GPAI Model Obligations
What a general-purpose AI model provider owes regulators under Annex XI versus downstream integrators under Annex XII, where the open-source carve-out stops and why GPAI penalties sit in Article 101, not Article 99.
Key takeaways: GPAI model obligations 5
What a general-purpose AI model provider owes regulators under Annex XI versus downstream integrators under Annex XII, and where the open-source carve-out and GPAI-specific penalties actually sit.
- GPAI rules did not move Chapter V of the AI Act was left completely untouched by the July 2026 Omnibus, so general-purpose AI model obligations read exactly as originally published.
- Two documents, two audiences Annex XI goes to regulators and Annex XII goes to downstream integrators, and Annex XII does not carry the design rationale or training detail that only Annex XI requires.
- Open source is not a blanket exemption The open-source carve-out covers only two of the four Article 53(1) duties, and it disappears entirely once a model carries systemic risk.
- Systemic risk is a moving line, not a fixed number The 10^25 FLOP systemic-risk threshold is a presumption under Article 51(2), not a fixed definition, and a delegated act can move it in either direction.
- Read Article 101, not Article 99, for GPAI provider fines GPAI provider fines sit in Article 101, not the general regime in Article 99, which is the article the July 2026 Omnibus actually amended.
In short: GPAI model obligations still run on the 2024 rulebook. Regulation (EU) 2026/1744 left Chapter V of the EU AI Act untouched, so Article 53 through Article 55 read exactly as published in 2024. Article 53(1) sets four duties for every general-purpose AI model provider, and two annexes split the paperwork by audience: Annex XI goes to regulators, Annex XII goes to the downstream integrators building on the model. The open-source carve-out reaches only two of those four duties and disappears once a model carries systemic risk. Article 101 sets the GPAI-specific fines, while Article 99 covers the general regime, and conflating the two misreads exposure in both directions.
Why GPAI obligations are exactly as originally published
The amendment enumeration skips Chapter V entirely, from Article 43 to Article 50 to Article 56
Regulation (EU) 2026/1744, the Digital Omnibus on AI, carries 43 numbered points in its own Article 1, and none touches Article 51 through Article 55, the five articles making up Chapter V: point (19) rewrites Article 43(3), point (20) rewrites Article 50(7) and point (21) rewrites Article 56(6). Annex XI, Annex XII and Annex XIII, the technical annexes behind Chapter V, are also absent from the amended-annex list.
Nothing about the chapter's applicability date moved either. The Commission's AI Act regulatory framework page, last updated 27 July 2026, still states general-purpose AI model obligations have applied since 2 August 2025. Legacy models follow the same pattern: point (39) rewrites Article 111 paragraph 2 and adds a new paragraph 4, on high-risk systems and content marking, but leaves paragraph 3 untouched. Article 111(3) as published gives providers placed on the market before 2 August 2025 until 2 August 2027 to comply, and that deadline stands.
The obligation chain, step by step
Article 53(1) sets four duties for every provider
Every provider of a general-purpose AI model owes four duties under Article 53(1), regardless of size or systemic risk: keep the Annex XI technical documentation current for regulators, share the Annex XII information with integrating providers while protecting its own intellectual property, maintain a copyright policy honoring rights reservations under Article 4(3) of Directive (EU) 2019/790 and publish a training-content summary on an AI Office template.
A downstream fine-tuner can cross into this duty set rather than staying a deployer. The Commission's Guidelines on the scope of the obligations for providers of general-purpose AI models, C(2025) 7719 final of 19 November 2025, set the operative test for exactly when that happens, addressed in detail below. Our LLM fine-tuning guide covers the adaptation work itself.
Providers cross a second line at Article 55 once systemic risk attaches
Article 55 adds four duties once a model carries systemic risk. Evaluate the model with standardized protocols, including adversarial testing such as red-teaming. Assess and mitigate systemic risks at Union level. Track, document and report serious incidents to the AI Office and, as appropriate, national authorities. Maintain adequate cybersecurity for the model and its infrastructure.
Article 55(2) rewards a code of practice or harmonized standard with a presumption of conformity; a provider following neither must show alternative means for the Commission to assess, so opting out shifts the burden of proof. The voluntary GPAI Code of Practice has three chapters, Transparency, Copyright and Safety and Security; xAI signed only the last, leaving the other two to alternative means.
