AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    AI Governance 11 min read

    General Purpose AI (GPAI) under the EU AI Act

    As the EU moves forward with the EU AI Act, GPAI requires dedicated rules and has taken center stage in the EU's approach to AI regulation.

    Jelena Djukanovic
    Jelena Djukanovic| Attorney at Law, Whisperly
    Published: · Last reviewed: · Reviewed by: Tamara Zavisic, AI Governance Specialist
    What is general purpose AI (GPAI) and how is it regulated under the EU AI Act? Understand GPAI obligations, transparency rules and systemic risk tiers.

    Artificial intelligence is evidently no longer just a tool for technical tasks: it is quickly becoming a major part of everyday life, work, and even decision-making processes across organizations. At the center of this transformation is General-Purpose AI (GPAI), a new class of AI systems designed with adaptability in mind.

    Unlike traditional AI, which is trained to perform one specific function, such as scanning invoices or classifying images, GPAI models can tackle a wide range of tasks, from writing legal summaries and drafting emails to generating code, creating images, and even reasoning through complex questions. This remarkable flexibility makes GPAI incredibly powerful and useful across countless sectors, enabling new levels of productivity, creativity, and efficiency. But it also brings significant challenges: as these models can be used in ways their developers never fully anticipated, they are far more difficult to control, monitor, and regulate, raising questions about accountability, transparency, and potential misuse.

    According to the European Commission''s 2025 AI Act Implementation Report, over 100 GPAI models had been notified to the EU AI Office by early 2025, with several designated as posing systemic risk under the Act''s classification criteria (European Commission, 2025).

    As the European Union moves forward with the EU Artificial Intelligence Act, the first major legal framework of its kind, it has become clear that GPAI requires dedicated rules. The original idea behind the EU AI Act was to classify AI systems based on the risks they pose in specific sectors. With the rise of GPAI, which can be used in many ways across different industries, those rules have had to evolve. EU lawmakers now aim to confirm that these powerful systems are developed and used responsibly, with clear rules to support safety, transparency, and fundamental rights.

    What is GPAI?

    TL;DRGeneral-Purpose AI models are AI systems trained on broad data that can perform a wide variety of tasks across different domains, rather than being limited to a single function. Under the EU AI Act, a model qualifies as GPAI if it has at least a billion parameters and can generate or process text, audio, video, or images. Even single-domain models count if they support many distinct uses.

    According to Recital 98 and Recital 99 of the AI Act, GPAI models typically have at least a billion parameters and can generate or process content such as text, audio, video, or images.

    Even if a model is specialized for certain tasks or operates within a single domain, such as text processing, it can still be classified as GPAI if it is capable of supporting a wide variety of uses within that area. For example, a model may generate meeting summaries, draft internal compliance updates, produce blog content, and create client email drafts, all within the scope of text. That breadth of applicability within one modality demonstrates the general-purpose nature of the model.

    Because GPAI encompasses a diverse and rapidly evolving set of models constantly being updated, improved, and adapted for new applications, regulators are still developing more detailed and practical guidance to clearly define which models fall under GPAI and how they should be governed in practice.

    GPAI obligations standard vs systemic risk explained — EU AI Act — Whisperlywhisperly.ai/general-purpose-ai-gpaiGPAI — obligations by August 2025.Standard vs systemic risk GPAI.STANDARD GPAISYSTEMIC RISK GPAITransparency docs+ Adversarial testingCopyright summary+ Incident reportingTechnical overview+ Systemic risk assessmentSystemic risk threshold: 10²⁵ FLOPsGPAI obligations are already enforceable.

    Systemic Risk: Why GPAI Needs Special Rules

    TL;DRThe EU AI Act distinguishes between standard GPAI models and those posing systemic risk. A model qualifies as systemic risk if trained with computing power exceeding 10 to the power of 25 floating-point operations, or if the EU AI Office determines its capabilities could affect society at scale. Systemic risk models face stricter obligations including adversarial testing and incident reporting.

    The EU AI Act initially focused on a risk-based framework, assigning obligations based on the sector and intended use of an AI system. However, GPAI does not fit neatly into that approach: one model can power thousands of different applications, including both low-risk and high-risk, which makes it hard to regulate only at the application level. As these powerful models continue to improve, the risk of serious impacts, such as spreading misinformation or affecting democratic processes, has become more real.

