Chapter V of the AI Act does not govern AI systems. It governs models. Its obligations fall on providers of general-purpose AI models (GPAI) and they have applied since 2 August 2025. They were not postponed.
The Regulation defines the general-purpose AI model (Article 3(63)) separately from the general-purpose AI system (Article 3(66)), which is a system based on such a model. Chapter V covers models only. An organisation can be the provider of the system without being the provider of the model, and the reverse is equally true.
What is a general-purpose AI model?
A model, not a system, and that is the first distinction to hold. Article 3(63) defines it by its significant generality and its ability to perform a wide range of distinct tasks, however it is placed on the market. Models used for research, development or prototyping before being placed on the market are expressly excluded.
“‘general-purpose AI model’ means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market”
Source: Article 3(63)
The text sets no threshold. The Commission’s adopted guidelines propose an indicative one: training compute above 10²³ floating-point operations, together with a generative modality. That criterion is rebuttable in both directions, and it appears nowhere in the Regulation.
That indicative threshold has nothing to do with the systemic-risk threshold, and the two are not even measured on the same quantity. The 10²³ figure is measured on compute directly updating the model’s parameters; the 10²⁵ figure, set by the Regulation itself, on the cumulative compute used for training. Writing “training compute” without saying which is the most common confusion on this subject.
What must a provider of a GPAI model do?
Technical documentation of the model, including its training and testing process and the results of its evaluation, containing at a minimum the information in Annex XI, to be provided on request to the AI Office and national competent authorities.
Information for downstream providers, enabling them “to have a good understanding of the capabilities and limitations of the general-purpose AI model”, containing at a minimum the elements in Annex XII.
A copyright policy, in particular to identify and comply with, “including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790”.
A public training-content summary: “a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office”. Use of that template is itself mandatory.
A provider established outside the Union must in addition appoint an authorised representative by written mandate before placing the model on the market, with documentation kept for ten years (Article 54).
Does an open-source licence exempt you?
From two obligations out of four, and never where there is systemic risk. Article 53(2) sets aside points (a) and (b) — technical documentation and information to downstream providers — for models released under a free and open licence. The copyright policy and the training-content summary remain due.
“The obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks.”
Source: Article 53(2)
Three obligations fall away, and three only: the technical documentation, the information for downstream providers, and (through Article 54, which carries the same exemption) the appointment of an authorised representative. The copyright policy and the training-content summary remain due. And the exemption falls away entirely as soon as the model presents a systemic risk.
The Commission’s adopted guidelines add that the licence must genuinely allow access, use, modification and redistribution, and that monetisation defeats the exemption, including where the model is hosted exclusively by the provider on its own platform and made accessible for payment. Those readings are the Commission’s, and they are not binding.
When does fine-tuning make you a provider?
Only where the modification is significant, and the obligations then attach to your modification rather than to the whole model. This is the question most asked by companies building on an existing model, and it comes in two parts.
The substantive test, set out in the Commission’s adopted guidelines: a downstream modifier becomes the provider of the modified model only where the modification leads to a significant change in the generality, the capabilities or the systemic risk of the model. The Commission also treats fine-tuning as one of the ways a model can be modified.
The numerical marker: where the training compute used for the modification exceeds one third of the compute used to train the original model, the Commission treats that as an indicative criterion for deciding whether the downstream modifier should be regarded as the provider.
It is not an automatic qualification rule. Crossing the one-third mark does not confer provider status; staying below it does not rule it out. And the Commission states a fraction, not a result: it nowhere writes an absolute figure such as 3.3 × 10²⁴.
Where a modifier can neither know nor estimate the training compute of the original model, a fallback applies: one third of 10²⁵ if the original model presents a systemic risk, one third of 10²³ otherwise.
The threshold is a fallback, not a licence. Anyone holding the parameter count and the token volume of the original model can estimate its training compute, and is therefore outside the fallback: the fallback opens only where the value can neither be known nor estimated.