Deployer duties begin at Article 26, a different chapter altogether
Chapter V never mentions a deployer. Article 26, in Chapter III, attaches duties to whoever puts a system built on the model into use: follow its instructions for use, assign human oversight to competent, trained and supported staff and, where you control input data, keep it relevant and representative. Monitor operation, report risk to the provider and the market surveillance authority and suspend use if a risk emerges even from following instructions. Keep the logs for at least six months, and tell workers before deploying at a workplace. The table below lines up all three.
| Obligation area | Model provider duty | What the integrator receives or must produce | Deployer duty |
|---|---|---|---|
| Technical documentation | Article 53(1)(a), Annex XI | Nothing under Chapter V | Uses the system per instructions |
| Downstream integration file | Article 53(1)(b), Annex XII | Annex XII, not the training detail behind it | Relies on integrator's instructions |
| Copyright and training-content duties | Article 53(1)(c)-(d) | Not supplied automatically, confirm by contract | No direct duty |
| Model evaluation, mitigation and cybersecurity | Article 55(1)(a)-(b) and (d), systemic-risk only | No visibility, negotiate by contract | No direct duty |
| Incident tracking and reporting | Article 55(1)(c) | Not notified automatically | Article 26(5), reports risk found |
| Human oversight of the system | Not addressed in Chapter V | Must design its own oversight | Article 26(2), competent oversight |
When a downstream modifier becomes the provider - the Commission's test
The operative standard, and the compute figure that operationalizes it
Not every fine-tuner or downstream modifier crosses into the provider role, and the Commission's guidelines are explicit about that starting point. Paragraph (58) states plainly that "it is not necessary for every modification of a general-purpose AI model to lead to the downstream modifier being considered the provider of the modified general-purpose AI model." A footnote to that paragraph treats fine-tuning as a subset of the broader category: "The Commission considers 'fine-tuning' to be one way of 'modifying' a general-purpose AI model." The operative test itself sits in paragraph (59): a downstream modifier becomes the provider of the modified model "only if the modification leads to a significant change in the model's generality, capabilities, or systemic risk."
That standard is qualitative, so paragraph (60) supplies an indicative criterion for applying it: the modifier becomes the provider where "the training compute used for the modification is greater than a third of the training compute of the original model (see paragraph 115 for how 'training compute' should be understood in these guidelines)." Paragraph (61) sets a fallback for when the original figure is neither known nor estimable, replacing the threshold "with a third of the threshold for a model being presumed to have high-impact capabilities (i.e. currently 10^25 FLOP, see Article 51(2) AI Act)" if the original model carried systemic risk, or "with a third of the threshold that is part of the indicative criterion for a model to be considered a general-purpose AI model (i.e. currently 10^23 FLOP, see Section 2.1)" if it did not. Both figures rest on how the guidelines themselves define "training compute," a definition set out in the guidelines' own annex and not reproduced here; check it directly before sizing a modification against either threshold.
The asymmetry: systemic risk does not scale back down
What attaches to a modifier who crosses the threshold is narrower than the whole model. Paragraph (65) limits the Article 53(1), points (a) and (b), documentation duties to "information on the modification," and limits the point (c) copyright policy and point (d) training-content summary to "the data used as part of the modification." Article 54 still applies in full, per paragraph (66), without the same scoping down.
Systemic-risk status gets no such scoping, and that asymmetry is the detail worth engineering around. Paragraph (67) states that a downstream actor who modifies a general-purpose AI model with systemic risk into a model for which it becomes the provider produces a model that "is presumed to have high-impact capabilities" and counts as a general-purpose AI model with systemic risk under Article 51(1), point (a). Paragraph (68) draws the consequence out directly: "the provider must notify the Commission in line with Article 52(1) AI Act, providing the information specified in paragraph 31," on top of the full Article 55 regime for systemic-risk providers. A fine-tuner can inherit the chapter's heaviest duty set from a modification that, measured only against the compute criterion in paragraph (60), looks comparatively small.
Annex XI versus Annex XII - two documents, two audiences
Annex XI is the file regulators can demand
The statute titles Annex XI, in its own words, "technical documentation for providers of general-purpose AI models." Section 1 sets the minimum: tasks performed, the systems it can integrate into, use policies, release date and distribution, architecture, parameter count, input and output modality and format and the license. Point 2 goes further, into design rationale, training methodology, data provenance and the compute and energy figures behind training. Little of this reaches an integrator, since the annex targets a regulator's desk, not a customer's team.
Annex XII is the file a downstream integrator actually receives
Annex XII carries a different title: information "for providers of general-purpose AI models to downstream providers that integrate the model into their AI system." It requires at minimum the tasks performed, the systems it integrates into, use policies, release date and distribution, how the model interacts with outside hardware or software, software versions, architecture, parameter count, modality, format and license. It also adds three development elements: technical means for integration, input and output size including context window length and training-data type, provenance and curation.
What Annex XII does not carry, and why that becomes a contract term
Compare the two lists and the gap is specific, not vague. Annex XII drops the design rationale, training methodology and the compute and energy figures Annex XI point 2 requires, and for a systemic-risk model it drops Section 2 outright: no evaluation results, no adversarial-testing detail, no architecture description. Reading only Annex XII, an integrator knows what the model does, not how it was built or what the provider found when it looked for systemic risk. Article 53(1)(b) explains why: the disclosure duty sits alongside the provider's right to protect its own intellectual property, a limit Annex XI does not carry, since a regulator rather than a competitor reads that file.
