General-purpose AI model (GPAI)
Also known as: GPAI, GPAI model
The EU AI Act's name for a broad model that can handle many different tasks and be built into many other AI products.
Draft - this entry has not been reviewed yet.
Formal
Under Art. 3(63) of the EU AI Act, a model of significant generality that can competently perform a wide range of distinct tasks and be built into many other systems; providers owe documentation, a copyright policy and a training-data summary (Art. 53), and more if the model poses risks to society as a whole (Art. 55).
In plain English
Like a company whose engine ends up in cars, boats and generators - the law asks the engine's maker for proper paperwork so every builder further down the line knows what they are fitting.
In practice
A Danish research centre releases a Danish-language model under an open licence; its project lead checks that this spares it the technical documentation, but it must still publish a summary of the training data and a copyright policy.
Why it matters
One model can sit under thousands of products, so since August 2025 the EU has placed duties directly on its maker instead of leaving every product builder to guess at the model's risks.
Technical deep dive
The AI Act separates the model from the system. A general-purpose AI model (Art. 3(63)) is the trained artefact - typically a large foundation model trained with self-supervision at scale - while a general-purpose AI system (Art. 3(66)) is a product built on such a model that can serve multiple purposes, such as a chat assistant. The model obligations in Chapter V (Arts. 51-55) sit with the provider that places the model on the EU market, and apply regardless of whether any downstream use is high-risk. Models used only for research, development or prototyping before being placed on the market are excluded. The Commission's guidelines of July 2025 add an indicative criterion: training compute above 10^23 FLOP combined with the ability to generate language, text-to-image or text-to-video; a downstream party that fine-tunes a model becomes a provider only if its modification uses more than roughly one third of the original training compute.
Art. 53(1) requires every GPAI provider to (a) keep technical documentation per Annex XI for the AI Office and national authorities, (b) give downstream providers the information in Annex XII so they can understand capabilities and limitations and meet their own duties, (c) implement a policy to comply with EU copyright law, including respecting text-and-data-mining opt-outs under Art. 4(3) of Directive (EU) 2019/790, and (d) publish a sufficiently detailed summary of training content using the AI Office template. Under Art. 53(2), models released under a free and open-source licence with public weights, architecture and usage information are exempt from (a) and (b), but not from (c) and (d), and not at all if they carry systemic risk. Non-EU providers must appoint an authorised representative (Art. 54).
A model has systemic risk if it has high-impact capabilities, presumed under Art. 51(2) when cumulative training compute exceeds 10^25 FLOP, or if the Commission designates it using the Annex XIII criteria. The provider must notify the Commission within two weeks of meeting the threshold (Art. 52) and may argue that the model nonetheless poses no systemic risk. Art. 55 then adds state-of-the-art model evaluation including adversarial testing, assessment and mitigation of systemic risks, tracking and reporting of serious incidents to the AI Office, and adequate cybersecurity for the model and its infrastructure.
The obligations have applied since 2 August 2025; models placed on the market before then have until 2 August 2027 (Art. 111(3)). The Commission's fining powers under Art. 101 - up to 3 % of worldwide turnover or EUR 15 million - apply from 2 August 2026. The General-Purpose AI Code of Practice (July 2025, under Art. 56), with chapters on transparency, copyright and safety and security, is a voluntary way to demonstrate compliance; its Model Documentation Form is the de facto template for Annex XI/XII information, and a model card published alongside it covers part of the downstream transparency duty.
What to learn first
Everything this builds on, foundations first.
- Artificial intelligence (AI)
- →CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →EU AI Act
- →General-purpose AI model (GPAI)
Relationships
- Requires
- EU AI Act
- Don't confuse with
- Foundation model
- Used with
- Model cardOpen-weight model
Sources & further reading
Standards & official texts
Official documentation
- European Commission - General-Purpose AI Code of Practice (2025) · European Commission
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…