European Union - General-Purpose AI Guidelines
European Commission Guidelines on the scope of obligations for providers of General‑Purpose AI models
European Union
RAI-EU-NA-ECGSOXX-2025The European Commission published non‑binding guidelines (July 2025) clarifying the scope and application of provider obligations under the EU Artificial Intelligence Act for General‑Purpose AI (GPAI) models. The Guidelines define GPAI by a compute threshold and capability criteria, explain who qualifies as a provider, set out exemptions for certain open‑source releases, and describe additional obligations for GPAI models posing systemic risks.
Summary
In July 2025 the European Commission published official Guidelines clarifying the scope of obligations that fall on providers of General‑Purpose AI (GPAI) models under the EU Artificial Intelligence Act (the AI Act). The Guidelines are a companion to the Commission’s reception of an independent multi‑stakeholder General‑Purpose AI Code of Practice and are intended to provide legal certainty to actors across the AI value chain ahead of the targeted entry into application of GPAI‑specific provisions on 2 August 2025. The Guidelines interpret and operationalise key AI Act concepts relevant to GPAI: how to determine when an AI model is a ‘general‑purpose AI model’; what constitutes a ‘provider’ of such a model; when a model is considered to be ‘placed on the market’; the obligations that apply to all GPAI providers (Article 53 AI Act) and the enhanced obligations applicable to GPAI providers whose models present systemic risks (Article 55 AI Act); the conditions under which open‑source models may be exempt from specified documentation and information obligations; and the enforcement approach the Commission will follow in the early implementation phase.
Key definitional guidance in the document uses a combined metric of computational resources and functional capability: an AI model is considered general‑purpose if (i) it was trained using compute exceeding 10^23 floating point operations and (ii) it is capable of generating language (text or audio), text‑to‑image or text‑to‑video outputs. The Guidelines align that definition with Article 3(63) of the AI Act and the Code of Practice. Providers are primarily those actors who develop and make available the model (including via APIs, libraries, downloads or physical media) and — critically — actors who materially modify or fine‑tune models in ways that change the model’s capabilities may, in specified circumstances, become providers under the AI Act.
The Guidelines restate the AI Act obligations: maintain and update technical documentation (including training and testing metadata and evaluation results), make available information for downstream integrators so they can comply with their own obligations, adopt a copyright compliance policy, and publish a sufficiently detailed summary of the content used for training according to an AI Office template. For GPAI providers whose models are classified as presenting systemic risks (the small subset of most advanced/impactful models), additional obligations include standardised model evaluation protocols, adversarial testing and documentation, systemic risk assessment and mitigation at Union level, robust cybersecurity protections for models and associated infrastructure, post‑market monitoring and incident reporting to the AI Office and national competent authorities.
The Guidelines explain the open‑source carve‑out: providers of models released under a free and open source licence that makes architecture, weights and usage parameters publicly available may be exempt from some Article 53 documentation and information duties, but this exemption does not apply if the model is classified as having systemic risk. The Commission also sets out the notification and cooperation expectations: providers of models that will be or may be classified as systemic must notify the AI Office without delay; the AI Office will offer cooperative engagement especially with providers that adhere to the voluntary Code of Practice during the first year after entry into application (2 Aug 2025–2 Aug 2026). From 2 August 2026 the Commission’s enforcement powers become fully available, including the power to impose fines and other measures. The AI Act itself prescribes administrative fines specific to GPAI providers (see Article 101), and general AI Act sanctions for prohibited AI practices and other breaches.
Although the Guidelines are not legally binding they represent the Commission’s interpretative guidance that will inform enforcement and operational activity by the AI Office and national competent authorities. The package of Commission materials also includes the Code of Practice, Q&As, the AI Office signatory process and service desk tools to assist providers in meeting requirements. The Guidelines therefore serve as a practical bridge between the text of the AI Act (adopted in 2024) and the technical and procedural steps model providers must take before and after the staged enforcement dates established in the Act.
