated into AI systems by downstream providers, the GPAI model provider must make available to those downstream providers the information and technical documentation they need to comply with their own obligations under the Act. This creates a supply chain of documentation obligation.

3. Copyright Policy

GPAI model providers must publish a sufficiently detailed summary of the training data used with respect to copyright law — enabling copyright holders to understand whether and how their content was used in training. The European AI Office is developing a template for this summary.

4. Data Protection Compliance

Training data must comply with applicable EU copyright law, and providers must put in place a policy to respect intellectual property rights under EU law.


The Systemic Risk Tier: Additional Obligations

GPAI models trained with more than 1025 FLOPs of compute — a threshold that currently captures the largest frontier models — are classified as GPAI models with systemic risk. These face additional obligations:

The 1025 FLOPs threshold is a proxy, not a final boundary. The European AI Office may designate specific models as having systemic risk even below this threshold, and the threshold itself may be revised as computing costs change.


What Downstream Providers Must Know

If your organisation builds products using a GPAI model — whether via API or by running a model on your own infrastructure — you are a downstream provider. Your GPAI model supplier's compliance status is your risk.

Downstream providers who deploy GPAI models in high-risk AI system contexts bear the full Article 9–17 obligations for those systems. The GPAI model provider's compliance with GPAI obligations does not substitute for the downstream provider's compliance with high-risk AI obligations.

This means that an enterprise using a foundation model API to power a credit scoring workflow is subject to both the GPAI model provider's transparency obligations and the enterprise's own high-risk AI obligations — including Article 12's automatic logging requirement.

The documentation chain matters: if you cannot demonstrate that your GPAI model provider has met their baseline obligations, your own technical documentation for the high-risk system built on top of it is incomplete by definition.


The Practical First Step

For GPAI model providers, the technical documentation obligation is non-negotiable and already in force. If you have not begun preparing that documentation, you are already late.

For downstream providers building on GPAI models, request your GPAI model provider's compliance documentation now. Do not assume that a well-known model provider is automatically compliant — verify.

And regardless of your position in the GPAI supply chain, if your AI system makes decisions that would be classified as high-risk under Annex III, the Article 12 logging obligation applies — and it applies from the first decision the system makes in a production context.

Transform your AI logs into regulatory evidence.

Provara seals every AI decision into a tamper-evident, cryptographically-chained ledger — producing signed evidence packets pre-mapped to EU AI Act, ISO 42001, NIST AI RMF, and SOC 2 requirements.

Request a 30-minute technical demo →