General-purpose AI models under the AI Act, what it requires of those who build them and those who integrate them

A general-purpose AI model is a model trained on large amounts of data that can perform a wide range of distinct tasks. It can be integrated into many systems, as happens with large language models. The AI Act, Regulation (EU) 2024/1689, regulates these models in Chapter V, separately from the AI systems that use them. Its obligations have applied since 2 August 2025 to whoever develops them and places them on the market, the model provider. There are four, and they are reinforced if the model has systemic risk, which is presumed when its training exceeded 10²⁵ floating point operations. The Commission can fine providers from 2 August 2026. Most companies do not build models, they integrate them into their products through an API. For them the AI Act does not apply this chapter, but it does apply the rules on AI systems, and it gives them a right to receive information from the model provider.

If you need an AI lawyer in Spain for your business, request a free initial assessment.

Table of contents

What a general-purpose AI model is

The AI Act distinguishes between the model and the system. The model is the trained component, capable of many tasks. The system is the product that uses it for a specific purpose, such as a customer service assistant or a contract reviewer. The same model can sit inside thousands of different systems.

The regulation defines a general-purpose model by its generality and its ability to competently perform a wide range of distinct tasks. Models used only for research, development or prototyping before being placed on the market are excluded. Large-scale language, image or multimodal models are the typical case.

The four obligations of the model provider

Article 53 of Regulation (EU) 2024/1689 imposes four obligations on the model provider.

  • Draw up and keep up to date the model’s technical documentation, covering its training, testing and evaluation results, to provide to the AI Office and the authorities on request
  • Make information and documentation available to providers of systems that integrate the model, so that they understand its capabilities and limitations and can comply with their own obligations
  • Put in place a policy to comply with Union copyright law, including the reservation of rights against text and data mining
  • Publish a sufficiently detailed summary of the content used to train the model, using the AI Office template

Models released under a free and open-source licence, with their weights and architecture publicly available, are exempt from the first two. Not from the last two, and not at all if the model has systemic risk. Providers established outside the Union must appoint an authorised representative established within it.

Models with systemic risk

A model has systemic risk if it has high-impact capabilities or if the Commission designates it on account of an equivalent impact, under Article 51. It is presumed to have those capabilities when the cumulative compute used for its training exceeds 10²⁵ floating point operations. The provider must notify the Commission when the threshold is met or when it becomes known that it will be met.

In addition to the four general obligations, Article 55 requires four more.

  • Evaluate the model with state-of-the-art protocols, including adversarial testing
  • Assess and mitigate systemic risks at Union level
  • Document and report serious incidents to the AI Office without undue delay
  • Ensure an adequate level of cybersecurity for the model and its infrastructure

The code of practice

In July 2025 the Commission published the code of practice for general-purpose models. It came with guidelines on the scope of these obligations and with the template for the training summary. Signing up to the code is voluntary, but it allows compliance with Articles 53 and 55 to be demonstrated until harmonised standards exist. The Digital Omnibus on AI asks the Commission to assess regularly whether the codes cover those obligations and to publish its assessment.

The timeline for general-purpose models

The Omnibus did not move the dates for general-purpose models. The table also includes the deadline for marking synthetic content, which it did add, because it affects many systems built on these models.

DateWhat applies
2 August 2025Obligations in Articles 53 to 55 for models placed on the market from that date
2 August 2026The Commission can fine model providers, under Article 101
2 December 2026Deadline for systems that generate synthetic content and were placed on the market before 2 August 2026 to mark it as artificial
2 August 2027Deadline to bring models placed on the market before 2 August 2025 into line

Fines for model providers reach 3 % of total worldwide turnover or 15 million euros, whichever is higher. They are imposed by the Commission, not by national authorities.

What changes if your company only integrates a model

A company that uses a third party’s model through an API to build its product is not the model provider. It is the provider of an AI system, and its obligations depend on how it uses it. If the product is a high-risk system under Annex III, it carries the full high-risk regime. If it interacts with people or generates content, it carries the transparency obligations in Article 50.

The right to receive information from the provider

Article 53(1)(b) requires the model provider to give the integrating company the information it needs to comply with the regulation. It is advisable to reflect this in the contract with the provider, together with notice of version changes and the allocation of liability if the model fails.

When modifying a model makes you a provider

Fine-tuning a third-party model with your own data may turn a company into the provider of the modified model. The Commission’s July 2025 guidelines set the criteria for deciding this according to the scale of the modification. An API integration with prompts or context documents does not. Large-scale retraining may, and the Article 53 obligations then fall on the modified part.

The AI Office as direct supervisor

The Omnibus, Regulation (EU) 2026/1744, gives the AI Office exclusive competence over certain systems based on a general-purpose model. These are systems where the model and the system belong to the same provider or its group. There are exceptions, such as systems in regulated products or in critical infrastructure. For a company that integrates a third-party model, its system is still supervised by the national authority.

Example: a contract review startup

This case is fictitious. Clausa Legaltech, S.L. is a Barcelona startup that offers businesses a contract reviewer. Its product calls a large US provider’s language model through an API and adds its own instructions and a library of reference clauses.

Clausa is not the model provider, so Articles 53 to 55 do not affect it. It is the provider of a system that is not in Annex III, so it is not high-risk. As its reviewer interacts with users, it must tell them they are dealing with an AI under Article 50, in force since 2 August 2026.

If Clausa decided to retrain the model on thousands of its own contracts, it would have to check against the guidelines whether the modification makes it the provider of the modified model. The transparency obligations are explained in our guide to AI Act Article 50 transparency obligations. The full framework is in our AI Act compliance guide for businesses.

What is a general-purpose AI model under the AI Act?

It is an AI model trained on large amounts of data that displays significant generality. It can competently perform a wide range of distinct tasks and be integrated into many systems. Large language models are the typical example. Models used only for research or prototyping before being placed on the market are excluded.

No. The obligations in Articles 53 to 55 fall on whoever develops the model and places it on the market. A company that integrates it through an API is the provider or deployer of an AI system. It carries that system’s obligations, such as Article 50 transparency, or the high-risk regime if its use is listed in Annex III.

When it has high-impact capabilities or the Commission designates it on account of an equivalent impact. It is presumed to have those capabilities if the cumulative compute used for its training exceeds 10²⁵ floating point operations. Those models must assess and mitigate systemic risks, carry out adversarial testing, report serious incidents and strengthen their cybersecurity.

Only in part. Those released under a free and open-source licence, with publicly available weights and architecture, do not have to draw up technical documentation or provide information to those who integrate them. They must have a copyright policy and publish the training content summary. If the model has systemic risk, there is no exemption.

Up to 3 % of total worldwide annual turnover or 15 million euros, whichever is higher, under Article 101. They are imposed by the Commission, not by national authorities, and it can do so from 2 August 2026 for infringements, failure to cooperate or inaccurate information.

The chapter on general-purpose models directly affects few companies, those that train their own models. But it shapes all those that build products on top of them, because their ability to meet their own obligations depends on the provider’s information. It is worth knowing what role your company plays in each product and reflecting it in your contracts with model providers. At Innovatech we analyse that allocation and the contracts as part of our AI legal advisory service. Write to us and we will give you a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.