What the modifier-turned-provider owes is limited to the modification: the documentation covers the modification only, and the copyright policy and training-content summary are likewise limited to the data used in the modification.
The Commission adopted its guidelines on the scope of the obligations for general-purpose AI model providers on 19 November 2025, as C(2025) 7719 final, with 141 numbered points. The file it publishes in English is not that text: it is the annex to the July 2025 draft, C(2025) 5045 final, with 144 points. The twenty-three other language versions carry the adopted text.
Two consequences. Point numbers do not carry across languages (they diverge from point 21 onwards) so a cross-reference taken from one version and applied to the other is wrong. And an English-language article quoting “the Commission’s guidelines” from that PDF is quoting a draft. This page therefore reports what the adopted guidelines say without presenting any of it as an English quotation, because no adopted English text exists to quote.
At what threshold does a model carry systemic risk?
Above 10²⁵ cumulative floating-point operations used for training, Article 51(2) presumes high-impact capabilities. It is a presumption, so it can be rebutted, and crossing the threshold triggers a duty to notify the Commission.
“A general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 10²⁵.”
Source: Article 51(2). The exponent is restored here: text extractions of the Regulation often flatten it.
This is a presumption, and it is rebuttable: Article 52(2) lets a provider present, with its notification, “sufficiently substantiated arguments” that the model does not, due to its specific characteristics, present systemic risks despite meeting the threshold. The Commission may also designate a model of its own motion, on the basis of the criteria in Annex XIII.
Notification to the Commission is due “without delay and in any event” within two weeks of the date on which the criterion is met, or on which it becomes known that it will be met (Article 52(1)). It can therefore fall due before training has finished.
Four further obligations then attach, under Article 55: model evaluation “in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing”; assessing and mitigating systemic risks at Union level; keeping track of, documenting and reporting serious incidents to the AI Office without undue delay, together with “possible corrective measures to address them”; and “an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model”.
Does the Code of Practice make you compliant?
No. It is voluntary, and it confers no presumption of conformity. Signing up weighs on the Commission’s assessment of a breach; it replaces compliance with nothing.
The General-Purpose AI Code of Practice, published on 10 July 2025, has three chapters: Transparency, Copyright, and Safety and Security, the last covering models with systemic risk only. The Commission issued its opinion and the AI Board its adequacy assessment, both on 1 August 2025.
It is voluntary. Signatories commit; the code imposes nothing. And it confers no presumption of conformity. Article 53(4) grants that presumption to compliance with European harmonised standards, and Article 55(2) carries the same rule for models with systemic risk, and as at 24 August 2026, the date of our last check, no harmonised standard reference had been published in the Official Journal of the European Union under Regulation (EU) 2024/1689. Providers adhering to no approved code and meeting no harmonised standard “shall demonstrate alternative adequate means of compliance for assessment by the Commission”.
Who enforces the obligations on GPAI models?
Compliance with Chapter V is outside the reach of national market surveillance authorities.
“The Commission shall have exclusive powers to supervise and enforce Chapter V, taking into account the procedural guarantees under Article 94. The Commission shall entrust the implementation of these tasks to the AI Office”
Source: Article 88(1)
Those powers took effect on 2 August 2026, a year after the obligations they enforce. They are rarely described, and they are heavy.
The Commission may request documentation and any necessary information (Article 91). The AI Office may, after consulting the AI Board, evaluate the model itself, but in two cases only: where the information obtained under Article 91 is insufficient, or to investigate systemic risks. The Commission may then request access to the model through APIs or other appropriate technical means, including the source code (Article 92(3)).
Article 93 goes further. The Commission may require the provider to take measures to comply with Articles 53 and 54; to implement mitigation measures where the evaluation has given rise to serious and substantiated concern of a systemic risk at Union level; and to restrict the making available of the model on the market, withdraw it or recall it.