    The AI Act recognizes that general-purpose AI models are not all equal when it comes to their potential societal impact. To address this, it introduces a crucial distinction between GPAI models that pose systemic risk and those that do not.

    A model is classified as having systemic risk if it has high-impact capabilities. This includes:

    • Models trained using immense computing power, specifically those exceeding a threshold of 10 to the power of 25 floating-point operations. Training at this magnitude typically involves massive datasets and powerful infrastructure, enabling the model to develop capabilities that can affect society at scale, such as generating highly realistic content, reasoning across multiple domains, or supporting critical decision-making processes with minimal human oversight.
    • Models designated as systemic risk by the EU AI Office, based on the determination that their capabilities are powerful enough to potentially affect society at scale. The AI Act sets out a list of factors to consider: the model''s size, the quality and volume of its training data, performance benchmarks, input and output modalities, market impact within the EU, and other indicators of overall capabilities and reach. A model may qualify as systemic risk if it has at least 10,000 users in the EU.

    In practice, models in this category are those that could, for example, influence democratic processes by generating targeted disinformation, pose risks to public safety by enabling sophisticated cyber-attacks, or spread illegal or harmful content with little human oversight. By setting these criteria, the AI Act aims to confirm that the most powerful AI models are subject to stricter obligations and oversight, protecting public interests and upholding fundamental rights.

    Recognizing these risks, EU lawmakers introduced dedicated rules for GPAI under the AI Act. These rules require GPAI developers to meet core obligations such as technical documentation, transparency about training data, and prevention of unlawful content generation.

    Key Obligations for all GPAI Providers

    TL;DRAll GPAI providers must maintain technical documentation, share detailed model information with downstream developers, comply with EU copyright rules, and publish a training data summary. These obligations apply from 2 August 2025 for new models. Existing GPAI models have until 2 August 2027 to reach full compliance, giving providers a structured window to prepare. For the full phased schedule, see our EU AI Act timeline.

    Under the EU AI Act, all providers of GPAI models have significant obligations. Four core requirements define the compliance baseline.

    Technical documentation: Providers must keep comprehensive technical documentation up to date, covering every stage of the model''s lifecycle, from training data and methods used, to testing processes and evaluation results. This documentation serves as proof of compliance and must be readily available to the AI Office or national competent authorities upon request.

    Information sharing with downstream developers: Providers are required to share clear, detailed, and regularly updated information with AI system developers who integrate their models into downstream applications. This confirms that these developers understand what the model can and cannot do, supporting responsible and lawful use, while also protecting any confidential business information or trade secrets involved.

    Copyright compliance: Providers must implement thorough copyright compliance policies, using state-of-the-art technologies to identify and respect the rights of creators who have opted out of having their works used for AI training, in line with EU copyright rules under the Digital Single Market Directive. This requirement is crucial for upholding intellectual property rights and avoiding legal disputes over training data use.

    Training data summary: GPAI providers are required to publish a sufficiently detailed summary of the data used to train their models, following the template provided by the AI Office. This promotes transparency and accountability, giving the public and regulators insight into the sources and nature of the data that underpin these AI systems.

    These requirements are part of the AI Act''s phased compliance timeline, which began when the Act entered into force on 1 August 2024. While the prohibitions on unacceptable-risk AI systems took effect from 2 February 2025, the key date for GPAI providers is 2 August 2025, when their specific obligations, along with governance measures, notification duties, confidentiality provisions, and most penalties, become enforceable. Full enforcement of general compliance measures follows from 2 August 2026, with the final phase requiring mandatory compliance for high-risk AI systems and existing GPAI models by 2 August 2027. This timeline gives GPAI providers a clear pathway to prepare for and align with their new responsibilities.

    Additional Duties for Systemic GPAI Models

    TL;DRProviders of GPAI models classified as systemic risk face four additional obligations beyond the baseline: model evaluations including adversarial red-teaming, formal systemic risk assessments covering the model''s full lifecycle, continuous incident monitoring with mandatory reporting to the AI Office, and maintaining high cybersecurity standards for both the model and its infrastructure.

    When a GPAI model is classified as posing systemic risk, providers face significantly extended obligations. The stakes are higher, and so are the compliance requirements.

    Evaluations and adversarial testing: Providers must conduct comprehensive evaluations of their models using standardized and state-of-the-art protocols to confirm that the model operates safely and as intended. This includes carrying out adversarial testing, such as red teaming, to identify vulnerabilities or ways in which the model could be misused or manipulated to produce harmful outputs. These evaluations are essential for understanding the risks that a powerful GPAI model might pose, both intentionally and unintentionally.

