Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: AI Governance

General-Purpose AI (GPAI)

Also known as: GPAI, General-purpose AI model, GPAI model, General-purpose artificial intelligence
Simply put

General-purpose AI (GPAI) refers to AI models trained on broad datasets that can perform a wide range of tasks, such as writing, coding, summarizing, and reasoning, rather than being built for a single narrow purpose. Because these models can be adapted to many downstream applications, they are treated as a distinct category under the EU AI Act. Not all obligations apply equally to every GPAI model, as heightened duties attach only to those posing greater risk.

Formal definition

General-purpose AI denotes AI models trained on broad data that display significant generality and are capable of competently performing a wide range of distinct tasks, regardless of how they are placed on the market, and that can be integrated into a variety of downstream systems or applications. Under the EU AI Act (Regulation (EU) 2024/1689), GPAI models form a regulated category with a tiered obligation structure: baseline requirements for providers generally include maintaining technical documentation, providing information to downstream providers integrating the model, implementing a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of the content used for training. Additional, more stringent obligations, such as model evaluation, systemic risk assessment and mitigation, adversarial testing, serious-incident reporting, and cybersecurity measures, apply only to GPAI models classified as presenting 'systemic risk'; they do not apply to all GPAI models. This entry describes the concept as framed by the EU AI Act and should not be read as equating GPAI with a specific model architecture or capability threshold; providers should verify precise classification criteria, obligations, and thresholds against the current authoritative text.

Why it matters

General-purpose AI models occupy a distinct regulatory category because a single model can be integrated into countless downstream systems, meaning that a flaw, bias, or capability in the underlying model can propagate across many applications and providers. The EU AI Act responds to this by placing obligations directly on the providers of GPAI models rather than leaving responsibility entirely with the businesses that build on top of them. For compliance teams, this matters because it introduces a layer of regulatory duty at the model level that is separate from the obligations attaching to specific AI systems or use cases.

The scope of these duties depends heavily on classification. Baseline obligations for GPAI model providers generally include maintaining technical documentation, providing information to downstream providers that integrate the model, implementing a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of the content used for training. More stringent duties—such as model evaluation, systemic risk assessment and mitigation, adversarial testing, serious-incident reporting, and cybersecurity measures—apply only to GPAI models classified as presenting systemic risk. Treating every GPAI model as subject to the full set of obligations would over-state the requirements; conversely, assuming a model is exempt without checking its classification carries compliance risk.

The Act can also reach providers outside the EU. A GPAI model generally falls within the Act's geographical scope where it is made available or used in the EU single market in the course of a commercial activity, giving the framework extraterritorial effect in some circumstances. Because classification thresholds, obligation details, and effective dates continue to be clarified through European Commission guidance and evolving enforcement practice, organizations should verify a model's specific status and the applicable duties against the current authoritative text rather than relying on general characterizations.

Who it's relevant to

Providers of GPAI models
Organizations that develop and place general-purpose AI models on the EU market are the primary addressees of the Act's GPAI obligations. Baseline duties generally include technical documentation, information-sharing with downstream integrators, a copyright-compliance policy, and a public summary of training content. Where a model is classified as presenting systemic risk, additional duties such as model evaluation, risk assessment and mitigation, adversarial testing, incident reporting, and cybersecurity measures apply. Providers should confirm their model's classification and the corresponding obligations against the current authoritative text.
Downstream providers and integrators
Businesses that build AI systems or applications on top of a GPAI model rely on information the model provider is required to supply. Understanding what documentation and information they are entitled to receive helps these organizations meet their own obligations under the Act for the systems they deploy. Their duties are distinct from those of the underlying model provider and depend on their specific role and use case.
Non-EU model providers with EU market reach
A GPAI model may fall within the Act's geographical scope where it is made available or used in the EU single market in the course of a commercial activity. Providers established outside the EU should therefore assess whether their models trigger the Act's extraterritorial reach, as this determination is fact-specific and depends on how the model is placed on or used in the market.
Compliance, legal, and governance teams
Compliance officers, legal counsel, and AI governance functions need to distinguish the binding requirements of the EU AI Act from the voluntary General-Purpose AI Code of Practice, and to separate baseline GPAI obligations from the heightened duties tied to systemic-risk classification. Because interpretation and enforcement practice continue to evolve, these teams should treat model classification as a live compliance question and verify obligations against official European Commission sources rather than general summaries.

