Do general-purpose AI models have extra EU AI Act rules?
Short answer: Yes. Regulation (EU) 2024/1689 (the "EU AI Act" / "AI-verordening") adds a dedicated layer of rules specifically for general-purpose AI models (GPAI models) on top of the horizontal rules that apply to all AI systems. These extra obligations sit in Chapter V of the Act (Articles 51–56) and target the providers of GPAI models directly, regardless of how the model is later used.
What counts as a GPAI model?
Under Article 3, point (63), a general-purpose AI model is an AI model that:
- demonstrates significant generality,
- is capable of competently performing a wide range of distinct tasks, and
- can be integrated into a variety of downstream systems or applications.
A footnote clarifies that a GPAI model may be released under a free and open-source licence (open weights), or under proprietary terms.
The typical case — obligations for every GPAI provider (Article 53)
Article 53 applies to every provider of a GPAI model placed on the EU market, regardless of whether the model is considered to pose systemic risk. Providers must:
- draw up and keep up to date the technical documentation listed in Annex XI (general description, training process, evaluation, capabilities and limitations) — Article 53(1)(a);
- provide that documentation and information to downstream integrators that intend to use the model in their AI systems, so they can comply with their own AI Act obligations — Article 53(1)(b);
- put in place a copyright-compliance policy, in particular respecting the text-and-data-mining opt-out under Article 4(3) of Directive (EU) 2019/790 — Article 53(1)(c);
- draw up and make publicly available a sufficiently detailed summary of the training content, following the template the AI Office provides — Article 53(1)(d) and Annex XII;
- cooperate with the AI Office and national competent authorities on requests for information and on compliance — Article 53(1)(e)–(f).
Article 55 extends the regime: a downstream provider that substantially modifies a GPAI model so that it remains a GPAI model becomes a provider itself and inherits the Article 53 obligations (the threshold here is large-scale modification; mere fine-tuning into a non-GPAI system does not trigger GPAI-provider status).
The extra layer — GPAI models with systemic risk (Articles 51–52, 55)
A GPAI model is presumed to present systemic risk if the compute used to train it exceeds 10²⁵ floating-point operations (FLOPs) — Article 51(2). The European Commission can also designate other GPAI models as systemic risk under Article 51(3) (procedure in Article 52).
For these models, Article 55 adds four further obligations:
- perform state-of-the-art evaluations and adversarial testing — Article 55(1)(a);
- assess and mitigate possible systemic risks at Union level, including risks from development, placing on the market or use — Article 55(1)(b);
- track and report serious incidents and possible misuse to the AI Office and, where relevant, national authorities — Article 55(1)(c);
- ensure adequate cybersecurity protection for the model and its physical infrastructure — Article 55(1)(d).
Main exceptions and limits
| Situation | Treatment under the EU AI Act |
|---|---|
| GPAI model released under a free and open-source licence (weights, architecture and training info publicly available) | Article 53(2) exempts such providers from the standard GPAI obligations — unless the model is classified as systemic risk, in which case Article 55 still applies in full |
| GPAI model with systemic risk | All of Article 53 plus all of Article 55 — the open-source carve-out does not apply |
| Models used only in scientific research and development before market placement | Carved out by Article 2(6) (R&D) and Article 2(8) (pre-market testing) |
| Natural persons using a GPAI model for purely personal, non-professional activity | Not treated as providers; the obligations fall on whoever placed the model on the market |
| National-security, defence and military uses | Excluded from the Act entirely — Article 2(3) |
| Models already on the market before2 August 2025 with no significant change | Transitional; GPAI rules apply from 2 August 2025 onwards (Article 113) |
When the GPAI rules start to apply (Article 113)
- 2 August 2025 — Article 53 (standard GPAI obligations) and Article 55 (systemic-risk obligations) become applicable.
- 2 August 2026 — Article 55 obligation on downstream providers who substantially modify a GPAI becomes applicable (per Article 113 as adopted; the downstream-providers' own provider-status obligation runs from 2 August 2027 in some scenarios — see Article 113 aa).
Who enforces the GPAI rules
The AI Office within the European Commission is the lead authority for GPAI models, supported by a board of national representatives — Article 68 and Article 88. National competent authorities can act on their territory — Article 70. Penalties for non-compliance with GPAI obligations are set by Article 101 (up to €15 million or 3% of global annual turnover for GPAI providers, whichever is higher).
Practical takeaway for providers and deployers
- If you place a general-purpose AI model on the EU market — in any form, including via an API — Article 53 obligations apply to you.
- If your model was trained with more than 10²⁵ FLOPs, expect the full Article 55 systemic-risk regime as well.
- If you integrate someone else's GPAI model into your product, you remain an AI-system provider/deployer under Chapters II–III, but you do not become a GPAI provider unless you make a substantial modification that keeps the model a GPAI.
- Open-source releases give relief from the standard GPAI duties but not from the systemic-risk duties.
Sources and citations
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act), CELEX number 32024R1689 — canonical EUR-Lex location:
https://eur-lex.europa.eu/eli/reg/2024/1689/oj- Article 3(63) — definition of general-purpose AI model
- Article 2(3), (6), (8) — scope exclusions (national security; R&D; pre-market activities)
- Article 51 — classification rules for GPAI with systemic risk (10²⁵ FLOPs threshold; Commission designation)
- Article 52 — procedure for systemic-risk designation
- Article 53 — obligations of providers of GPAI models (technical documentation, downstream info, copyright policy, training-data summary, cooperation with authorities); Article 53(2) — free/open-source carve-out
- Article 55 — additional obligations for providers of GPAI models with systemic risk
- Article 68 / Article 70 / Article 88 — governance (AI Office; national competent authorities)
- Article 101 — penalties - Article 113 — dates of application
- Annex XI — technical documentation for GPAI models
- Annex XII — template for the publicly available training-data summary
- Directive (EU) 2019/790 (Copyright in the Digital Single Market Directive), Article 4(3) — text-and-data-mining opt-out referenced by Article 53(1)(c) of the AI Act.
Tool note: During this session the live web-search tool returned no results for queries on Regulation (EU) 2024/1689, so the EUR-Lex article anchors could not be fetched directly. The CELEX identifier (32024R1689) and the article numbers above are the official references in the published text of the Act; readers should verify the current consolidated text on EUR-Lex for any binding use.
This article is general information, not legal advice. For a binding assessment of how the EU AI Act applies to a specific model or deployment, consult a qualified EU-law adviser.