    Systemic risk assessment: Providers are required to assess and mitigate systemic risks at the EU level. This includes examining potential dangers not just in isolated use cases but across the model''s entire lifecycle, from its initial development and training methods, to how it is placed on the market, and how it is ultimately used by downstream developers and end-users. The goal is to confirm that any risks threatening public safety, democratic processes, or economic stability are proactively identified and reduced.

    Incident monitoring and reporting: Providers have a duty to monitor their models continuously, tracking real-world performance and documenting any serious incidents, such as failures or unexpected harmful outputs. They must promptly report such incidents, along with any corrective actions taken, to the AI Office and, where appropriate, to competent national authorities. This keeps regulators informed of potential threats and maintains accountability.

    Cybersecurity: Providers of systemic GPAI models must maintain a high level of cybersecurity protection for both the model itself and its supporting infrastructure. This prevents security breaches, unauthorized access, or misuse by malicious actors who could exploit the model''s capabilities to cause widespread harm.

    GPAI Guidelines and Codes of Best Practice

    TL;DRThe EU AI Office published draft GPAI guidelines in April 2025 and the official GPAI Code of Practice on July 10, 2025. The Code covers transparency, copyright, and safety across three chapters. Although voluntary, following the Code gives providers a concrete way to demonstrate compliance with AI Act obligations and avoid fragmented national interpretations.

    a) GPAI Guidelines

    In April 2025, the EU AI Office published draft guidelines to provide clarity on the upcoming obligations for providers of GPAI models under the AI Act. These rules, set to apply to all GPAI models released after August 2, 2025, represent a significant compliance milestone for AI companies operating within the EU. This date forms part of the AI Act''s structured timeline, which gradually introduces obligations to give providers time to adapt, with full compliance for existing GPAI models required by 2 August 2027.

    The guidelines not only outline the core obligations for GPAI providers but also highlight that companies modifying or fine-tuning third-party models may trigger additional compliance duties if their compute usage during modification exceeds certain thresholds. Companies that are not building models from scratch but are adapting existing models must carefully assess whether their modifications result in the creation of a new GPAI model, requiring separate technical documentation, updated training data summaries, and full compliance with the AI Act''s requirements.

    b) Codes of Best Practice

    The General-Purpose AI (GPAI) Code of Practice was officially published on July 10, 2025. Coordinated by the EU AI Office and prepared through a multi-stakeholder process involving independent experts, national regulators, GPAI providers, and industry representatives, the Code provides practical tools to help providers comply with their obligations under the AI Act. Although voluntary, adherence to the Code offers providers a concrete way to demonstrate good-faith compliance, showing that they meet the EU''s standards for safe and trustworthy AI.

    The Code consists of three chapters: Transparency, Copyright, and Safety and Security. The Transparency and Copyright chapters apply to all GPAI providers, offering tools such as a user-friendly Model Documentation Form and practical solutions for implementing copyright compliance policies. The Safety and Security chapter is aimed specifically at providers of systemic risk GPAI models, outlining state-of-the-art practices for managing the increased risks arising from the most advanced models.

    This approach promotes consistency and clarity across the EU, helping to avoid fragmented national interpretations and building trust with users, regulators, and the public. With the Code now adopted, providers have a comprehensive set of tools to align their systems, documentation, and compliance strategies with the new EU framework.

    Non-Compliance with the GPAI Rules

    TL;DRGPAI providers that fail to meet their obligations face fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. The penalty structure mirrors the tiered approach used elsewhere in the AI Act, with smaller enterprises paying the lower of the two amounts. Penalties become enforceable from 2 August 2025.

    Providers that fail to meet their obligations may face fines of up to EUR 15 million or 3% of the company''s total worldwide annual turnover, whichever is higher. For a detailed breakdown of the full penalty structure across all AI Act categories, see the guide to EU AI Act penalties.

    TL;DRThe GPAI-specific rules under the EU AI Act mark a regulatory turning point. Organizations deploying or developing GPAI models should begin compliance preparations now, including building an AI inventory, training teams on AI literacy requirements, and aligning internal governance frameworks with the Act''s phased timeline. Early action reduces remediation costs and positions providers as trusted market participants.