Full article
Read full text ↗Overview
The European Commission's "Guidelines on the scope of obligations for providers of general‑purpose AI models" (published July 2025) clarify how selected provisions of the Artificial Intelligence Act apply to general‑purpose AI (GPAI). They form part of a package that also includes the independent General‑Purpose AI Code of Practice and Commission Q&As, and are intended to reduce legal uncertainty for developers, cloud providers, downstream integrators and other stakeholders. The Guidelines explain the GPAI definition (a compute threshold of 10^23 floating point operations combined with generative capabilities such as language, text‑to‑image or text‑to‑video), identify who is a ‘provider’ (developers, distributors, and in specific cases, actors who materially modify models), set out the documentation, transparency and copyright policy duties for all GPAI providers, and detail the enhanced model evaluation, systemic risk management and cybersecurity obligations for GPAI models deemed to pose systemic risks. The Commission positions the Guidelines as an interpretative tool to guide enforcement by the European AI Office and national competent authorities, while encouraging voluntary adherence to the General‑Purpose AI Code of Practice as a practical means of demonstrating compliance with Articles 53 and 55 of the AI Act.
Definitions
The Guidelines operationalise central terms from the AI Act. "General‑purpose AI model" is defined by the Commission as a model trained with compute exceeding 10^23 floating point operations and capable of generating language (text or audio), text‑to‑image or text‑to‑video. "Provider" generally refers to the actor that develops and makes the GPAI model available to others (including by API, library, download or physical media), but the Guidelines also describe when an actor that fine‑tunes, modifies or redistributes a model becomes a provider. "Placing on the market" is understood broadly to include making models available in the Union market by any technical means, whether the provider is established in the Union or in a third country.
Governance and Institutional Framework
The Guidelines explain roles and coordination mechanisms among EU institutions and national authorities. The AI Office (European Commission) is the primary EU‑level enforcement and coordination body for GPAI obligations; it will operate alongside the European Artificial Intelligence Board and national competent authorities and market surveillance authorities. The AI Office is empowered by the AI Act to request information, access models (including via APIs or access tools), carry out model evaluations, and, in coordination with Member States, impose measures and sanctions in line with Article 101. The Guidelines also discuss confidentiality protections for documentation and trade secrets and cross‑border cooperation arrangements for supervision and incident responses.
Key Focus Areas
The Guidelines concentrate on four areas: (1) how to identify GPAI models (compute threshold + generative capability); (2) who is a provider and what counts as placing on the market; (3) exemptions and special conditions for open‑source releases (public availability of parameters/weights/architecture can exempt providers from certain obligations under Article 53, but not where systemic risk is present); and (4) the enforcement approach, including the role of voluntary adherence to the General‑Purpose AI Code of Practice in the first year after entry into application. For GPAI models with systemic risk, the Guidelines stress standardised model evaluation, adversarial testing, Union‑level systemic risk assessment and mitigation, cybersecurity expectations, and robust post‑market monitoring and incident reporting to the AI Office and national authorities.
Implementation Framework
The Commission sets out practical and phased expectations. Obligations for GPAI providers (Article 53 AI Act) apply from 2 August 2025; the AI Office will prioritise cooperative engagement during the first year (2 August 2025–2 August 2026) particularly with providers who commit to the Code of Practice; and full enforcement powers (including fines) are in scope from 2 August 2026. Providers established outside the Union must appoint an authorised representative in the Union prior to placing GPAI models on the Union market. Providers can rely on approved Codes of Practice or harmonised European standards to demonstrate compliance; otherwise they must show alternative adequate means of compliance for Commission assessment.
Monitoring and Evaluation
The Guidelines describe the mechanisms for ex‑ante and ex‑post evaluation. The AI Office can request information and access to models, perform evaluations using APIs and technical tools, and use independent experts. For systemic‑risk GPAI models, providers must maintain detailed technical documentation, carry out standardised evaluations including adversarial testing, keep incident logs, and notify serious incidents without undue delay. Market surveillance authorities and national competent authorities cooperate with the AI Office to monitor compliance; confidentiality and protection of trade secrets are guaranteed under the AI Act's Article 78 provisions.
