Library
GPAI Model Obligations, Explained
If you did not train and place the model on the market, you are probably a deployer, not a GPAI provider, and Chapter V is not your chapter. Providers have been on the clock since 2 August 2025: transparency, copyright policy, a training-content summary, and extra duties above 10^25 FLOPs.
Last reviewed
MikeFounder & developer
- EU AI Act
- AI governance
- Compliance
On this page
Who this is for
- Operators who buy or call a foundation model (most readers)
- The smaller set who train or substantially modify a general-purpose model and place it on the EU market
- People mixing up “we use ChatGPT” with “we are a GPAI provider”
Read this first: provider versus deployer
Under Regulation (EU) 2024/1689:
- A GPAI model provider (Article 3) develops a general-purpose AI model and places it on the market. Chapter V (Articles 51–56) is written for them.
- A deployer puts an AI system into use under their authority. Most companies using a vendor API, an office Copilot, or an embedded model in a SaaS tool are deployers.
If you only call someone else's model, stop here for Chapter V. Your live duties are more likely Article 50 transparency (from 2 August 2026), GDPR, and, if the use-case sits in Annex III, high-risk duties from 2 December 2027. See the timeline and Annex III.
You become a provider of a system, not of the GPAI model, when you build a product on top of a third-party model and place that product on the market. That is a different role. Fine-tuning can, in some cases, make you a provider of a modified model. That is a facts-and-degree question for counsel. Do not assume a light prompt wrapper has turned you into OpenAI.
The Digital Omnibus (Regulation (EU) 2026/1744) did not defer Chapter V. GPAI duties have applied since 2 August 2025.
What “general-purpose” means
A GPAI model is one trained on a large amount of data, able to perform a wide range of distinct tasks, and that can be integrated into a variety of systems (Article 3). The Commission's GPAI guidelines (published to sit beside the Code of Practice) treat training compute as a practical indicator. Do not confuse that indicative discussion with the systemic-risk threshold below. They are not the same number.
Baseline duties: Article 53 (every GPAI provider)
From 2 August 2025, providers of GPAI models placed on the Union market must, in substance:
- Draw up and keep technical documentation (Annex XI), including training and testing information, and keep it up to date.
- Supply downstream information to people who integrate the model (Annex XII): capabilities, limitations, and what they need to comply.
- Put in place a copyright policy that respects Union copyright law, including the reservation of rights under Article 4(3) of Directive (EU) 2019/790.
- Publish a sufficiently detailed summary of the content used for training, according to a template provided by the AI Office.
Open-source GPAI models released under a free licence that allows access, use and modification get a narrower Article 53 set, unless they pose systemic risk. Systemic-risk models do not get the open-source relief.
Models already on the market before 2 August 2025 have until 2 August 2027 to comply (Article 111). New models comply from placement.
Systemic risk: Article 51 and 55
A GPAI model is classified as having systemic risk if:
- it has high-impact capabilities, presumed where cumulative training compute exceeds 10^25 floating-point operations (FLOPs) (Article 51(2)); or
- the Commission designates it, on its own initiative or after a qualified alert from the scientific panel, having regard to Annex XIII.
The 10^25 presumption is rebuttable. The provider may argue to the Commission that the model does not in fact show high-impact capabilities. Until that argument succeeds, treat the threshold as the working line.
Crossing the threshold triggers Article 52 notification to the Commission, and Article 55 duties on top of Article 53: model evaluation, adversarial testing, tracking and mitigating systemic risk, incident reporting, cybersecurity of the model and its physical infrastructure.
As of 13 August 2026 we have not seen 2026/1744 amend the 10^25 figure. If a delegated act under Article 51(3) moves it, this page will say so.
What deployers should still do
Even when Chapter V is not yours:
- Know which model you are calling, and whether the provider documents copyright and training-data summaries you can rely on.
- Do not send personal data to a model endpoint without a GDPR basis and a transfer story. See international transfers and GDPR and AI.
- Put the vendor on the vendor checklist, including training-on-your-data clauses.
- Classify your system against Annex III. The model's Chapter V status does not answer that question.
Questions
We fine-tune a vendor model on our tickets. Are we a GPAI provider?
Often you are a deployer (or a system provider) using a third-party model. Substantial modification of a GPAI model can create provider duties for the modified model. That depends on how far the fine-tune changes the general-purpose character. Record what you did. A LoRA on a support corpus is not automatically Chapter V.
Does the high-risk delay help GPAI providers?
No. Chapter V applied from 2 August 2025. Regulation (EU) 2026/1744 deferred Annex III high-risk system duties, not model duties.
What is the systemic-risk compute number?
10^25 FLOPs of cumulative training compute, as a rebuttable presumption under Article 51(2) of 2024/1689. The Commission can also designate a model on qualitative grounds.
We only operate in the UK. Does Chapter V catch us?
If you place the model on the Union market, or the output is used in the Union, Article 2 can still reach you. UK establishment alone is not a shield. UK-only deployment with no EU use is a different analysis. It is still not a reason to ignore the ICO or UK ADM rules.
What changed
- 13 August 2026: First publication. Cadence: medium (90–180 days). Next review due 9 January 2027. Off-cycle if the AI Office or a delegated act changes the systemic-risk threshold or the Code of Practice status.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
- EU AI Act: Timeline & Current StatusAs of 13 August 2026, Regulation (EU) 2026/1744 has moved Annex III high-risk duties to 2 December 2027 and Annex I product-safety high-risk duties to 2 August 2028. Article 5 prohibitions, GPAI Chapter V, and Article 50 transparency are not part of that deferral.
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.