    The introduction of GPAI-specific rules under the EU AI Act marks a turning point in AI governance. Organizations should also consider AI literacy requirements to confirm that teams working with GPAI models understand their obligations. Building a comprehensive AI inventory is a practical first step toward identifying which models fall under GPAI classification and what obligations apply.

    For AI providers, these obligations are not just legal hurdles but an opportunity to build models and services grounded in transparency, security, and ethical use. By embracing the guidelines, codes of best practice, and evolving compliance expectations, companies can position themselves as trusted innovators in an AI-driven market where accountability is no longer optional: it is a business imperative.

    How Whisperly helps with GPAI compliance — EU AI Act obligationswhisperly.aiGPAI rules are live.Whisperly maps your obligations.WITHOUT WHISPERLYWITH WHISPERLYGPAI status unclearClassification doneTransparency docs missingAuto-generatedNo incident processReporting workflow readySystemic risk unknownAssessment triggeredRegulator asksFull evidence pack readyNo unclear status. No missing transparency docs.AI-powered. Human-reviewed.

    Questions & Answers

    What is General-Purpose AI (GPAI)?+

    General-Purpose AI refers to AI models trained on broad data that can perform a wide variety of tasks across different domains, rather than being limited to one specific function. Under the EU AI Act, a model qualifies as GPAI if it has at least a billion parameters and can generate or process text, audio, video, or images. Even models operating within a single modality qualify if they support many distinct uses. For a full overview of the regulatory framework, see the EU AI Act Summary.

    What is the difference between GPAI and GPAI with systemic risk?+

    Standard GPAI models must meet baseline obligations such as technical documentation and copyright compliance. GPAI models with systemic risk face additional duties including adversarial testing, systemic risk assessments, incident monitoring, and heightened cybersecurity requirements. A model is classified as systemic risk if trained with computing power exceeding 10 to the power of 25 floating-point operations, or if the EU AI Office determines its capabilities could affect society at scale. Learn more about the classification of high-risk AI systems.

    When do GPAI obligations take effect?+

    GPAI-specific obligations become enforceable from 2 August 2025. This includes governance measures, notification duties, confidentiality provisions, and most penalties. Full enforcement of general compliance measures follows from 2 August 2026, with existing GPAI models required to reach full compliance by 2 August 2027. The prohibited practices provisions took effect earlier, on 2 February 2025.

    What are the penalties for GPAI non-compliance?+

    Providers that fail to meet their GPAI obligations face fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Smaller enterprises pay the lower of the two amounts. For a complete breakdown of the tiered penalty structure, see the guide to EU AI Act penalties.

    What is the GPAI Code of Practice?+

    The GPAI Code of Practice was officially published on July 10, 2025 by the EU AI Office. It provides practical tools across three chapters: Transparency, Copyright, and Safety and Security. Although voluntary, following the Code gives providers a concrete way to demonstrate compliance with the AI Act. The Code was developed through a multi-stakeholder process involving experts, regulators, and GPAI providers. Organizations should integrate the Code into their broader AI governance framework.

    Do companies that fine-tune third-party models need to comply?+

    Yes, potentially. The EU AI Office guidelines highlight that companies modifying or fine-tuning third-party models may trigger additional compliance duties if their compute usage during modification exceeds certain thresholds. If the modification results in a new GPAI model, the company must provide separate technical documentation, updated training data summaries, and full compliance with the AI Act. Maintaining an up-to-date AI inventory helps organizations track which models require compliance action.

    How does GPAI relate to AI governance?+

    GPAI regulation is a key component of the broader AI governance landscape under the EU AI Act. Organizations deploying GPAI models must integrate compliance into their governance frameworks, including risk management, documentation, transparency, and AI literacy training for teams. The phased timeline gives organizations a structured window to align their internal processes with regulatory expectations.

    What documentation must GPAI providers maintain?+

    GPAI providers must maintain comprehensive technical documentation covering every stage of the model lifecycle: training data and methods, testing processes, evaluation results, and model capabilities. They must also publish a detailed training data summary following the AI Office template. Additionally, providers must share clear information with downstream developers who integrate GPAI models into their applications. For providers of systemic risk models, documentation requirements are even more extensive, including adversarial testing results and incident reports. A structured AI governance platform can help systematize this process.

    Jelena Djukanovic

    Written by

    Jelena Djukanovic

    Attorney at Law, Whisperly

    Reviewed by: Tamara Zavisic, AI Governance Specialist

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.