EU AI Act Rules for General-Purpose AI: What GPAI Providers Need to Know in 2026
The EU AI Act creates a dedicated compliance framework for EU AI Act general-purpose AI (GPAI) model providers, and it applies to you regardless of whether your model is also classified as high-risk. If your organisation builds, fine-tunes, or releases a GPAI model in the EU market, two sets of obligations apply. The baseline tier is under Article 53. The stricter systemic risk tier, under Article 55, covers the most advanced models.
This article covers both tiers and the systemic risk threshold. It also covers Article 50 watermarking, deepfake labelling, and the practical steps your team needs before enforcement powers activate on 2 August 2026. For the complete guide to the EU AI Act, see the JAGGAER pillar page.
What is a general-purpose AI model under the EU AI Act?
A GPAI model, as defined in Article 3(63), processes large amounts of training data, covers a wide range of tasks, and integrates into downstream systems. The key distinction: the obligation attaches to the model itself (weights, architecture, artefacts), not to the downstream application. Indicative scope threshold: training compute above 1023 FLOPs plus language, image, or video output (EC Guidelines, July 2025). For a broader explanation, see what the EU AI Act is and how it works.
Two categories excluded from Chapter V
Research & Development Models
Models not yet placed on the EU market do not trigger Chapter V obligations.
Obligations trigger at Point of EU market release
- Excluded until market release
Open-Source Models (with caveats)
Article 53(2) reduces (but does not eliminate) obligations for models with publicly available weights, architecture, and usage terms.
⚠ Copyright compliance obligations still apply
⚠ Training data summary obligations still apply
⚠ Exemption falls away entirely if the model later meets the systemic risk threshold
- Partial exemption – see dedicated section below
JAI
JAGGAER’s AI assistant JAI operates across sourcing, contracts, and supplier management
JAI generates model-level documentation, audit logs, and compliance records across Source-to-Pay workflows.
The two-tier GPAI framework
Every GPAI provider faces two sets of obligations. Article 53 covers the baseline; it applies to all providers. Article 55 adds stricter requirements if your model’s training compute crosses 1025 FLOPs (the systemic risk threshold under Art. 51(2)). To understand where your model sits in the broader classification system, see EU AI Act risk categories explained.
Standard GPAI: All Providers (Art. 53)
- Technical documentation per Annex XI
- Downstream deployer information per Annex XII
- Copyright compliance policy (Dir. (EU) 2019/790)
- Public training data summary (AI Office mandatory template)
Systemic Risk: Additional Obligations (Art. 55)
- Model evaluations including adversarial testing
- Systemic risk assessment and mitigation
- Serious incident reporting to the EU AI Office
- Adequate cybersecurity for model weights and infrastructure
Standard GPAI obligations: what all providers must do
As an EU AI Act general-purpose AI provider, you face four baseline obligations under Article 53, effective 2 August 2025.
01
Technical documentation
- Architecture, training data, energy consumption, capabilities/limitations
- Version-specific; retained 10 years (Code of Practice, Ch. 1)
02
Training data transparency
- Sources, pre-processing, and copyright compliance
- Mandatory AI Office template (July 2025). No substitutes.
03
Downstream deployer information
- Enable deployers to meet their own EU AI Act obligations
- 14-day response window; public contact details required
04
EU copyright law compliance
Art. 53(1)(c) & Dir. (EU) 2019/790
- Applies regardless of licence or data source type
- Comply with text and data mining opt-out (Dir. (EU) 2019/790)
JAGGAER
JAGGAER’s contract management module stores, versions, and retrieves supplier and AI-related documentation
JAGGAER CLM tracks contract versions, data-sharing clauses, and third-party AI provider terms.
Systemic risk: what it means and who it applies to
Your model carries EU AI Act systemic risk if its cumulative training compute exceeds 1025 FLOPs. FLOPs (floating-point operations) are the standard measure of AI training scale. Measurement covers the training run only, not inference. Article 51(2) sets this threshold and creates a rebuttable presumption.
Training at this scale costs tens of millions of euros (Epoch AI, 2024, cited by EC). Frontier LLMs and multimodal foundation models are most likely to exceed it (EC GPAI Q&A, 2025). If your model meets or will meet the threshold, Article 52(1) requires you to notify the Commission within two weeks. You may submit benchmark or scaling law evidence to contest the designation. Obligations remain in force during any review.
The Scientific Panel may also designate models below 1025 FLOPs based on reach or capability. Once designated, Article 55 adds four obligations on top of the Article 53 baseline:
Test your model. Report every incident. Lock down the weights. Plus energy disclosure. The four requirements are:
Transparency and watermarking obligations
From 2 August 2026, you must ensure all AI-generated content is machine-detectable as AI-produced (Article 50, Reg. (EU) 2024/1689). These EU AI Act transparency requirements under Article 50 apply to both GPAI providers and deploying organisations. Systems already on the market by 2 August 2026 have a grace period until 2 December 2026.
EU AI Act watermarking provenance requirements
Art. 50 & draft Transparency Code, Dec 2025
- C2PA metadata embedding is the baseline; combine with additional active watermarking
- No single technique meets the robustness standard
- GPAI providers must enable marking at the model or API layer
Deepfake labelling
Art. 50(4) & Art. 3(60)
- AI-generated content resembling real persons, places, or events that could appear authentic
- Label as artificially created; disclose AI origin. Interim: “AI” Common Icon, localised per member state
JAI
JAI generates and flags AI-produced procurement content within the JAGGAER platform
JAI labels and logs every AI-generated sourcing document, RFx output, and contract summary.
The GPAI Code of Practice
Published 10 July 2025, coordinated by the EU AI Office with input from AI developers, civil society organisations, and national authorities. The EC and AI Board confirmed it as an adequate compliance tool, a safe harbour for GPAI obligations. Three chapters: Transparency and Copyright (all providers); Safety and Security (systemic risk models only).
Signatory
Sign the Code
- Presumption of conformity with Arts. 53 & 55
- Reduced admin burden and greater legal certainty
Non-signatory
Demonstrate compliance separately
- Must carry out gap analysis and report to the AI Office
- Higher evidentiary burden; more frequent enforcement scrutiny
Open-source GPAI models: reduced obligations?
If you release your GPAI model under an open-source licence with publicly available weights, architecture, and usage terms, two key obligations fall away. Article 53(2) removes the technical documentation and downstream deployer information requirements. Three hard limits still apply.
1
Does not apply to systemic risk models
A model above 1025 FLOPs carries full Article 55 obligations regardless of licence.
2
Copyright and training data obligations still apply
Art. 53(1)(c) and (d) apply to all GPAI models regardless of licence or data source.
3
Requires genuine openness
Models behind registration walls or access controls are unlikely to qualify.
Practical steps for GPAI providers
Your priority actions before Commission enforcement powers activate on 2 August 2026:
Penalty exposure: See EU AI Act fines for GPAI non-compliance and EU AI Act compliance deadlines for the full 2025–2027 obligation arc.
What changed in 2026: EU AI Act GPAI updates
7 May 2026
Provisional agreement
Digital Omnibus: GPAI obligations unaffected
Annex III high-risk obligations postponed to 2 December 2027. GPAI Chapter V unaffected. Article 50 takes effect 2 August 2026 (grace period to 2 December 2026 for systems already on the market).
H1 2026
Clarified
AI Office gets exclusive GPAI supervisory competence
AI Office has exclusive competence where model and system share the same provider. Carve-outs: law enforcement, border management, judicial authorities, financial institutions. Reg. (EU) 2024/1689 governs until Official Journal publication.
FAQ
Under Article 3(63) of Regulation (EU) 2024/1689, a GPAI model processes large amounts of training data, covers a wide range of tasks, and integrates into downstream systems. The obligation attaches to the model, not the application. Indicative threshold: above 1023 FLOPs plus language, image, or video output (EC Guidelines, 2025).
Yes. Recital 99 cites large language models as a typical GPAI example. EU AI Act foundation models (LLMs and multimodal systems under Article 3(63)) are subject to Chapter V GPAI obligations from 2 August 2025.
EU AI Act systemic risk is the potential for large-scale harm from the most advanced GPAI models. Article 51(2) presumes your model carries it if training compute exceeds 1025 FLOPs. The Commission may also designate models independently via the Scientific Panel.
New models on the EU market: GPAI obligations from 2 August 2025 (Articles 51–56). Enforcement powers activate 2 August 2026. Models already on the market before 2 August 2025 have until 2 August 2027 to comply (Art. 111(3)).
Four things under Article 53: technical documentation (Annex XI) and deployer information (Annex XII). Also: a copyright compliance policy under Directive (EU) 2019/790 and a training data summary using the AI Office mandatory template.
Yes. Article 50 requires all AI-generated content to be machine-detectable as AI-produced from 2 August 2026. The Transparency Code mandates C2PA metadata embedding combined with active marking.
Deployers must label AI-created deepfakes as artificially made and disclose their AI origin (Article 50(4)), regardless of medium. Exceptions cover law enforcement use and evidently artistic works.
Article 51(1)(a) and (2) sets the threshold at 1025 FLOPs, the training compute level above which your GPAI model carries systemic risk. Measurement covers the full training run, not inference. The designation is rebuttable: submit benchmark or scaling law evidence to contest it.
Yes, but only partially. Article 53(2) removes technical documentation and deployer information requirements for open-source models with publicly available weights and usage terms. Copyright compliance and the training data summary still apply.
The EU AI Office published the EU AI Act GPAI Code of Practice on 10 July 2025; the EC and AI Board endorsed it as an adequate compliance tool. Signing creates a presumption of conformity with Articles 53 and 55 from 2 August 2026. Non-signatories must report their compliance approach to the AI Office.
Yes, if their training compute exceeds 1025 FLOPs. Providers of GPT-4, Claude, Gemini, or comparable models must notify the Commission under Article 52(1) and fulfil Article 55 EU AI Act systemic risk obligations.
Next steps
Risk Classification
EU AI Act Risk Categories Explained
Read More
Deadlines
EU AI Act Compliance Deadlines: Key Dates
Read More
Fines & Penalties
EU AI Act Fines for GPAI Non-Compliance
Read More
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



