European Union
EU AI Act General-Purpose AI Obligations (Articles 51-56), Explained
Chapter V's obligations run with the model, not the use case — and releasing your weights openly waives less of it than most teams assume.
Most of the EU AI Act sorts obligations by what a system is used for. Articles 51 through 56 — Chapter V — don't. They attach to the model itself, regardless of how any downstream company deploys it, which is why a compliance team that's only mapped its products against the Act's risk tiers can still miss an entire obligations track if it trains, fine-tunes into a new model, or redistributes a general-purpose AI model of its own. The obligations became applicable on August 2, 2025, and reach a much wider set of companies than "the handful of frontier labs everyone's heard of."
Why GPAI obligations attach to the model, not the use case
A single foundation model can end up embedded in thousands of downstream products spanning every risk tier the Act defines — a customer-service chatbot here, a high-risk hiring tool there. Making the provider of that underlying general-purpose AI model responsible for use-case-specific compliance on every one of those products would be unworkable, so Chapter V instead puts a fixed set of duties on the provider of the model itself, independent of what anyone downstream builds with it. That's the core distinction to hold onto: everything below applies because of what you trained and released, not because of what any particular customer does with it afterward.
The baseline four: what every GPAI provider owes under Article 53
Article 53 sets four obligations that apply to every provider of a general-purpose AI model, full stop, before any systemic-risk analysis even enters the picture:
- Technical documentation — maintained records of the training and testing process, including evaluation results, made available to the AI Office and national competent authorities on request.
- Downstream integrator information — documentation given to companies building products on top of the model, sufficient for them to understand the model's capabilities and limitations well enough to meet their own obligations under the Act.
- A copyright policy — specifically, one that respects EU copyright law, including honoring the text-and-data-mining opt-outs that rights holders are entitled to register under existing EU copyright rules.
- A public training-data summary — a "sufficiently detailed" public description of the content used to train the model, following a template the AI Office publishes for this purpose.
None of these four require the model to be dangerous, novel, or even particularly large. A mid-size company fine-tuning an open base model into something substantial enough to count as its own general-purpose AI model, and then releasing it, is in scope for the same four duties as a much bigger lab. The Act doesn't draw a bright line between "fine-tuning that creates a new GPAI model" and "fine-tuning that's just downstream use of someone else's" — a company doing substantial enough fine-tuning to place a materially new model on the market should evaluate its own release terms under Article 53 rather than assume the original provider's compliance already covers it.
What the open-source exemption actually waives — and what it never touches
This is the part of Chapter V most often misread. Article 53(2) exempts providers of models released under a genuinely free and open-source license — one that allows access, use, modification, and redistribution, with parameters, weights, and architecture information made publicly available — from two of the four obligations above: technical documentation and downstream integrator information.
It does not touch the other two. The copyright-policy obligation and the public training-data summary apply to an open-source provider exactly as they apply to a closed one — open licensing has nothing to do with whether the training data respected copyright opt-outs or how detailed the public summary of that data needs to be. And the entire exemption evaporates the moment a model is classified as posing systemic risk, discussed next — at that point, open-weight release status stops mattering for Chapter V purposes altogether.
Systemic risk: the 10^25 FLOPs threshold and the two-week notification clock
Article 51 adds a second, more demanding tier for the most capable models. A general-purpose AI model is classified as posing systemic risk if it has "high-impact capabilities," which Article 51 presumes are present once the cumulative computation used to train the model exceeds 10^25 floating-point operations — a figure chosen because training compute is measurable before release and correlates broadly with capability, unlike more subjective capability benchmarks. A model can also be designated this way by the European Commission directly, acting on its own initiative or following a qualified alert from its scientific panel, using the broader criteria set out in Annex XIII, independent of the compute figure.
Once a provider meets — or knows it will meet — the compute threshold, Article 52 requires notifying the Commission within two weeks. A provider can attach substantiated arguments that its specific model, despite crossing the threshold, doesn't actually present systemic risk given its particular characteristics; the Commission can also designate a model on its own if it becomes aware of systemic-risk-level capabilities the provider never notified it about. If the Commission maintains a systemic-risk designation after reassessment, the provider can request another reassessment no earlier than six months later.
The extra obligations for systemic-risk providers under Article 55
Crossing into systemic-risk classification doesn't replace the Article 53 baseline — it adds four more duties on top of it:
- Model evaluation and adversarial testing — standardized evaluation protocols and tools reflecting the state of the art, including documented adversarial testing specifically aimed at identifying and mitigating systemic risks.
- Union-level risk assessment and mitigation — actively assessing and mitigating the systemic risks the model could pose across the EU, not just risks specific to one deployment.
- Serious incident tracking and reporting — keeping track of, documenting, and reporting serious incidents and any corrective measures to the AI Office and relevant national authorities without undue delay.
- Cybersecurity protection — an adequate level of cybersecurity for both the model itself and the physical infrastructure it runs on.
This is the layer that turns Chapter V from a documentation-and-transparency exercise into something closer to an ongoing safety-testing obligation — and it's scoped narrowly on purpose, since only a small number of frontier-scale models are expected to actually cross the compute threshold.
Non-EU providers: the Article 54 authorized representative requirement
A provider established outside the EU has to appoint, by written mandate, an authorized representative established within the Union before placing a general-purpose AI model on the EU market. That representative becomes a point of contact the AI Office and national authorities can address directly on compliance matters, in addition to or instead of the provider itself. The same exemption logic from Article 53 carries over here: a genuinely free and open-source, non-systemic-risk model doesn't require this either — but a systemic-risk model does, regardless of license.