Inside GPAI

General-Purpose AI (GPAI) Model
An AI model that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems or applications. Under the EU AI Act (Regulation (EU) 2024/1689), GPAI models are regulated as a distinct category from AI systems more broadly. The precise scope and any thresholds are set out in the Act and accompanying guidance, which readers should verify against the current official text.
Baseline Provider Obligations
Obligations that generally apply to providers of GPAI models under the EU AI Act. As reflected in the relevant provisions (see Art 53), these are principally: maintaining and keeping up to date technical documentation of the model; making information and documentation available to downstream providers who integrate the model; putting in place a policy to comply with EU copyright law; and drawing up and making publicly available a sufficiently detailed summary of the content used to train the model. Certain requirements may be modulated for models released under free and open-source licences; verify the specific carve-outs against the current text.
GPAI Models with Systemic Risk
A sub-category of GPAI models designated as posing systemic risk, based on criteria set out in the Act (for example, high-impact capabilities assessed against defined thresholds). Providers of these models are subject to additional obligations beyond the baseline, which under Art 55 may include model evaluation and adversarial testing, assessment and mitigation of systemic risks, tracking and reporting of serious incidents, and ensuring an adequate level of cybersecurity. These heightened duties do not apply to GPAI models that are not so classified.
Regulatory Instrument and Scope
GPAI as a defined regulatory category is a creature of EU law, specifically the EU AI Act, which is binding legislation rather than a voluntary standard. Its reach can extend to providers established outside the EU where their models are placed on the EU market or otherwise fall within the Act's territorial scope. Other jurisdictions (for example the United States and the United Kingdom) do not use an identical GPAI construct and address foundation or general-purpose models through different, and in places non-binding, mechanisms.
Codes of Practice and Guidance
The EU AI Act contemplates codes of practice and supporting guidance to help providers demonstrate compliance with GPAI-related obligations pending or alongside harmonised standards. Adherence to such a code is generally a voluntary means of evidencing compliance rather than a separate legal obligation in itself. The content, status, and availability of these instruments continue to evolve and should be checked against the latest authoritative sources.

Common questions

Answers to the questions practitioners most commonly ask about GPAI.