Penalties, Liability, and Appeals
While the Guidelines are interpretative and non‑binding, the AI Act contains clear enforcement mechanisms. Article 101 empowers the Commission to impose fines on GPAI providers of up to 3% of worldwide annual turnover or EUR 15,000,000 (whichever is higher) for specified infringements (intentional or negligent breaches, failures to comply with information requests or access measures, failure to provide access for evaluations). More severe or specific prohibited practices may attract higher fines under other AI Act provisions (for the most serious prohibited practices fines can reach EUR 35,000,000 or 7% of turnover). Providers have procedural safeguards and appeal routes through EU courts; the Guidelines outline expectations of cooperation during investigations and note the Commission's preference for early voluntary compliance where feasible.
Relationship to Other Instruments
The Guidelines connect to multiple EU legal instruments and initiatives: they interpret Articles 53 and 55 of the AI Act, complement the General‑Purpose AI Code of Practice, and work alongside the AI Office's tools (service desk, compliance checker) and forthcoming harmonised standards and implementing acts. They also reference other Union legislation relevant to copyright, trade secrets and data protection; providers must ensure compliance across these regulatory regimes when placing models on the Union market.
International Alignment
The Guidelines acknowledge international cooperation needs and encourage codes of practice and standards that align with global approaches. The AI Office and the AI Board will engage internationally to facilitate interoperability of oversight, share best practices, and avoid fragmentation. The Guidelines also emphasise that extraterritorial application will occur where providers place models on the EU market: non‑EU providers must appoint Union representatives and comply with EU obligations, which creates an international reach intended to protect Union fundamental rights and safety while encouraging global regulatory convergence.
Implementation Timeline
| Event | Date |
|---|---|
| Guidelines publication (Commission library & news) | 2025‑07‑18 |
| General‑Purpose AI Code of Practice published (independent experts) | 2025‑07‑10 |
| Entry into application of GPAI obligations (Chapter III, Section 4 & related) | 2025‑08‑02 |
| Commission cooperative enforcement period (first year; emphasis on Code signatories) | 2025‑08‑02 → 2026‑08‑02 |
| Full Commission enforcement powers (applicable to GPAI enforcement) | 2026‑08‑02 |
| Compliance deadline for GPAI models already on market before 2025‑08‑02 | 2027‑08‑02 |
Sources and References
Requirements for a company
What an organisation has to do under European Union - General-Purpose AI Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
13- Assess if your model meets the General-Purpose AI model definition.Developers of AI models.
- Determine if your role qualifies you as a 'provider' of a GPAI model.Actors developing, modifying, or distributing GPAI models.
- Appoint an authorised representative in the Union.Providers of GPAI models established outside the Union.
- Maintain detailed technical documentation for your GPAI model.Providers of GPAI models.
- Publish model capabilities, limitations, and integration guidance.Providers of GPAI models.
- Establish and implement a policy to comply with EU copyright law.Providers of GPAI models.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
1- Voluntarily adhere to the General-Purpose AI Code of Practice.Providers of GPAI models.
Should not do
0Nothing in this category.
