Skip to content
AI ActAigolex Team

AI Act: What obligations apply to developers of General-Purpose AI (GPAI) models?

With the entry into force of the EU AI Act, General-Purpose AI (GPAI) models are subject to specific obligations. The goal is to ensure transparency, accountability, and risk management across the entire AI value chain.

With the entry into force of the European AI Act, General-Purpose AI (GPAI) models - meaning general models like LLMs, multimodal models, or foundation models - are also subject to specific obligations.

The legislator's goal is simple: to ensure transparency, accountability, and risk management for technologies that can be integrated into thousands of different applications.

The main obligations for GPAI providers are defined primarily in Articles 53-56 of the AI Act.

Let's see what this means in practice.

1. Technical documentation of the model

Developers of a GPAI model must create and maintain detailed technical documentation describing the model and its development process.

This documentation must include information such as:

  • Model architecture
  • Number of parameters
  • Input and output modalities
  • Intended purpose and possible uses
  • Training methods
  • Data used for training, validation, and testing
  • Computational resources used
  • Estimated energy consumption

This information must be made available to competent authorities upon request.

The purpose is to allow authorities and actors in the AI supply chain to understand how the model works and how it was built.

2. Information for downstream users

Providers must provide sufficient information so that those integrating the model (for example, companies building AI applications) can use it in compliance with the regulation.

This includes:

  • Technical instructions for integration
  • Limitations of the model
  • Acceptable use policies
  • Information on known risks

In practice, if someone builds an AI product on top of your model, they must have the tools to comply with the AI Act themselves.

3. Copyright compliance policy

One of the most debated obligations concerns training data.

Providers must:

  • Implement a policy to respect European copyright law
  • Identify and respect any opt-outs from rights holders
  • Properly manage protected content used in datasets

This obligation applies even if the model's training took place outside the EU.

4. Transparency on training data

Providers must publish a summary of the content used for training the model.

It is not required to reveal every single dataset or file (to protect trade secrets), but the summary must indicate:

  • Main data sources
  • Categories of datasets
  • Archives or databases used

The goal is to allow interested parties, such as authors or publishers, to understand if their content might have been used in training.

5. Authorized representative in the EU (for non-EU providers)

If the model provider is not based in the European Union, they must appoint an authorized representative in the EU.

This representative:

  • Acts as a point of contact with European authorities
  • Can be responsible for communications and compliance checks

The goal is to prevent companies outside the EU from selling models in the European market without legal accountability.

6. Additional obligations for models with "systemic risk"

Some very powerful models (for example, large foundation models) can be classified as GPAI with systemic risk.

In this case, obligations increase and include:

  • In-depth model evaluations
  • Safety testing and adversarial testing
  • Analysis and mitigation of systemic risks
  • Reporting of serious incidents to authorities
  • Advanced cybersecurity measures

These measures serve to reduce risks that could have large-scale impacts on society or the economy.

7. Adoption of codes of practice

The European AI Office encourages GPAI providers to adhere to codes of practice.

These codes serve to:

  • Standardize compliance practices
  • Define common metrics and procedures
  • More easily demonstrate compliance with the regulation

If a provider follows a recognized standard, they can obtain a presumption of conformity with respect to certain obligations.

Conclusion

Developers of General-Purpose AI models must face a new regulatory responsibility.

In summary, the provider must:

  • Document the model and the development process
  • Provide information to downstream developers
  • Respect copyright in training data
  • Publish a summary of data sources
  • Appoint an EU representative if necessary
  • Manage and mitigate systemic risks (for more powerful models)

The AI Act does not ban the development of foundation models, but it introduces a new rule of the game: transparency and accountability along the entire AI supply chain.

Or, translated into less diplomatic language: you can build the next revolutionary model, but Europe wants to know how you trained it, what it can do, and what risks it brings with it.

Aigolex

AI Act compliance assisted by AI. From your repositories and files to your inventory, with Legis or your assistant: less manual work, less time and lower costs.

( Understand Prove Repeat )

© 2026 Aigolex. All rights reservedBologna, Italy

Aigolex is software, not a law firm: it does not provide legal advice and does not replace a professional's.