Withdrawal and recall of a model therefore exist in hard law, independently of any voluntary commitment. And where, in the course of the structured dialogue under Article 93(2), a provider of a model with systemic risk commits to mitigation measures, the Commission may by decision make those commitments binding and declare that there are no further grounds for action, a mechanism carried over from competition law, which turns a voluntary step into an enforceable obligation.
What remedy do you have against a model provider?
Almost every company building on someone else’s model is a downstream provider within the meaning of Article 3(68). The Regulation gives them one route against the model provider:
“Downstream providers shall have the right to lodge a complaint alleging an infringement of this Regulation. A complaint shall be duly reasoned and indicate at least:”
Source: Article 89(2)
Three elements are required: the point of contact of the model provider; a description of the relevant facts, the provisions concerned and why an infringement is alleged; and any other information the downstream provider considers relevant.
When do these obligations apply?
Since 2 August 2025 for the Chapter V obligations, with 2 August 2027 for models already on the market before that date. This chapter was not postponed by the omnibus.
| Date | What applies |
|---|---|
| 2 August 2025 | Obligations of general-purpose AI model providers, Chapter V |
| 2 August 2026 | Commission enforcement powers over Chapter V, and Article 101 fines |
| 2 August 2027 | Compliance deadline for models placed on the market before 2 August 2025 |
What this page rests on
Chapter V, Articles 3, 51 to 56 and 88 to 94, and Annexes XI to XIII of Regulation (EU) 2024/1689, in the consolidated version of 27 July 2026, the authentic text remaining the one published in the Official Journal. Quotations from the Regulation are reproduced from the official English text. Positions attributed to the Commission come from its guidelines on the scope of the obligations for general-purpose AI model providers, C(2025) 7719 final of 19 November 2025, the adopted text, which exists in twenty-three language versions but not in English. They are reported here, not quoted, precisely for that reason, and they are not binding.
Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026.
Frequently asked questions
What is a GPAI model?
Article 3(63) defines it as a model that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way it is placed on the market, and that can be integrated into a variety of downstream systems or applications. Models used for research, development or prototyping activities before being placed on the market are excluded.
Did the Digital Omnibus postpone the GPAI obligations?
No. No Chapter V date moved: the obligations of general-purpose AI model providers have applied since 2 August 2025. The Omnibus did rewrite Article 56(6), on the assessment of the adequacy of the codes of practice, but it touched no provider obligation. What took effect later, on 2 August 2026, are the Commission’s enforcement powers over that chapter and its power to impose fines under Article 101, which the third paragraph of Article 113 expressly excepts from the August 2025 date. For the first year the Commission could take no enforcement action, but the obligations themselves were due.
If I fine-tune an open-source model, do I become a provider?
Not automatically. The substantive test in the Commission’s adopted guidelines is whether the modification leads to a significant change in the generality, capabilities or systemic risk of the model. The Commission adds a numerical marker (modification compute above one third of the compute used to train the original model) but calls it an indicative criterion: crossing it does not confer provider status, and staying below it does not rule it out. Those guidelines are not binding. Note also that the English-language file the Commission publishes is the July 2025 draft, not the adopted text.
Is a model released under a free and open-source licence exempt?
Only partly, and this is the most common error. Article 53(2) exempts models released under a free and open-source licence allowing access, use, modification and distribution, and whose parameters (weights, model architecture information and model usage information) are made publicly available, from the technical documentation and downstream information obligations; Article 54 does the same for appointing an authorised representative. The copyright policy and the public training-content summary remain due. And the exemption never applies to a model with systemic risk.
Does signing the Code of Practice make me compliant?
No. The GPAI Code of Practice is voluntary: adhering to it helps demonstrate compliance but confers no presumption. A presumption of conformity comes only from a harmonised standard whose reference is published, or from common specifications adopted under Article 41, and as at 24 August 2026, the date of our last check, no harmonised standard reference had been published in the Official Journal of the European Union under Regulation (EU) 2024/1689. A provider adhering to no code and meeting no standard must demonstrate alternative adequate means of compliance for assessment by the Commission.
This content is a technical and regulatory information resource. It does not constitute legal advice.