How compliance actually gets demonstrated: the GPAI Code of Practice
Article 56 lets the AI Office facilitate voluntary codes of practice that providers can rely on to demonstrate compliance with Articles 53 and 55 until formal harmonised standards are published. This isn't hypothetical — the European Commission published the actual General-Purpose AI Code of Practice on July 10, 2025, in three chapters covering transparency, copyright, and safety and security. Signing isn't mandatory, but it carries a real benefit: signatories get a presumption of conformity, a lighter compliance posture than demonstrating compliance from scratch during an AI Office inquiry. Most major model providers — including OpenAI, Google, Anthropic, Microsoft, Amazon, and Mistral AI — signed within weeks for exactly that reason. For what each of the Code's three chapters actually commits a signatory to do — and why Meta declined while xAI signed only part of it — see our breakdown of what GPAI Code of Practice signatories actually commit to.
A worked example: classifying a mid-size foundation model
Take a hypothetical company, Aurora Labs, that trains a 30-billion-parameter language model called AuroraLM and releases it under an open license with weights, architecture, and usage information all made public. Because AuroraLM was trained on roughly 4×10^24 FLOPs — under the 10^25 threshold — and the release genuinely meets the open-source criteria, Aurora Labs owes only two of the four Article 53 duties: a copyright policy honoring EU text-and-data-mining opt-outs, and a public training-data summary using the AI Office template. It's exempt from the technical-documentation and downstream-information duties specifically because of the open license.
Now suppose Aurora Labs trains a successor model, AuroraLM-2, and this time cumulative training compute comes in at 1.3×10^25 FLOPs. Two things change at once. First, all four Article 53 duties now apply in full — the open-source exemption is gone the instant the systemic-risk presumption attaches, regardless of licensing choice. Second, Aurora Labs has two weeks from the point it knows the threshold is met to notify the Commission under Article 52, and unless it can substantiate that AuroraLM-2's specific characteristics mean it doesn't actually pose systemic risk, it now also owes the full Article 55 package: adversarial testing, Union-level risk mitigation, incident reporting, and cybersecurity protections for the model and its infrastructure. Most providers in this position sign the GPAI Code of Practice rather than build a bespoke compliance program from zero.
Enforcement timeline and penalties
Chapter V's obligations have been legally applicable since August 2, 2025, but there's a one-year adjustment period before the Commission can actually use its supervision and enforcement powers against GPAI providers — those powers activate on August 2, 2026. For models that were already on the market before the obligations took effect, providers have until August 2, 2027 to bring them into full compliance. Once enforcement powers are live, GPAI-specific breaches under Article 101 carry fines of up to €15 million or 3% of a provider's total worldwide annual turnover, whichever is higher — a lower ceiling than the €35 million or 7% tier reserved for violations of the Article 5 prohibited practices, since Chapter V is a transparency-and-testing regime, not a categorical ban.
The practical takeaway for any team that trains, substantially fine-tunes, or redistributes a foundation model: run the Article 53 baseline checklist regardless of your release strategy, run the compute math against the 10^25 threshold before you assume Article 55 doesn't apply to you, and don't treat an open license as a substitute for the copyright and training-data-summary work — because it never was one. For how this model-level track sits alongside the deployer-facing transparency duties that attach to specific high-risk systems, see our breakdown of Article 13's instructions-for-use requirements.
Frequently asked questions
- Does releasing a model as open source exempt it from all EU AI Act GPAI obligations?
- No. Only two of Article 53's four obligations — technical documentation and information for downstream integrators — are waived for models released under a genuinely free and open-source license with publicly available parameters, weights, and architecture. The copyright-policy and public training-data-summary obligations apply regardless of license, and the whole exemption disappears if the model is classified as posing systemic risk.
- What is the 10^25 FLOPs threshold and what happens if a model crosses it?
- It's the cumulative training-compute figure at which Article 51 presumes a general-purpose AI model has 'high-impact capabilities' and must be classified as posing systemic risk. Crossing it triggers a two-week notification duty to the Commission under Article 52 and, unless the provider successfully argues the specific model doesn't actually pose systemic risk, adds Article 55's extra obligations — model evaluation, adversarial testing, risk mitigation, incident reporting, and cybersecurity protection — on top of the Article 53 baseline.
- Is the GPAI Code of Practice mandatory?
- No, it's voluntary, but signing gives a provider a presumption of conformity with the relevant Chapter V obligations, which is why most major model providers signed on shortly after the European Commission published it in July 2025. A provider can still comply without signing, but then has to demonstrate compliance directly rather than relying on the Code's presumption.
- When can the Commission actually fine a company for a GPAI obligation violation?
- Obligations became legally applicable on August 2, 2025, but the Commission's supervision and enforcement powers over GPAI providers only start on August 2, 2026 — a one-year adjustment period. Providers of models already on the market before August 2, 2025 have until August 2, 2027 to bring them into compliance.
- Does a company that only fine-tunes someone else's foundation model have Article 53 obligations?
- It depends on whether the fine-tuning is substantial enough to make the fine-tuner a provider of a new general-purpose AI model in its own right, rather than simply a downstream deployer building on someone else's model. The Act doesn't set a bright-line technical test for this; a fine-tuner making a materially new model available on the market should assume Article 53 could apply and evaluate its own compute and release terms rather than assume the original provider's compliance covers it.
Sources & references
Suggested next reading
regulations eu
The EU AI Act
regulations
GPAI (General-Purpose AI Model)
regulations eu