The compliance obligations of providers of general-purpose AI (GPAI) models under the European Union’s Artificial Intelligence (AI) Act entered into application Aug. 2, 2025.

The overall aim of the AI Act’s obligations for providers of GPAI models is to ensure that such models are “transparent, in line with EU and national copyright law, and that providers of the most advanced or most impactful GPAI models assess and mitigate the systemic risks presented,” the European Commission stated.

This article provides a recap of providers’ compliance obligations, explores a suite of recently released resources out of the Commission to help providers meet their obligations, including new guidance on how to report “serious incidents” to national authorities, and explains the upcoming enforcement timeline.

Compliance obligations

Applicable as of Aug. 2, 2025, providers of GPAI models must satisfy the following specific obligations under the AI Act:

  • Draw up and maintain technical documentation about the model, including details on the development process, to provide the AI Office upon request.
  • Provide information to downstream AI system providers to help them understand the model’s capabilities and limitations and comply with their own obligations.
  • Implement a policy to comply with EU copyright law and related rights; and
  • Publish a “sufficiently detailed summary” of content used for training GPAI models.

Providers of GPAI models released under a free and open-source license may be exempt from certain obligations under certain conditions. Providers of GPAI models with systemic risk, including open-source models, must meet additional obligations, however.

Such obligations include performing a model evaluation; identifying and mitigating systemic risk; ensuring an adequate level of cybersecurity protections for the model and its physical infrastructure; and documenting and reporting relevant information about serious incidents and possible corrective measures to the AI Office and, as appropriate, national authorities without undue delay.

A suite of resources

The Commission in July released a suite of resources giving additional clarity to providers on their obligations under the AI Act. Collectively, this resources “provide a clear and actionable framework for providers of GPAI models to comply with the AI Act, reducing administrative burden, and fostering innovation while safeguarding fundamental rights and public trust,” the Commission stated.

One such resource is the “Guidelines on the Scope of the Obligations for Providers of GPAI Models,” which clarify key concepts in the AI Act. The guidelines serve as an interpretive framework to help determine whether the model qualifies as a GPAI model, who must comply, and whether any exemptions apply.

The guidelines complement a second resource, the GPAI Code of Practice (CoP). Developed by independent experts in a multi-stakeholder process, the CoP has been formally endorsed by the Commission and AI Board as “an adequate voluntary tool for providers of GPAI models to demonstrate compliance with the AI Act.” AI model providers who voluntarily adhere to the CoP “will reduce their administrative burden” and be provided “more legal certainty than if they proved compliance through other methods,” the Commission explained.

The CoP consists of three chapters addressing the following compliance obligations:

  • Transparency chapter: Includes a user-friendly Model Documentation Form, enabling providers to easily document the information necessary to comply with the AI Act obligation on model providers to ensure sufficient transparency.
  • Copyright chapter: Offers providers practical solutions to meet the AI Act’s obligation to put in place a policy to comply with EU copyright law.
  • Safety and Security chapter: Offers concrete state-of-the-art practices for managing systemic risks (i.e. risks from the most advanced models). Providers should rely on this chapter to comply with the AI Act obligations for providers of GPAI models with systemic risk.

As a third resource, the Commission has made available a “template for the public summary of training content of GPAI models.” The template provides only a “minimal baseline” for the information that should be made publicly available, the Commission noted.

The template lists six types of datasets: publicly available datasets; private non-publicly available datasets obtained from third parties; data crawled and scraped from online sources; user data; synthetic data; and other sources of data that do not fall under these categories.

Providers must further describe what measures they implement before model training to respect rightsholders’ reservation of rights, “including the opt-out protocols and solutions honored by the provider or, as applicable, by third parties from which datasets have been obtained,” the Commission stated in an Explanatory Notice. Providers must also describe any measures taken to avoid or remove illegal content under EU law from the training data.

Serious incident reports

Article 73 of the AI Act requires providers of high-risk AI systems to report “serious incidents” to national authorities, but guidance was lacking on how to do so. To fill this gap and help providers meet these reporting obligations, the Commission on Sept. 26 released draft guidance and an incident report template.

Article 3 of the AI Act defines a serious incident to mean “an incident or malfunctioning of an AI system that directly or indirectly leads to serious harm or death of a person; “serious and irreversible disruption” of a critical infrastructure’s management or operation; the infringement of obligations under EU law intended to protect fundamental rights; and serious harm to property or the environment;

Before this reporting requirement takes effect in August 2026, providers should refer to the draft guidance as a framework, as it suggests definitions on key terms, including what qualifies as a serious incident (indirectly or directly), and offers practical examples. Participation in the public consultation process ends Nov. 7. The Commission is seeking input, in particular, on alignment with overlapping reporting requirements.

Enforcement timeline

In the first year beginning Aug. 2, 2025, the AI Office “will offer to collaborate closely, in particular with providers who adhere to the Code of Practice, to ensure that models can be placed on the EU market without delay,” the Commission explained in an FAQ.

“If providers adhering to the Code do not fully implement all commitments immediately, the AI Office will not consider them to have broken their commitments under the Code,” the Commission continued. “Instead, the AI Office will consider them to act in good faith and will be ready to collaborate to ensure full compliance.”

From Aug. 2, 2026, the Commission will begin fully enforcing the obligations, including through the imposition of fines. Providers of GPAI models could potentially face significant fines, ranging from the greater of €7.5 million or 1.5% of global group annual revenues to €35 million or 7% of global group annual revenue, depending on the nature of the violation, and company size.

Providers of GPAI models that were placed on the market before Aug. 2, 2025, have until Aug. 2, 2027 to come into compliance with the AI Act’s obligations.

Kai Zenner, Head of Office for MEP Axel Voss, has compiled a collection of all official AI Act documents, accessible here. Zenner will be speaking on a panel at ACI’s “AI & RegTech for Financial Services and Insurance Summit,” which will be held on Jan. 22-23, 2026, in New York.

For more information, and to register, please visit: https://www.americanconference.com/ai-regtech/