General-purpose AI model providers under the EU AI Act must maintain up-to-date technical documentation, share relevant information with downstream companies that integrate the model, put in place a policy to respect EU copyright law, and publish a sufficiently detailed summary of the content used to train the model, obligations that have applied since 2 August 2025. Models classified as carrying systemic risk, a status presumed once training compute exceeds 10^25 floating point operations, face additional duties, including adversarial testing and model evaluation, tracking and reporting serious incidents to the AI Office, and ensuring an adequate level of cybersecurity for the model and its infrastructure. The voluntary General-Purpose AI Code of Practice, developed with the AI Office and industry, gives providers a documented way to demonstrate compliance with these duties ahead of harmonized technical standards. Providers that fine-tune or substantially modify an existing general-purpose model can themselves take on provider obligations for that modified version. Companies that only use a general-purpose model through an API inherit lighter downstream obligations but still need the documentation the provider supplies. Nanobase AI, an NVIDIA Inception Program member, helps enterprises evaluate which general-purpose models come with the documentation needed to support their own compliance obligations.
Two tiers, not one uniform set of rules
The EU AI Act does not treat every general-purpose AI model the same way. It draws a line between a baseline set of duties that apply to all GPAI model providers and a stricter set that applies only to models presumed to carry systemic risk. Confusing the two tiers is the most common source of over-compliance, where a company building a modest fine-tuned model assumes it needs the same documentation regime as a frontier lab. Almost every GPAI provider only needs to meet the baseline tier; the systemic-risk tier is reserved for models at the extreme end of training compute.
What the baseline tier requires
Since 2 August 2025, every provider placing a general-purpose AI model on the EU market has carried these obligations:
| Obligation | What it means in practice |
|---|---|
| Technical documentation | Maintain up-to-date records of training methodology, architecture, and evaluation results |
| Downstream information sharing | Give integrators enough detail to understand the model's capabilities and limitations |
| Copyright policy | Put in place a policy to identify and respect EU copyright law, including text-and-data-mining opt-outs |
| Training data summary | Publish a sufficiently detailed public summary of the content used to train the model |
These four duties apply regardless of model size, and a company fine-tuning an existing open-weight model and redistributing it as a distinct model can inherit provider status for these purposes. The baseline tier is the one nearly every GPAI provider actually needs to satisfy, and it has applied since 2 August 2025 regardless of the model's scale.
The systemic-risk tier
A GPAI model is presumed to carry systemic risk once its training compute exceeds 10^25 floating point operations, a threshold that currently captures only the largest frontier models but is written into the Act as a fixed technical trigger rather than a judgment call. Providers of these models face additional duties: adversarial testing and model evaluation before and after release, systemic risk assessment and mitigation, incident reporting to the AI Office for serious incidents, and cybersecurity protections for the model and its infrastructure. A provider can also be designated as systemic-risk by regulatory decision even below the compute threshold, though this is expected to be uncommon in practice.
The Code of Practice as a compliance shortcut
The GPAI Code of Practice, developed with input from industry, is a voluntary framework that a provider can sign onto to demonstrate compliance with the Act's transparency, copyright, and (for systemic-risk providers) safety and security chapters. Signing it does not exempt a provider from all scrutiny, but it does create a presumption of compliance that regulators generally accept without requiring bespoke documentation review. For most GPAI providers evaluating how to demonstrate compliance efficiently, adopting the Code of Practice is a faster path than building an equivalent internal framework from scratch. Signing the Code of Practice trades some flexibility for a regulator-recognized shortcut, which is usually a good trade for providers without an existing bespoke compliance program.
What this means if you build on top of a GPAI model rather than train one
Most companies interacting with the AI Act's GPAI provisions are not training frontier models; they are integrating an existing model such as GPT, Claude, or an open-weight model like Llama or Qwen into a product. In that case, the GPAI obligations sit with the model's original provider, and the integrating company's duties come from its own role as a provider or deployer of the downstream AI system, not from the GPAI chapter directly. The GPAI obligations sit with whoever provides the underlying model, not with the company that only integrates it into a downstream product. This is general information, not legal advice, and providers should confirm their specific compute and distribution profile against the Act's text.
Frequently asked questions
Does fine-tuning an open-weight model make us a GPAI provider?
It can, if the fine-tuned model is placed on the market as a distinct model rather than used purely internally. The determining factor is distribution and modification scope, not the amount of compute used for fine-tuning itself, which is typically far below the systemic-risk threshold.
What counts as 10^25 FLOPs in practical terms?
This threshold currently only captures training runs at the scale of the largest publicly known frontier models, well beyond what most enterprise fine-tuning or custom model training involves. Most companies building on existing models never approach this figure.
Is the training data summary required to list every source?
No, the Act requires a "sufficiently detailed" summary, not an exhaustive per-document list, and the European Commission has published a template describing the expected level of detail, generally covering major data categories and sources rather than individual documents.
Do open-weight models have different GPAI obligations than closed ones?
The baseline obligations apply regardless of whether weights are open or closed, though open-weight providers meeting certain conditions can qualify for narrower documentation duties for the downstream information-sharing requirement specifically.
How Nanobase AI helps
Nanobase AI helps enterprises understand where GPAI provider obligations start and where their own deployer or downstream-provider duties begin, particularly when a company customizes an open-weight model for internal use. This work is part of our broader AI security and compliance practice, alongside hands-on private LLM deployment that keeps model customization inside a company's own environment.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.