General-Purpose AI (GPAI)
General-purpose AI (GPAI) refers to AI models trained on broad datasets that can perform a wide range of tasks, such as writing, coding, summarizing, and reasoning, rather than being built for a single narrow purpose. Because these models can be adapted to many downstream applications, they are treated as a distinct category under the EU AI Act. Not all obligations apply equally to every GPAI model, as heightened duties attach only to those posing greater risk.
General-purpose AI denotes AI models trained on broad data that display significant generality and are capable of competently performing a wide range of distinct tasks, regardless of how they are placed on the market, and that can be integrated into a variety of downstream systems or applications. Under the EU AI Act (Regulation (EU) 2024/1689), GPAI models form a regulated category with a tiered obligation structure: baseline requirements for providers generally include maintaining technical documentation, providing information to downstream providers integrating the model, implementing a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of the content used for training. Additional, more stringent obligations, such as model evaluation, systemic risk assessment and mitigation, adversarial testing, serious-incident reporting, and cybersecurity measures, apply only to GPAI models classified as presenting 'systemic risk'; they do not apply to all GPAI models. This entry describes the concept as framed by the EU AI Act and should not be read as equating GPAI with a specific model architecture or capability threshold; providers should verify precise classification criteria, obligations, and thresholds against the current authoritative text.
Why it matters
General-purpose AI models occupy a distinct regulatory category because a single model can be integrated into countless downstream systems, meaning that a flaw, bias, or capability in the underlying model can propagate across many applications and providers. The EU AI Act responds to this by placing obligations directly on the providers of GPAI models rather than leaving responsibility entirely with the businesses that build on top of them. For compliance teams, this matters because it introduces a layer of regulatory duty at the model level that is separate from the obligations attaching to specific AI systems or use cases.
The scope of these duties depends heavily on classification. Baseline obligations for GPAI model providers generally include maintaining technical documentation, providing information to downstream providers that integrate the model, implementing a policy to comply with EU copyright law, and publishing a sufficiently detailed summary of the content used for training. More stringent duties—such as model evaluation, systemic risk assessment and mitigation, adversarial testing, serious-incident reporting, and cybersecurity measures—apply only to GPAI models classified as presenting systemic risk. Treating every GPAI model as subject to the full set of obligations would over-state the requirements; conversely, assuming a model is exempt without checking its classification carries compliance risk.
The Act can also reach providers outside the EU. A GPAI model generally falls within the Act's geographical scope where it is made available or used in the EU single market in the course of a commercial activity, giving the framework extraterritorial effect in some circumstances. Because classification thresholds, obligation details, and effective dates continue to be clarified through European Commission guidance and evolving enforcement practice, organizations should verify a model's specific status and the applicable duties against the current authoritative text rather than relying on general characterizations.
Who it's relevant to
Inside GPAI
Common questions
Answers to the questions practitioners most commonly ask about GPAI.