The open-source carve-out, and where it stops
Only two of the four Article 53(1) duties are covered
A model released under a free and open-source license, with parameters, architecture and usage information all public, gets relief from only two of the four Article 53(1) duties: Annex XI to regulators under point (a) and Annex XII to integrators under point (b). The copyright policy under point (c) and the training-content summary under point (d) sit outside the carve-out. Open weights answer what the model is, not what data trained it or whether training respected a rights holder's reservation, exactly what points (c) and (d) exist to cover.
Systemic risk erases the carve-out entirely
The carve-out does not survive systemic risk. Once a model meets either route covered next, the license stops mattering, and the provider owes the full Article 53 set plus everything Article 55 adds. Article 54 carries a parallel exception: a non-Union provider must appoint an authorized representative who keeps the technical documentation for 10 years and whom regulators may address instead of the provider, but that duty too skips an open-source model with public parameters, unless it has systemic risk. The representative must end its mandate and inform the AI Office if the provider acts against its obligations.
Systemic risk - a presumption, not a fixed line
The compute figure is a presumption, not a definition
Article 51(2) states it precisely: "A general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25." The word "presumed" matters: crossing 10^25 floating point operations triggers it automatically, but the underlying test in paragraph 1, point (a) is high-impact capabilities evaluated on appropriate tools and methodologies. A model under the figure is not ruled safe, only that it has not tripped the shortcut.
A Commission decision is the second route in
Paragraph 1, point (b) supplies a route that does not depend on compute. The Commission can designate a model as carrying systemic risk by its own decision, ex officio or on a scientific-panel alert, where it finds capabilities equivalent to point (a), assessed against the criteria in Annex XIII: parameter count, data set size or quality including token counts, training compute or a cost or time proxy, input and output modalities against state-of-the-art thresholds, benchmark results including autonomy and adaptability, and reach against a presumption at 10,000 registered business users in the Union plus the number of registered end users. None reads as a bright line the way the compute figure does; the Commission weighs them together.
The whole line moves by delegated act
Neither route sits under a fixed threshold. A delegated act can move 10^25 in either direction, so a model comfortably under today's line can land over tomorrow's without one additional training run. Sub-threshold today does not mean sub-threshold for life, and a compliance program treating the figure as a one-time gate will miss the point where it moves.
Penalties - correcting the Article 99 and Article 101 mix-up
Article 101 reaches only providers of general-purpose AI models
Article 101(1) lets the Commission impose "fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher" on providers of general-purpose AI models. That figure gets quoted often as the AI Act's general ceiling. It is not: the article sits inside Chapter XII with the rest of the enforcement provisions, and its title names who it binds. A high-risk system provider, a deployer, an importer or a distributor outside the GPAI chain never faces it.
Article 99 is the general regime, and the Omnibus amended that one instead
The general penalty ceiling for everyone else sits in Article 99, and point (38) of the amending act replaces its paragraph 1, the provision the July 2026 Omnibus actually touched. The two articles have never been interchangeable: a GPAI-specific ceiling is not the general rule, and the general rule does not cover GPAI providers, whose real exposure sits under the higher figure.
Three of the four grounds are about cooperation, not substance
Article 101(1) sets four grounds, and only the first is a substantive breach. Point (a) covers a provider that "infringed the relevant provisions of this Regulation." Point (b) covers one that "failed to comply with a request for a document or for information pursuant to Article 91, or supplied incorrect, incomplete or misleading information." A third, point (c), covers one that "failed to comply with a measure requested under Article 93." Point (d), truncated in the text reviewed here, covers failing to give the Commission access to the model for an Article 92 evaluation. A provider that never triggers point (a) can still face the same ceiling for refusing a document request or blocking an evaluation, cooperation with the AI Office being as much a financial exposure as the underlying rules.
A contract checklist for downstream integrators
Annex XII sets a floor, not a full answer. Everything Chapter V does not require a provider to hand over still has to come from somewhere once an integrator commits engineering time and a customer relationship to a model it cannot control. Some of that gap closes by negotiating with the provider; the rest has to be built, since no contract term replaces engineering work Annex XII never promised.
What to negotiate into the contract
Five terms recur across the gap Annex XII leaves open.
- Notice of model version changes with a stated deprecation window, so an integration does not break on a silent update.
- Access to evaluation results and adversarial-testing findings for a systemic-risk model, since Annex XI Section 2 stops at the regulator's desk.
- Training-data representations tied to the Article 53(1)(c) copyright policy.
