← Course outline
Aavistus Training · ai-act · AIA.09

General-purpose AI models

What you'll learn

The GPAI regime: classification and the systemic-risk compute presumption, provider obligations (documentation, copyright policy, training-content summary), and the additional duties for systemic-risk models (evaluation, incident reporting, cybersecurity).

Regulation — cited to the current EU text

What counts as a general-purpose AI model with systemic risk

The EU AI Act introduces a distinct regulatory layer for general-purpose AI (GPAI) models — that is, foundation models capable of serving a wide range of downstream tasks and being integrated into other AI systems. Within that category the regulation singles out a sub-tier carrying heavier obligations: GPAI models with systemic risk.

Classification as a systemic-risk model can happen in two ways. First, the model may have high impact capabilities, assessed using appropriate technical tools and methodologies including indicators and benchmarks 32024R1689 Article 51@2024-06-13. Second, the Commission may designate a model — on its own initiative or following a qualified alert from the scientific panel — as having capabilities or impact equivalent to the first condition, having regard to the criteria in Annex XIII 32024R1689 Article 51@2024-06-13.

To avoid the need for a full capability assessment in every case, the regulation introduces a compute presumption: a GPAI model is presumed to have high impact capabilities when the cumulative computation used for its training, measured in floating-point operations, exceeds 10²⁵ FLOPs 32024R1689 Article 51@2024-06-13. This figure is a rebuttable proxy, not a ceiling on what can be regulated — the Commission shall adopt delegated acts to amend the thresholds listed in paragraphs 1 and 2 and supplement the associated benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art 32024R1689 Article 51@2024-06-13.

Baseline obligations for all GPAI providers

All providers of GPAI models — systemic-risk or otherwise — must fulfil four core obligations.

Technical documentation. Providers must draw up, and keep current, technical documentation of the model covering its training and testing process and the results of its evaluation. At minimum it must contain the information specified in Annex XI. This documentation is provided to the AI Office and national competent authorities on request 32024R1689 Article 53@2024-06-13.

Downstream integration documentation. Providers must draw up, keep up-to-date and make available, to AI system providers who intend to integrate the GPAI model, information and documentation that enables a good understanding of the model's capabilities and limitations and supports compliance with the regulation. The minimum content is set out in Annex XII. Intellectual property rights, confidential business information, and trade secrets remain protected, but that protection cannot eliminate the obligation 32024R1689 Article 53@2024-06-13.

Copyright policy. Providers must put in place a policy to comply with Union law on copyright and related rights. This includes identifying and complying with a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790, including through state-of-the-art technologies 32024R1689 Article 53@2024-06-13.

Training-content summary. Providers must draw up and make publicly available a sufficiently detailed summary of the content used for training, in accordance with a template provided by the AI Office 32024R1689 Article 53@2024-06-13.

Providers of models released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model — where parameters, weights, architecture information, and model-usage information are publicly available — are exempt from the technical documentation and downstream-integration obligations. That exemption does not apply to GPAI models with systemic risk 32024R1689 Article 53@2024-06-13. Until a harmonised standard is published, providers may demonstrate compliance through codes of practice; compliance with a European harmonised standard creates a presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission 32024R1689 Article 53@2024-06-13.

Additional duties for systemic-risk models

Providers whose models clear the systemic-risk threshold carry four further obligations in addition to the obligations listed in Articles 53 and 54 32024R1689 Article 55@2024-06-13.

Model evaluation and adversarial testing. Providers must perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art. This includes conducting and documenting adversarial testing of the model aimed at identifying and mitigating systemic risks 32024R1689 Article 55@2024-06-13.

Systemic risk assessment and mitigation. Providers must assess and mitigate possible systemic risks at Union level — including their sources — that may arise from the development, placing on the market, or use of the model 32024R1689 Article 55@2024-06-13.

Incident reporting. Providers must track, document, and report without undue delay to the AI Office, and where appropriate to national competent authorities, relevant information about serious incidents and possible corrective measures 32024R1689 Article 55@2024-06-13.

Cybersecurity. Providers must ensure an adequate level of cybersecurity protection for the model itself and for its physical infrastructure 32024R1689 Article 55@2024-06-13.

Codes of practice and European harmonised standards play the same compliance-demonstration role here as they do under Article 53; providers who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission 32024R1689 Article 55@2024-06-13.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The items below are labeled illustrative context only and are not sources of regulatory obligation.

Chinese foundation model providers entering the EU market. A July 2026 report noted Chinese technology companies aggressively expanding their international footprint through cloud-based software and foundation models, with integrated-circuit exports nearly doubling in value year-on-year CASE-1. From a regulatory standpoint this is directly relevant to the GPAI regime: any provider placing a GPAI model on the EU market or putting it into service in the EU is subject to the Article 53 obligations regardless of where the provider is established. If such a model crosses the 10²⁵ FLOP training-compute threshold, the Article 55 systemic-risk duties apply as well. The cross-border expansion of large foundation models is precisely the scenario the GPAI chapter was designed to capture.

General-purpose models in electoral contexts. A July 2026 study conducted during Hungarian parliamentary elections found that AI chatbots gave voters inaccurate, inconsistent, and volatile guidance on which parties to support — including recommending parties that were not even standing for election CASE-2. The researchers concluded that the results raise serious concerns about the reliability of general-purpose AI systems in electoral contexts. This illustrates why the regulation requires systemic-risk providers to conduct adversarial testing aimed at identifying failure modes before deployment, and to track and report serious incidents: a high-capability GPAI model diffused broadly into electoral use represents exactly the kind of Union-level systemic impact the Article 55 assessment-and-mitigation duty is intended to address.

Foundation models beyond text: robotics. A July 2026 interview with startup RLWRLD described a dexterity robot foundation model aimed at addressing demographic decline through capable physical automation CASE-3. The case illustrates that the GPAI category is not limited to language models. Any foundation model — regardless of modality or application domain — that meets the definition and the compute threshold falls within the same classification and documentation framework.

Check your understanding

1. At what cumulative training-compute threshold is a GPAI model presumed to have high impact capabilities?

2. A GPAI model is released under a fully open-source licence with parameters, weights, architecture, and usage information all publicly available. Which statement is correct?

3. How must a GPAI provider make available the summary of content used for training?

4. To whom must a systemic-risk GPAI provider report serious incidents without undue delay?

5. Beyond automatic classification based on training compute, how else can a GPAI model be designated as carrying systemic risk?