regulations

GPAI (General-Purpose AI Model)

An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.

Engineers reviewing documentation for a general-purpose AI foundation model
Photo: Jakub Żerdzicki via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

GPAI is the EU AI Act's category for models built to be broadly capable rather than purpose-built for one task — the statutory language covers models trained with large amounts of data using self-supervision at scale that display significant generality and can be integrated into a wide range of downstream applications. In practice, this is the category that covers large foundation models, whether or not any specific product built on top of one ever gets classified as high-risk.

Why GPAI runs on a separate track from the risk tiers

Most of the EU AI Act sorts systems by risk tier based on use case — what a system is used for. GPAI obligations attach instead to the model itself, regardless of downstream use, because a single foundation model can end up powering thousands of different applications across every risk tier at once. Providers of GPAI models face baseline transparency obligations — technical documentation, information for downstream integrators, a copyright policy, and a summary of training data — that became applicable in August 2025, ahead of most of the Act's high-risk provisions.

The extra tier: systemic-risk models

A smaller set of the most capable GPAI models — presumptively those trained using more than 10^25 floating-point operations, or otherwise designated by the European Commission — face additional obligations: model evaluation and adversarial testing, systemic-risk assessment and mitigation, incident reporting, and cybersecurity protections. This tier exists because a small number of frontier-scale models carry risk exposure the baseline transparency rules don't fully address, and it's the EU AI Office — not a national regulator — that supervises and enforces both tiers directly. For the full breakdown of exactly which obligations apply to whom — including what the open-source exemption does and doesn't waive — see our deep dive on Articles 51 through 56.

For how GPAI obligations fit into the Act's broader structure, see our EU AI Act overview.

Executives reviewing an AI governance accountability structure in an office
Photo: Vitaly Gariev via Unsplash

ai governance

AI Governance

The structure of accountability, review, and decision rights a company puts in place to control how it builds, buys, and deploys AI systems.
Governome Editorial Team · 2 min read
Analysts monitoring a high-risk AI system's outputs on screens
Photo: Boitumelo via Unsplash
An AI system subject to heightened legal obligations because of what it's used for — not because of the underlying technology — typically because it materially affects access to employment, credit, healthcare, housing, or legal standing.
Governome Editorial Team · 2 min read
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Engineers and compliance staff reviewing technical documentation for a general-purpose AI model
Photo: selcuk sarikoz via Unsplash
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Governome Editorial Team · 9 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read