regulations
GPAI (General-Purpose AI Model)
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
GPAI is the EU AI Act's category for models built to be broadly capable rather than purpose-built for one task — the statutory language covers models trained with large amounts of data using self-supervision at scale that display significant generality and can be integrated into a wide range of downstream applications. In practice, this is the category that covers large foundation models, whether or not any specific product built on top of one ever gets classified as high-risk.
Why GPAI runs on a separate track from the risk tiers
Most of the EU AI Act sorts systems by risk tier based on use case — what a system is used for. GPAI obligations attach instead to the model itself, regardless of downstream use, because a single foundation model can end up powering thousands of different applications across every risk tier at once. Providers of GPAI models face baseline transparency obligations — technical documentation, information for downstream integrators, a copyright policy, and a summary of training data — that became applicable in August 2025, ahead of most of the Act's high-risk provisions.
The extra tier: systemic-risk models
A smaller set of the most capable GPAI models — presumptively those trained using more than 10^25 floating-point operations, or otherwise designated by the European Commission — face additional obligations: model evaluation and adversarial testing, systemic-risk assessment and mitigation, incident reporting, and cybersecurity protections. This tier exists because a small number of frontier-scale models carry risk exposure the baseline transparency rules don't fully address, and it's the EU AI Office — not a national regulator — that supervises and enforces both tiers directly. For the full breakdown of exactly which obligations apply to whom — including what the open-source exemption does and doesn't waive — see our deep dive on Articles 51 through 56.
For how GPAI obligations fit into the Act's broader structure, see our EU AI Act overview.
Suggested next reading
ai governance
AI Governance
regulations
High-Risk AI System
regulations eu
The EU AI Act
regulations eu