GPAI (General-Purpose AI Model)

What is a GPAI model?

GPAI stands for general-purpose AI model, and it is the AI Act's name for a model that can do many different things rather than one specific thing. In everyday terms: the large language models you actually use are GPAI models.

The Act defines it as an AI model, including one trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks. The load-bearing words there are significant generality. A model trained to spot defects on one production line is not a GPAI model. A model that can summarise, translate, write code and answer questions about almost anything is.

The reason this category exists at all is that the rest of the AI Act is organised around use cases. That approach does not work for a model that has no single use case, because the same model ends up in a customer service tool, a recruitment system and a game. So the Act regulates the model separately from the applications built on top of it.

Model, system, and why the distinction matters

The Act separates two things that people run together in conversation, and the difference decides who is responsible for what.

A general-purpose AI model is the model itself. The weights, the thing that was trained.

A general-purpose AI system is a system built on such a model that can serve a variety of purposes, both for direct use and for being built into other AI systems.

The practical consequence is a split in responsibility. The provider of the model carries the GPAI obligations. When you build something on top of that model, you are not suddenly a model provider, but you can become the provider of an AI system, and if your use case sits in Annex III you are then looking at the high-risk obligations. In other words, the model being compliant does not make your application compliant.

GPAI with systemic risk

Within the GPAI category, the Act carves out a heavier tier for models with systemic risk.

Systemic risk is defined as a risk specific to the high-impact capabilities of general-purpose AI models, one that has a significant effect on the EU market because of the model's reach, or because of actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights or society as a whole, and that can propagate at scale across the value chain.

Read that carefully and you can see what the drafters were worried about. Not a model that gives a bad answer, but a model that so many downstream systems depend on that one weakness in it becomes everybody's weakness at the same time.

Providers of models in this tier carry extra duties: managing systemic risk, evaluating the model, reporting serious incidents, and cybersecurity requirements. This tier is aimed at the largest model providers, so it is very unlikely to be you. It is still worth knowing, because it is one of the things you can ask a supplier about.

What this means for you as a customer

Almost every company reading this is a user of GPAI models and not a provider of one. The duties are not yours, and the outputs of those duties are useful to you.

GPAI providers have to prepare and keep technical documentation about the model. They also have to make information available to the companies who build on it, so that those companies understand the model's capabilities and limitations well enough to meet their own obligations. There are also requirements around copyright policy and around publishing a summary of the content used for training.

That last point is the one to remember at procurement time. If a supplier cannot tell you what a model can and cannot do, or cannot point you at documentation, that is not just an inconvenience. It is a gap in the paperwork you will need if your own application turns out to be high-risk.

Enforcement since August 2026

The GPAI obligations themselves have applied since 2 August 2025. What changed on 2 August 2026 is enforcement.

From that date the Commission's enforcement powers over general-purpose AI model providers came into force, along with the full penalty regime. The Commission can request documentation and information, carry out evaluations of a model, require measures including risk mitigation, market restriction, recall or withdrawal, and impose fines. For GPAI providers those fines go up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher.

There is one more date worth knowing. Providers of models that were already on the market before 2 August 2025 have until 2 August 2027 to comply.

A Code of Practice for general-purpose AI exists alongside this, covering transparency, copyright and safety and security. Signing it is voluntary, and it is a way for a provider to show how it meets its obligations.

What to watch out for with GPAI

Do not confuse the tiers. GPAI is about the model. High-risk is about the use. A perfectly ordinary GPAI model used to screen job applicants gives you a high-risk system, and the model's own compliance does not help you there.

Ask for the documentation before you sign. The information a GPAI provider owes to downstream builders is exactly what you need for your own file. Ask for it during procurement, not during an audit.

Self-hosting changes your position. Running an open-weight model yourself is fine, but if you fine-tune or substantially modify a model, ask a lawyer where the line to provider status sits for you. That question has a real answer and it depends on what you did.

A later high-risk deadline is not a general postponement. The delay agreed in 2026 applies to high-risk obligations. The GPAI provisions were not moved, and they have been in force since 2025.

Last Updated: August 25, 2026 Back to Dictionary
Keywords
gpai general-purpose ai model ai act foundation model high-risk ai system systemic risk model card open-weight model llm compliance ai governance