What Is a General-Purpose AI Model Under the EU AI Act?

8 min readAbleneo AI transformation team

What Is a General-Purpose AI Model Under the EU AI Act?

Short answer. A general-purpose AI model is an AI model that shows significant generality and can competently perform a wide range of distinct tasks, then be built into many downstream systems. The large language models behind ChatGPT, Claude, and Gemini are the clearest examples. Under the EU AI Act (Regulation (EU) 2024/1689), providers of these models have carried a dedicated set of obligations since 2 August 2025, covering technical documentation, a copyright policy, and a public summary of training data. Models trained with more than 10^25 floating-point operations carry extra duties, because the law presumes they pose systemic risk.

1What This Means in Practice

The EU AI Act splits its rules into two layers. One layer governs AI systems by use case, classifying a credit-scoring or insurance-pricing system as high-risk. The other layer, Chapter V, Articles 51 to 56, governs the general-purpose AI model itself, the underlying engine that can be pointed at many tasks. A general-purpose AI (GPAI) model is defined by capability, not by a single application: it displays significant generality and can be integrated into a variety of downstream systems. The European Commission’s guidance treats a model trained with more than 10^23 floating-point operations that can generate language, image, or video as an indicative case of generality.

The rules sort GPAI models into two tiers. Every GPAI model carries a baseline set of obligations under Article 53. A smaller group, the models trained above the 10^25 floating-point operation threshold, are presumed to pose systemic risk and carry the heavier obligations of Article 55 on top. The point of the model-level rules is to create a documentation chain: the model provider records how the model was built and what it can do, then passes that information to the companies that build products on it.

2Why This Matters for Regulated Industries

For banks and insurers in Slovakia, the Czech Republic, and Austria, the GPAI rules sit upstream of the high-risk obligations they already face. A bank rarely trains a frontier model. It buys access to one and wires it into lending, claims handling, or customer service. The model-level documentation that a provider must publish, capabilities, limitations, and integration guidance, is the raw material a bank needs to meet its own duties on a high-risk system, including the human oversight and transparency requirements that apply to credit scoring and life and health insurance pricing. Roughly 94% of Ableneo’s production projects use large language models, so for most regulated AI programs a GPAI model already sits somewhere in the stack.

The dates make this current, not theoretical. The GPAI obligations have applied since 2 August 2025. They also interlock with DORA, which has applied since 17 January 2025 and treats an external AI model as an ICT third-party service that needs contractual audit rights and an exit plan. A financial entity that runs a generative AI use case now has to satisfy both regimes: the AI Act for how the model is documented and governed, DORA for whether the service stays available and accountable when it fails.

A general-purpose AI model is the underlying engine, models like those behind ChatGPT, Claude, and Gemini, governed by Chapter V, Articles 51 to 56 of the EU AI Act.

3What Obligations Do Providers of GPAI Models Have?

Article 53 sets four baseline obligations for every GPAI model provider. First, maintain up-to-date technical documentation of the model, its training, and its testing, following the template in Annex XI. Second, give downstream providers the information and documentation they need to understand the model’s capabilities and limitations and to meet their own obligations, per Annex XII. Third, put in place a policy to comply with EU copyright law, including the text-and-data-mining rules. Fourth, publish a sufficiently detailed summary of the content used to train the model, using the template issued by the AI Office.

Providers established outside the EU must appoint an authorised representative in the Union. Providers of GPAI models released under a free and open-source licence get a partial exemption from the documentation and downstream-information duties, but the copyright policy and the training-data summary still apply, and the exemption falls away entirely once a model is classified as systemic risk.

4What Is a General-Purpose AI Model With Systemic Risk?

Article 51 classifies a GPAI model as carrying systemic risk when it has high-impact capabilities. The law sets a presumption: a model is presumed to have high-impact capabilities when the cumulative compute used for its training is greater than 10^25 floating-point operations. The Commission can also designate a model as systemic-risk on other grounds, such as its number of users, its scalability, or its access to tools, even below that compute threshold.

Models in this group carry the Article 55 obligations on top of the baseline. They must run model evaluation including adversarial testing, assess and mitigate systemic risks at Union level, report serious incidents and corrective measures to the AI Office without undue delay, and maintain adequate cybersecurity for the model and its physical infrastructure. These duties target the small set of frontier models whose failure or misuse could ripple across the market, not the everyday models a bank integrates into a single workflow.

5Is the GPAI Code of Practice Mandatory?

No. The General-Purpose AI Code of Practice, published in its final version on 10 July 2025, is voluntary. It was drafted by independent experts convened by the AI Office and organised into three chapters: Transparency, Copyright, and Safety and Security. The first two chapters address the baseline Article 53 duties, the third addresses the systemic-risk duties of Article 55.

Signing the Code gives a provider a clear route to show compliance, and the AI Office will treat adherence as a factor when it weighs any penalty. A provider that does not sign is not breaking the law by that fact alone, but it has to demonstrate compliance by other means and explain to the AI Office how its own measures meet the Act. Signing reduces the documentation burden of proving compliance from scratch.

6Does a Bank That Uses ChatGPT Become a GPAI Provider?

Usually not. A bank that calls a model through an API and builds an internal tool on it is a deployer, and if it places that tool on the market as a system, it is a downstream system provider with obligations at the system level, not the GPAI-model level. The GPAI provider obligations of Articles 53 and 55 fall on the company that develops and first supplies the model, such as the lab behind the foundation model. A bank crosses into provider territory only when it trains a GPAI model itself or substantially modifies an existing one, and then only for the part it changes. For most CEE financial institutions, the practical task is to collect the provider’s documentation and use it to satisfy their own high-risk and DORA obligations.

7When Do the Rules Apply, and What Are the Penalties?

The GPAI obligations apply from 2 August 2025 for models placed on the market on or after that date. The AI Office’s enforcement powers, including requests for information and the ability to require corrective measures, begin on 2 August 2026. Models that were already on the market before 2 August 2025 have until 2 August 2027 to come into full compliance. The penalty ceiling for GPAI providers under Article 101 is a fine of up to 3% of worldwide annual turnover or 15 million euro, whichever is higher. A provider that signs the Code of Practice and follows it can expect the AI Office to account for that when it sets any fine.

8The Ableneo Perspective

The compliance question for a bank is rarely the model itself, it is whether the surrounding system is documented, governed, and recoverable. Ableneo builds that structure into delivery for regulated clients across Central Europe, including ČSOB, Erste, and UNIQA, where a model ships with logged decisions, human oversight, and a documentation trail from the first release. About 80% of Ableneo projects reach production, against an industry pattern of pilots that stall before they meet a control, and that rate comes from designing for audit before the first model goes live. Our work on AI transformation treats the GPAI model, the data around it, and the people who use it as one system, because a compliant deployment depends on the structure that surrounds the model.

Key takeaways

Sources

Planning AI in a regulated business? Ableneo takes systems from classification to governed production.

Talk to Ableneo