General-Purpose AI & Foundation Models
The risk tiers were written for AI systems with a fixed purpose. Foundation models broke that mould - one model, countless uses - so the Act added a separate regime for general-purpose AI. If you train, fine-tune, or distribute a foundation model, this lesson is your obligation list.
Why GPAI Needed Its Own Rules
The risk tiers classify a system by what it is for. A foundation model has no single purpose - the same large language model can write marketing copy, triage support tickets, or assist a medical workflow. Regulating it by use-case is impossible at the model layer, because the model provider does not control how downstream developers will deploy it. So the Act created a parallel track: obligations that attach to the general-purpose AI model itself, regardless of where it ends up. These rules became applicable in August 2025.
The Baseline: Obligations for All GPAI Providers
Every provider of a general-purpose AI model placed on the EU market must:
- Maintain technical documentation of the model - its training and testing process and evaluation results - available to the AI Office on request.
- Provide information to downstream providers who integrate the model, so they can understand its capabilities and limitations and meet their own obligations.
- Put in place a copyright policy that respects EU copyright law, including honouring the text-and-data-mining rights reservations (opt-outs) that rightsholders have expressed.
- Publish a sufficiently detailed summary of the content used to train the model, following the template provided by the AI Office.
Providers of models released under a genuinely free and open-source licence get a partial exemption from the documentation and downstream-information duties - but not from the copyright policy and training-data summary, and not at all if the model has systemic risk.
The Heavier Track: GPAI with Systemic Risk
A small number of the most capable models are designated as having systemic risk - the kind of model whose failures or misuse could ripple across the economy or society. A model is presumed to have systemic risk when the cumulative compute used to train it crosses a very high threshold (set in the Act at 1025 floating-point operations), and the AI Office can designate others on a case-by-case basis.
Providers of systemic-risk models carry the baseline duties plus:
- Model evaluation, including standardised and adversarial testing (red-teaming) to identify and mitigate systemic risks;
- Systemic-risk assessment and mitigation across the model lifecycle;
- Serious-incident tracking and reporting to the AI Office and relevant authorities;
- Adequate cybersecurity for the model and its physical infrastructure.
Codes of Practice
Because the GPAI rules are new and technical, the Act leans on codes of practice - drawn up with the AI Office and industry - as the practical bridge to compliance until harmonised standards exist. Adhering to an approved code is a way for providers to demonstrate compliance with the GPAI obligations. If you provide a model, following the relevant code of practice is currently the most concrete path to showing you have met your duties.
What to Do If You Touch a Foundation Model
- Determine your role. API caller (downstream)? Fine-tuner (possibly a provider)? Original trainer (provider)?
- If you are a GPAI provider, build the documentation, downstream-information pack, copyright policy, and training-data summary now - these have applied since August 2025.
- Check the systemic-risk threshold. If your training compute approaches the threshold, the heavier track applies and you should engage with the AI Office early.
- If you are downstream, capture the information the model provider supplies - you will need it to classify and document your own end system under the tiers.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX