General-purpose AI model obligations
General-purpose AI (GPAI) model obligations require providers to maintain detailed technical documentation and provide transparency information to downstream developers who integrate the model into AI systems. Providers must also comply with EU copyright law and, if their model is classified as posing a "systemic risk," adhere to stricter evaluation, cybersecurity, and reporting requirements.
What it means
These obligations shift focus from the final application (the AI system) to the underlying engine (the GPAI model). The intent is to ensure that anyone building an application on top of a powerful base model has enough technical information to manage risks effectively and comply with their own safety duties.
In practice, this creates a tiered compliance structure. All GPAI providers must meet baseline transparency and copyright requirements. However, models that exceed specific computational thresholds or are designated by the AI Office as posing "systemic risks" face an additional layer of governance, including mandatory adversarial testing and incident reporting.
How to meet it
- Compile comprehensive technical documentation detailing the model's training process, architecture, and intended purpose for review by the AI Office.
- Create a standardized information package or transparency manual for downstream providers that explains how to properly implement and use the model.
- Establish a formal policy and technical mechanism to respect EU copyright law, specifically regarding the "opt-out" rights of rightsholders for text and data mining.
- Develop a detailed summary of the content used for training the model, ensuring it is sufficiently transparent for regulators.
- For systemic risk models: Implement a continuous model evaluation framework including red-teaming and adversarial testing to identify vulnerabilities.
- For systemic risk models: Deploy enhanced cybersecurity protections for the model's infrastructure to prevent unauthorized access or manipulation.
Evidence an auditor asks for
- The Technical Documentation file containing training data descriptions, hyperparameters, and validation methods.
- Copies of the documentation provided to downstream users/integrators (e.g., technical manuals or API transparency guides).
- A written Copyright Compliance Policy and logs showing how "opt-out" requests from rightsholders are processed.
- The Systemic Risk Assessment report, including results from adversarial testing and mitigation plans for identified risks.
Common pitfalls
- Confusing the role of a GPAI model provider with that of an AI system provider; these have different obligations under the Act.
- Providing generic marketing or API documentation instead of the specific technical transparency required by Chapter V.
- Failing to account for copyright opt-outs in training datasets, assuming "fair use" concepts from other jurisdictions apply within the EU.