All questions

Do general-purpose AI models have extra EU AI Act rules?

EU AI ActLegislation verified on Ook in het Nederlands

Short answer: Yes. Regulation (EU) 2024/1689 (the "EU AI Act" / "AI-verordening") adds a dedicated layer of rules specifically for general-purpose AI models (GPAI models) on top of the horizontal rules that apply to all AI systems. These extra obligations sit in Chapter V of the Act (Articles 51–56) and target the providers of GPAI models directly, regardless of how the model is later used.

What counts as a GPAI model?

Under Article 3, point (63), a general-purpose AI model is an AI model that:

  • demonstrates significant generality,
  • is capable of competently performing a wide range of distinct tasks, and
  • can be integrated into a variety of downstream systems or applications.

A footnote clarifies that a GPAI model may be released under a free and open-source licence (open weights), or under proprietary terms.

The typical case — obligations for every GPAI provider (Article 53)

Article 53 applies to every provider of a GPAI model placed on the EU market, regardless of whether the model is considered to pose systemic risk. Providers must:

  • draw up and keep up to date the technical documentation listed in Annex XI (general description, training process, evaluation, capabilities and limitations) — Article 53(1)(a);
  • provide that documentation and information to downstream integrators that intend to use the model in their AI systems, so they can comply with their own AI Act obligations — Article 53(1)(b);
  • put in place a copyright-compliance policy, in particular respecting the text-and-data-mining opt-out under Article 4(3) of Directive (EU) 2019/790 — Article 53(1)(c);
  • draw up and make publicly available a sufficiently detailed summary of the training content, following the template the AI Office provides — Article 53(1)(d) and Annex XII;
  • cooperate with the AI Office and national competent authorities on requests for information and on compliance — Article 53(1)(e)–(f).

Article 55 extends the regime: a downstream provider that substantially modifies a GPAI model so that it remains a GPAI model becomes a provider itself and inherits the Article 53 obligations (the threshold here is large-scale modification; mere fine-tuning into a non-GPAI system does not trigger GPAI-provider status).

The extra layer — GPAI models with systemic risk (Articles 51–52, 55)

A GPAI model is presumed to present systemic risk if the compute used to train it exceeds 10²⁵ floating-point operations (FLOPs) — Article 51(2). The European Commission can also designate other GPAI models as systemic risk under Article 51(3) (procedure in Article 52).

For these models, Article 55 adds four further obligations:

  • perform state-of-the-art evaluations and adversarial testing — Article 55(1)(a);
  • assess and mitigate possible systemic risks at Union level, including risks from development, placing on the market or use — Article 55(1)(b);
  • track and report serious incidents and possible misuse to the AI Office and, where relevant, national authorities — Article 55(1)(c);
  • ensure adequate cybersecurity protection for the model and its physical infrastructure — Article 55(1)(d).

Main exceptions and limits

SituationTreatment under the EU AI Act
GPAI model released under a free and open-source licence (weights, architecture and training info publicly available)Article 53(2) exempts such providers from the standard GPAI obligations — unless the model is classified as systemic risk, in which case Article 55 still applies in full
GPAI model with systemic riskAll of Article 53 plus all of Article 55 — the open-source carve-out does not apply
Models used only in scientific research and development before market placementCarved out by Article 2(6) (R&D) and Article 2(8) (pre-market testing)
Natural persons using a GPAI model for purely personal, non-professional activityNot treated as providers; the obligations fall on whoever placed the model on the market
National-security, defence and military usesExcluded from the Act entirely — Article 2(3)
Models already on the market before2 August 2025 with no significant changeTransitional; GPAI rules apply from 2 August 2025 onwards (Article 113)

When the GPAI rules start to apply (Article 113)

  • 2 August 2025 — Article 53 (standard GPAI obligations) and Article 55 (systemic-risk obligations) become applicable.
  • 2 August 2026 — Article 55 obligation on downstream providers who substantially modify a GPAI becomes applicable (per Article 113 as adopted; the downstream-providers' own provider-status obligation runs from 2 August 2027 in some scenarios — see Article 113 aa).

Who enforces the GPAI rules

The AI Office within the European Commission is the lead authority for GPAI models, supported by a board of national representatives — Article 68 and Article 88. National competent authorities can act on their territory — Article 70. Penalties for non-compliance with GPAI obligations are set by Article 101 (up to €15 million or 3% of global annual turnover for GPAI providers, whichever is higher).

Practical takeaway for providers and deployers

  • If you place a general-purpose AI model on the EU market — in any form, including via an API — Article 53 obligations apply to you.
  • If your model was trained with more than 10²⁵ FLOPs, expect the full Article 55 systemic-risk regime as well.
  • If you integrate someone else's GPAI model into your product, you remain an AI-system provider/deployer under Chapters II–III, but you do not become a GPAI provider unless you make a substantial modification that keeps the model a GPAI.
  • Open-source releases give relief from the standard GPAI duties but not from the systemic-risk duties.

Sources and citations

  • Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act), CELEX number 32024R1689 — canonical EUR-Lex location: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
    • Article 3(63) — definition of general-purpose AI model
    • Article 2(3), (6), (8) — scope exclusions (national security; R&D; pre-market activities)
    • Article 51 — classification rules for GPAI with systemic risk (10²⁵ FLOPs threshold; Commission designation)
    • Article 52 — procedure for systemic-risk designation
    • Article 53 — obligations of providers of GPAI models (technical documentation, downstream info, copyright policy, training-data summary, cooperation with authorities); Article 53(2) — free/open-source carve-out
    • Article 55 — additional obligations for providers of GPAI models with systemic risk
    • Article 68 / Article 70 / Article 88 — governance (AI Office; national competent authorities)
    • Article 101 — penalties - Article 113 — dates of application
    • Annex XI — technical documentation for GPAI models
    • Annex XII — template for the publicly available training-data summary
  • Directive (EU) 2019/790 (Copyright in the Digital Single Market Directive), Article 4(3) — text-and-data-mining opt-out referenced by Article 53(1)(c) of the AI Act.

Tool note: During this session the live web-search tool returned no results for queries on Regulation (EU) 2024/1689, so the EUR-Lex article anchors could not be fetched directly. The CELEX identifier (32024R1689) and the article numbers above are the official references in the published text of the Act; readers should verify the current consolidated text on EUR-Lex for any binding use.

This article is general information, not legal advice. For a binding assessment of how the EU AI Act applies to a specific model or deployment, consult a qualified EU-law adviser.