Who must do what
The obligations under European Union - General-Purpose AI Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Developers of AI models. | Assess if your model meets the General-Purpose AI model definition. “"General‑purpose AI model" is defined by the Commission as a model trained with compute exceeding 10^23 floating point operations and capable of generating language, text‑to‑image or text‑to‑video.” | Aug 2, 2025 | — | Critical |
| 2 | Actors developing, modifying, or distributing GPAI models. | Determine if your role qualifies you as a 'provider' of a GPAI model. “"Provider" generally refers to the actor that develops and makes the GPAI model available to others, but the Guidelines also describe when an actor that fine‑tunes, modifies or redistributes a model becomes a provider.” | Aug 2, 2025 | — | Critical |
| 3 | Providers of GPAI models established outside the Union. | Appoint an authorised representative in the Union. “Providers established outside the Union must appoint an authorised representative in the Union prior to placing GPAI models on the Union market.” | Before placing on market | — | Critical |
| 4 | Providers of GPAI models. | Maintain detailed technical documentation for your GPAI model. “set out the documentation, transparency and copyright policy duties for all GPAI providers” | Aug 2, 2025 | — | Critical |
| 5 | Providers of GPAI models. | Publish model capabilities, limitations, and integration guidance. “set out the documentation, transparency and copyright policy duties for all GPAI providers” | Aug 2, 2025 | — | Critical |
| 6 | Providers of GPAI models. | Establish and implement a policy to comply with EU copyright law. “set out the documentation, transparency and copyright policy duties for all GPAI providers” | Aug 2, 2025 | — | Critical |
| 7 | Providers of systemic-risk GPAI models. | Perform standardised model evaluations for systemic-risk GPAI models. “For systemic‑risk GPAI models, the Guidelines stress standardised model evaluation, adversarial testing, Union‑level systemic risk assessment and mitigation, cybersecurity expectations” | Aug 2, 2025 | — | Critical |
| 8 | Providers of systemic-risk GPAI models. | Conduct adversarial testing for systemic-risk GPAI models. “For systemic‑risk GPAI models, the Guidelines stress standardised model evaluation, adversarial testing” | Aug 2, 2025 | — | Critical |
| 9 | Providers of systemic-risk GPAI models. | Implement robust cybersecurity measures for systemic-risk GPAI models. “detail the enhanced model evaluation, systemic risk management and cybersecurity obligations for GPAI models deemed to pose systemic risks.” | Aug 2, 2025 | — | Critical |
| 10 | Providers of systemic-risk GPAI models. | Maintain incident logs for systemic-risk GPAI models. “For systemic‑risk GPAI models, providers must maintain detailed technical documentation, carry out standardised evaluations including adversarial testing, keep incident logs” | Aug 2, 2025 | — | Critical |
| 11 | Providers of systemic-risk GPAI models. | Notify serious incidents to the AI Office and national authorities without undue delay. “For systemic‑risk GPAI models, providers must [...] notify serious incidents without undue delay.” | Aug 2, 2025 | — | Critical |
| 12 | Providers of open-source GPAI models. | Ensure public availability of model parameters, weights, and architecture for open-source exemptions. “public availability of parameters/weights/architecture can exempt providers from certain obligations under Article 53” | Aug 2, 2025 | — | Important |
| 13 | Providers of GPAI models. | Demonstrate compliance using approved Codes of Practice, harmonised standards, or alternative means. “Providers can rely on approved Codes of Practice or harmonised European standards to demonstrate compliance; otherwise they must show alternative adequate means of compliance” | Aug 2, 2025 | — | Important |
| 14 | Providers of GPAI models. | Voluntarily adhere to the General-Purpose AI Code of Practice. “encouraging voluntary adherence to the General‑Purpose AI Code of Practice as a practical means of demonstrating compliance with Articles 53 and 55 of the AI Act.” | — | — | Recommended |
Related Regulations
General-Purpose AI Code of Practice
European Union95% similar
European Commission Guidelines regarding the definition of an 'AI system' (clarifying Article 3(1) of the AI Act)
European Union92% similar
Template for the public summary of training content for General‑Purpose AI models (training-data transparency template)
European Union92% similar
European Commission Guidelines regarding prohibited AI practices (guidance on Article 5 prohibitions)
European Union92% similar
Hiroshima Process International Guiding Principles for Organizations Developing Advanced AI Systems and International Code of Conduct for Organizations Developing Advanced AI Systems
G790% similar
© Regulations.AI · updated on 13-Jun-2026