- An indemnity for claims from the model's training data or outputs, shifting financial risk toward whichever party chose the training corpus rather than the one that only integrated it.
- A warranty that the Annex XII file stays accurate as the model updates, not only on the day it was handed over.
What no contract term can supply
Some of the gap sits inside the integrator's own build, and naming it in a contract does not move the work anywhere else.
- Human oversight of the resulting system is the integrator's own Article 26 duty.
- Its own Annex IV technical documentation file, if the integrator's system counts as high-risk, has to exist regardless of what Annex XII says, drawing on its own testing.
- Monitoring, incident detection and input data quality at the integrator's own system, since Article 55 reporting and Article 26(4) duties both bind its own build, not the model itself.
Our RAG versus fine-tuning guide covers one recurring fork inside that gap: ground the model's answers in retrieved data you control, or adapt the model itself, a decision Annex XII gives no help making. This checklist reflects engineering and commercial judgment, not a substitute for a lawyer reviewing your contract and model.
How Pharos Production supports GPAI integration and compliance
Our AI integration services practice builds that side. Our AI governance practice maps the contract terms against what Annex XII actually contains, the same split running through the wider EU AI Act compliance work this article sits inside.
Sources: Regulation (EU) 2024/1689 (the EU AI Act), Articles 26, 51, 53, 54, 55, 99, 101 and 111, plus Annexes XI, XII and XIII, via EUR-Lex; Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), Article 1 points (38) and (39), via EUR-Lex, ELI data.europa.eu/eli/reg/2026/1744/oj; the European Commission's AI Act regulatory framework page; the Commission's GPAI Code of Practice page; and the Commission's Guidelines on the scope of the obligations for providers of general-purpose AI models, C(2025) 7719 final of 19 November 2025, observed 28 July 2026. This article is engineering guidance, not legal advice. Confirm every duty against the primary text with qualified counsel before you rely on it.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 7
No matches
Try a different keyword, change the topic or clear filters
-
No, the Digital Omnibus left Chapter V, the general-purpose AI model chapter, completely untouched. Article 1 of the amendment itself enumerates its points directly from Article 43 to Article 50 to Article 56, skipping Articles 51 through 55 and their annexes entirely.
General-purpose AI model obligations read exactly as originally published in Regulation (EU) 2024/1689, at a time when almost everything around them changed.
-
Article 53(1) sets four duties for every general-purpose AI model provider. A provider must keep Annex XI technical documentation current for regulators, share the Annex XII information with downstream integrating providers, maintain a copyright policy honoring rights reservations under Directive (EU) 2019/790, and publish a training-content summary using the AI Office template.
These four duties apply regardless of model size or systemic-risk status, though a systemic-risk model owes additional duties under Article 55.
-
Annex XI is the technical documentation a provider keeps for regulators, while Annex XII is the information a provider shares with downstream integrating providers, and the two carry different content for different audiences. Annex XI goes further into design rationale, training methodology, data provenance and the compute and energy figures behind training, none of which Annex XII requires.
The split exists because Article 53(1)(b) balances what an integrator needs to know against the right of the provider to protect its own intellectual property.
-
A GPAI provider owes a downstream integrator the tasks the model performs, the systems it can integrate into, its use policies, release date, architecture, parameter count, modality, input and output format including context window length, license and training-data provenance, under Annex XII. Annex XII does not include design rationale, training methodology or the compute and energy figures Annex XI requires, and for a systemic-risk model it drops the evaluation and adversarial-testing detail entirely.
Anything in that gap has to be negotiated by contract, since Chapter V does not require the provider to hand it over.
-
No, the open-source carve-out does not survive systemic risk. Even below that line, it only covers two of the four Article 53(1) duties, the Annex XI documentation and the Annex XII disclosure, leaving the copyright policy and the training-content summary duties in place regardless of license.
Once a model meets either systemic-risk route, the license stops mattering and the provider owes the full Article 53 and Article 55 duty set.
-
A model is presumed to carry systemic risk under Article 51(2) once its training used more than 10^25 floating point operations of cumulative computation. A second route exists through Commission designation, either on its own initiative or following a qualified alert from the scientific panel, assessed against the criteria in Annex XIII such as parameter count and reach.
Neither route sits under a fixed threshold, since a delegated act can move the compute figure in either direction.
-
GPAI model providers face fines up to the higher of 3 percent of worldwide annual turnover or EUR 15,000,000, under Article 101, not the general penalty regime in Article 99, which the Omnibus amended instead. Article 101 sets four grounds for that fine, and three of them are cooperation failures rather than substantive breaches: failing to supply requested documents or information, failing to comply with a requested measure, or blocking Commission access to the model for an evaluation.
Only the first ground actually covers infringing the substantive provisions of the regulation, so a provider can face the same ceiling for refusing to cooperate as for breaking a rule.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.