Do all providers of general-purpose AI models face safety obligations under the EU AI Act?
No. Under Regulation (EU) 2024/1689, the baseline obligations that apply to all GPAI model providers are generally limited to matters such as maintaining technical documentation, providing information to downstream providers who integrate the model, putting in place a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of the content used for training. Explicit safety-related duties—such as model evaluation and adversarial testing, systemic risk assessment and mitigation, serious incident tracking and reporting, and adequate cybersecurity protection—generally apply only to GPAI models classified as presenting systemic risk. Providers should verify the current allocation of duties against the latest official text, as interpretation and supporting guidance continue to develop.
Is 'general-purpose AI' just another way of saying a high-risk AI system under the Act?
No—these are distinct concepts that the Act keeps separate. A GPAI model is defined by its capability to perform a wide range of tasks and its capacity to be integrated into many downstream systems, and it is regulated at the model layer. 'High-risk AI system' is a separate classification tied to specific use cases and contexts of deployment, carrying its own set of obligations at the system layer. A GPAI model may be built into a system that is later classified as high-risk, but the two categories are not equivalent, and being general-purpose does not by itself make a model high-risk. Readers should treat the model-level and system-level obligations as different regimes.
How can a provider tell whether its GPAI model is treated as having systemic risk?
The Act sets out criteria for identifying GPAI models with systemic risk, which generally turn on the model's capabilities and reach, including reference to the computational resources used in training as an indicator, alongside a mechanism for designation. Because the specific thresholds, indicators, and designation procedures are technical and subject to guidance from the relevant EU bodies, a provider should assess its position against the current official text and any published methodology rather than relying on a fixed figure. Where a model falls into the systemic-risk category, a materially broader set of obligations applies. This overview does not substitute for a case-specific legal assessment.
What baseline documentation should a GPAI model provider prepare regardless of systemic-risk status?
For GPAI models generally, providers are expected to prepare and keep up to date technical documentation about the model, make appropriate information and documentation available to downstream providers who integrate the model into their own systems, adopt a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the training content. The precise expected contents of each item are shaped by the Act's annexes and by supporting guidance, so providers should confirm the current requirements against the authoritative source and tailor their records to their own facts.
Does the EU AI Act's GPAI regime reach providers established outside the EU?
It can. The Act is generally understood to have extraterritorial reach in that obligations may attach to providers placing GPAI models on the EU market or making them available in the Union, irrespective of where the provider is established. The practical scope of that reach, and how it interacts with the roles of importers, distributors, and downstream providers, depends on the specific arrangement. Non-EU providers should confirm whether and how the obligations apply to their distribution model and should not assume that being located outside the EU removes them from scope.
If we fine-tune or modify an existing GPAI model, do we take on provider obligations?
Possibly. Making substantial modifications to a GPAI model can, in certain circumstances, cause the modifying organization to be treated as a provider with respect to the changes, which may bring associated obligations. Whether this occurs generally depends on the nature and extent of the modification and on how the resulting model is placed on the market or put into service. Because the boundary between using, adapting, and re-providing a model is fact-specific and subject to evolving interpretation, organizations that fine-tune models should assess their status against the current text and seek professional judgment for their particular circumstances.
How do the GPAI provisions relate to voluntary standards and codes of practice?
The GPAI provisions are binding regulatory requirements, whereas codes of practice and technical standards referenced in connection with the Act are, in themselves, voluntary instruments intended to help demonstrate compliance. Adhering to an approved code of practice or a relevant standard may support a provider in showing that it meets applicable obligations, but such instruments do not replace the legal requirements and their availability and content evolve over time. Providers should distinguish what the Regulation mandates from what supporting standards recommend, and verify both against current authoritative sources.

Common misconceptions

All GPAI model providers must carry out risk assessment, adversarial testing, incident reporting, and cybersecurity measures under the EU AI Act.
These safety-oriented duties apply only to GPAI models classified as posing systemic risk (Art 55). For GPAI models generally, the baseline obligations (Art 53) are limited to technical documentation, information-sharing with downstream providers, a copyright-compliance policy, and a public summary of training content. Practitioners should not assume the systemic-risk obligations apply to every model.
GPAI is a global standard or classification that applies the same way everywhere.
GPAI as defined is a category under the EU AI Act, which is binding EU legislation. Other jurisdictions regulate general-purpose or foundation models differently, and some rely on voluntary or non-binding approaches. The EU framework can apply extraterritorially where models reach the EU market, but its specific obligations are not a universal standard.
Complying with a code of practice is itself a mandatory legal requirement for GPAI providers.
Codes of practice generally function as a voluntary route to demonstrate compliance with the underlying legal obligations, not as a standalone mandate. The binding requirements come from the Act itself; a provider may demonstrate compliance by other adequate means, and the status of these instruments continues to develop.

Best practices

Determine early whether a given model meets the GPAI definition and, separately, whether it is classified as a GPAI model with systemic risk, since the applicable obligations differ substantially between the two.
For GPAI models generally, prioritise the baseline obligations: maintain current technical documentation, prepare information and documentation for downstream integrators, establish a copyright-compliance policy, and produce a public summary of training content.
Where a model is (or may become) classified as posing systemic risk, plan for the additional Art 55-type duties such as model evaluation and adversarial testing, systemic-risk mitigation, serious-incident tracking and reporting, and cybersecurity measures.
Assess territorial exposure, including potential extraterritorial application where a model is placed on or reaches the EU market, and map any parallel obligations in other jurisdictions rather than assuming the EU approach applies uniformly.
Treat codes of practice and guidance as evolving voluntary compliance tools, monitor their development, and document the chosen means of demonstrating compliance.
Verify all specific obligations, article references, thresholds, and effective dates against the current official text of Regulation (EU) 2024/1689 and applicable guidance, and involve qualified legal and compliance professionals for application to particular circumstances.
Promotional banner for the Pentest Readiness checklist download