EU AI Act
General-purpose AI under the EU AI Act: provider obligations and what downstream users get
Obligations for providers of general-purpose AI (GPAI) models have applied since 2 August 2025, and the Commission can enforce them with fines from 2 August 2026. Models placed on the market before 2 August 2025 must comply by 2 August 2027. If you build products on a GPAI model you are usually a downstream provider or deployer, not a GPAI provider, and your useful right is information.
Who this applies to
- GPAI model providers
- Providers placing a general-purpose AI model on the EU market. Duties apply from 2 Aug 2025; Commission fines from 2 Aug 2026 for models placed after 2 Aug 2025; legacy models by 2 Aug 2027.
- Providers of GPAI models with systemic risk
- Models presumed to have high-impact capabilities where training compute exceeds 10^25 FLOP carry extra duties under Article 55.
- Downstream providers and deployers
- Organisations integrating a GPAI model into an AI system. They receive documentation, and become a GPAI provider only if they make a substantial modification.
What every GPAI provider must do
Chapter V of the AI Act (Articles 51 to 56). Per the Commission's guidelines for GPAI providers, these obligations became applicable on 2 August 2025.
- Technical documentation of the model, including training and testing and evaluation results, kept up to date and available to the AI Office on request (Annex XI).
- Information for downstream providers so they can understand the model's capabilities and limits and meet their own obligations (Annex XII).
- Copyright policy to comply with EU copyright law, including identifying and honouring rights reservations.
- Public summary of training content, using the Commission's template.
Open-source providers get a partial exemption from some documentation duties, but not from the copyright policy or the training-content summary, and never when the model has systemic risk.
Systemic-risk models
A model is presumed to have high-impact capabilities, and therefore systemic risk, when cumulative training compute exceeds 10^25 floating-point operations (Article 51(2)). Providers of these models must additionally:
- Perform model evaluation, including adversarial testing.
- Assess and mitigate systemic risks.
- Report serious incidents to the AI Office.
- Ensure an adequate level of cybersecurity for the model and its physical infrastructure.
A provider can try to rebut the presumption. Built-in safety measures do not by themselves rebut it, according to guidance commentary.
Are you a GPAI provider if you fine-tune a model?
Usually not. The Commission guidelines set an indicative criterion that a model is general-purpose if its training compute is above 10^23 FLOP and it can generate language, images or video. A downstream modifier becomes a provider of the modified model only if the compute used for the modification exceeds one third of the original model's training compute. These thresholds come from a summary of the guidelines on the Modulos guidance page (secondary source) and are indicative, not binding. Ordinary fine-tuning and prompt or retrieval configuration typically stay below them, but take legal advice for a specific case.
The GPAI Code of Practice
The Commission published the General-Purpose AI Code of Practice on 10 July 2025. It is voluntary and has three chapters: Transparency (with a Model Documentation Form), Copyright, and Safety and Security, which applies only to systemic-risk models. The Commission page lists signatories including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, OpenAI, Aleph Alpha and Cohere. xAI signed only the Safety and Security chapter. Signing gives more legal certainty and a lighter way to demonstrate compliance; it does not remove exposure to fines.
Why this matters if you build on models: check which models you approve have a signatory provider, and request their Model Documentation Form or equivalent. Under Article 25(4), providers of high-risk systems and third-party suppliers of components must agree in writing on information and technical access, and GPAI models are not covered by the open-source exemption from that duty.
What the Digital Omnibus changed
The Omnibus did not change the GPAI duty dates or the Article 101 fine dates. It gave the AI Office exclusive supervisory competence over AI systems built on a GPAI model by the same provider, and over AI integrated into very large online platforms and search engines. Which authority supervises a given system depends on who provides the model and the system, so confirm it for your case.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| Know which GPAI models you use and their documentation (Art. 53 information, Annex XII) | Approved-models list in the Trust Profile across a gateway that fronts 50+ LLMs. | Approved-model register with provider documentation links. | Policy, Risk, Traceability |
| Swap or restrict a model if the provider's position changes | Model gateway and policy that allow, deny or reroute by model. | Policy change history and routing records. | Policy, Access |
| Record which model produced which output | Action trace data to model to agent to decision to outcome. | Per-request model identity in the audit log. | Traceability, Auditability |
| Pin and verify local models | Local models are pinned to a fixed revision and checksum-verified on download. | Revision and checksum record. | Security, Evidence |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte is not the GPAI provider of the models it routes to. Training documentation, copyright policy and training-content summaries are the model providers' obligations.
- It does not train frontier models, so Article 55 systemic-risk duties are not what your use of the platform creates.
- It does not verify a provider's Code of Practice status for you. Check the Commission's signatory list.
- It does not decide whether your own fine-tuning makes you a GPAI provider.
Frequently asked questions
When did GPAI obligations start?
On 2 August 2025. The Commission's enforcement powers, including fines, apply from 2 August 2026, and models placed on the market before 2 August 2025 have until 2 August 2027.
What is the fine for GPAI providers?
Under Article 101 the Commission can fine up to 3% of worldwide turnover or EUR 15 million, whichever is higher, for intentional or negligent breaches.
Is the GPAI Code of Practice mandatory?
No. It is a voluntary tool. Providers that do not sign must show compliance by other adequate means, and signing does not remove the risk of fines.
Does fine-tuning a model make me a GPAI provider?
Usually not. Under the Commission guidelines a modifier becomes a provider only above an indicative compute threshold, one third of the original training compute. Check your case.
What should I ask my model provider for?
Their Model Documentation Form or equivalent technical documentation under Annex XII, their copyright policy, and the public training-content summary. If you build a high-risk system, agree information and access terms in writing (Art. 25(4)).
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- European Commission: guidelines for providers of general-purpose AI models
- European Commission: General-Purpose AI Code of Practice
- AI Act Article 53, GPAI provider obligations (AI Act Service Desk)
- AI Act Article 101, fines on GPAI providers (AI Act Service Desk)
- AI Act Article 25, value-chain responsibilities (AI Act Service Desk)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex) (Adopted 8 July 2026, published 24 July 2026, in force 27 July 2026.)
- AI Act Service Desk: implementation timeline (European Commission) (Reflects the Digital Omnibus amendments.)
- Modulos: Commission guidance on GPAI models (Secondary summary, used for the 10^23 FLOP indicative criterion and the one-third modification threshold.)
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.