General-Purpose AI Models Under The EU AI Act And The Code Of Practice
Providers of large models such as LLMs have had binding EU duties since August 2025. Here is who counts as a provider, when systemic risk applies and what the voluntary Code of Practice adds.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Most of the EU AI Act regulates AI systems according to how they are used. Large language models and other foundation models do not fit that pattern, because a single model can end up in thousands of products. The Act therefore gives general-purpose AI models their own chapter, Chapter V, with duties that fall on the company that provides the model.1
Those duties are binding and have applied since 2 August 2025. The Digital Omnibus on AI, adopted in July 2026, left them essentially unchanged.2 This article explains who is covered, the extra tier for models with systemic risk, and how the voluntary General-Purpose AI Code of Practice fits in. For the risk tiers that apply to AI systems, see The EU AI Act After The Digital Omnibus.
What Counts As A General-Purpose AI Model
The legal test looks at breadth rather than size. A model qualifies when it is general enough to handle many different kinds of task well and can be built into a wide variety of other systems and applications. Large models trained by self-supervision on huge datasets are the obvious examples. A model that is still only being researched, developed or prototyped, and has not been placed on the market, is outside the definition.3
The Act separates the model from the system built on it. A chatbot product is an AI system; the language model inside it is a general-purpose AI model. Any company whose AI system integrates a model is a downstream provider, whether the model is its own or bought in from someone else.3 A company that simply integrates another provider’s model takes on no Chapter V duties for that model, and it is entitled to information from the model provider so it can meet its own obligations for the system. That changes if it modifies the model significantly: the Commission’s guidelines, which are not legally binding but show how it will enforce the rules, treat a significant modifier as the provider of the resulting model.4
Duties For Every Model Provider
Under Article 53, every provider of a general-purpose AI model placed on the EU market must:5
- keep technical documentation of the model, including how it was trained and tested, and give it to the AI Office or national authorities on request;
- give downstream providers enough information and documentation to understand the model’s capabilities and limits;
- put in place a policy to comply with EU copyright law, including respecting rights holders’ opt-outs from text and data mining;
- publish a sufficiently detailed summary of the content used for training.
A narrow exemption covers open-source models. To qualify, the licence must let anyone access, use, modify and distribute the model, and the parameters, including the weights, together with information on the architecture and on model usage, must be public. Such models are exempt from the first two duties, but not from the copyright policy or the training summary. Providers established outside the EU must appoint an authorised representative inside the EU before placing a model on the market, unless the open-source exemption applies. Neither exemption is available for models with systemic risk.5
The Systemic Risk Tier
A small group of the most capable models carry extra obligations. A model is classified as having systemic risk if it has high-impact capabilities, or if the Commission designates it. It is presumed to have high-impact capabilities when the compute used to train it exceeds 10^25 floating point operations.5 Providers must notify the Commission without delay, and within two weeks at most, once a model has high-impact capabilities, including by crossing the compute threshold, or once they know it will. The threshold is a presumption, not a final verdict: a provider may argue that its model does not in fact present systemic risk, and a model below the threshold can still be classified if its capabilities are judged to be high-impact.
Under Article 55, providers of these models must also evaluate the model using state-of-the-art methods, including adversarial testing; assess and mitigate systemic risks at EU level; track and report serious incidents to the AI Office without undue delay; and ensure adequate cybersecurity for the model and its physical infrastructure.5 The attacks these evaluations look for, such as jailbreaks and model theft, are covered in AI Security.
Do you place on the EU market a model that handles many different kinds of task well and can be built into all sorts of other systems?
- Yes:
Did training use more than 10^25 floating point operations, does the model otherwise have high-impact capabilities, or has the Commission designated it?
- Yes:
Systemic Risk Tier. Article 53 and Article 55 duties apply, with no open-source exemption. The Safety and Security chapter of the Code of Practice is relevant.
- No:
Is the model released under a free and open-source licence that allows access, use, modification and distribution, with its weights, architecture and usage information public?
- Yes:
Reduced Duties. You still need a copyright policy and a public training content summary. No authorised representative is required.
- No:
Standard Model Provider. All four Article 53 duties apply. The Transparency and Copyright chapters of the Code are relevant.
- Yes:
- Yes:
- No:
Do you build an AI product on top of another provider’s general-purpose model?
- Yes:
Downstream Provider. No Chapter V duties for an unmodified model, but your system may be high-risk or carry transparency duties, and you can request documentation from the model provider.
- No:
Chapter V Does Not Apply. Check the AI system rules instead.
- Yes:
The General-Purpose AI Code Of Practice
The Commission published the General-Purpose AI Code of Practice on 10 July 2025. It has three chapters: Transparency, Copyright, and Safety and Security. The last applies only to providers of models with systemic risk. The Commission and the AI Board have confirmed it as an adequate voluntary tool for showing compliance.6
Signing is voluntary. As of 7 October 2026, the Commission lists 22 organisations that signed the full code, including OpenAI, Google, Microsoft, Amazon, Mistral AI and Anthropic. xAI signed only the Safety and Security chapter, so it must show compliance on transparency and copyright by other means.6 The Digital Omnibus clarified the code’s legal weight: providers may rely on a code assessed as adequate to demonstrate compliance, but it does not give a presumption of conformity, so it is evidence rather than a safe harbour.7
| Topic | Binding Duty (AI Act) | Code Of Practice Chapter |
|---|---|---|
| Documentation For Authorities And Downstream Providers | Article 53(1)(a) and (b) | Transparency |
| Copyright Policy And Opt-Outs | Article 53(1)(c) | Copyright |
| Evaluation, Adversarial Testing And Risk Mitigation | Article 55(1)(a) and (b), systemic risk only | Safety and Security |
| Serious Incident Reporting | Article 55(1)(c), systemic risk only | Safety and Security |
| Cybersecurity Of Model And Infrastructure | Article 55(1)(d), systemic risk only | Safety and Security |
Dates And Enforcement
The Commission has exclusive powers to supervise and enforce the model rules, and it entrusts that work to the AI Office. The Commission can fine model providers up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher, under Article 101, a power that applies from 2 August 2026.8
- In effect
European Union · European Parliament and Council Binding
Obligations for providers of general-purpose AI models (Chapter V) apply.
- Upcoming
European Union · European Parliament and Council Binding
General-purpose AI models placed on the market before 2 August 2025 must comply with the Chapter V obligations.
Footnotes
-
European Parliament and Council, “Regulation (EU) 2024/1689 (Artificial Intelligence Act)”, Chapter V and Article 113, Official Journal, 12 July 2024. eur-lex.europa.eu ↩
-
European Parliament and Council, “Regulation (EU) 2026/1744 (Digital Omnibus on AI)”, 8 July 2026, Official Journal, 24 July 2026. eur-lex.europa.eu ↩
-
Regulation (EU) 2024/1689, Article 3, points (63), (66) and (68), and Article 53(1)(b). eur-lex.europa.eu ↩ ↩2
-
European Commission, “Guidelines for providers of general-purpose AI models”, page updated 28 April 2026. digital-strategy.ec.europa.eu ↩
-
Regulation (EU) 2024/1689, Articles 51 to 55, including Articles 53(2) and 54(6). eur-lex.europa.eu ↩ ↩2 ↩3 ↩4
-
European Commission, “The General-Purpose AI Code of Practice”, page updated 7 October 2026. digital-strategy.ec.europa.eu ↩ ↩2
-
Regulation (EU) 2026/1744, recital 41. eur-lex.europa.eu ↩
-
Regulation (EU) 2024/1689, Articles 88, 101 and 113. eur-lex.europa.eu ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.