Skip to content
Confir.
Glossary

General-Purpose AI Model (GPAI): Definition Under the EU AI Act

Definition10 August 2026· 5 min read

A GPAI model is defined in Article 3(63) of the EU AI Act. It is a cross-cutting Chapter V category, not a risk tier; duties sit with the provider.

A general-purpose AI model (GPAI model) is, under Article 3(63) of the EU AI Act, Regulation (EU) 2024/1689, an AI model — including one trained on a large amount of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems. The large language and image models behind tools like ChatGPT, Gemini, Llama and Mistral are GPAI models.

The single most important thing to understand: GPAI is not a risk tier. It is a separate, cross-cutting category governed by Chapter V of the Act, sitting alongside the prohibited / high-risk / limited / minimal classification rather than inside it.


GPAI model vs AI system

The Act distinguishes the model from the system built on it. A GPAI model is the underlying engine; an AI system (Article 3(1)) is the deployed application with an intended purpose. You classify the system by its use under Articles 5, 6 and 50; the model carries its own obligations under Chapter V. The same GPAI model can sit behind a minimal-risk drafting tool and a high-risk recruitment system — the model's status does not change, but each system is classified on its own use.

This is why you should never call a system "high-risk" merely because it runs on an LLM, and never call an LLM "high-risk" in itself.


Who carries the obligations

The duties fall on the GPAI model provider, not on downstream deployers who simply use the model through an API. Under Article 53, every GPAI model provider must:

  • maintain technical documentation of the model;
  • provide downstream providers with the information they need to comply;
  • put in place a policy to comply with EU copyright law;
  • publish a sufficiently detailed summary of the content used for training.

If a model crosses the systemic-risk threshold — Article 51 presumes this at 10^25 FLOPs of cumulative training compute — additional obligations under Article 55 apply: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity. Designation can also follow a qualified alert from the scientific panel under Article 90.


Open-source GPAI: a partial carve-out

Article 53(2) relieves providers of GPAI models released under a free and open-source licence from the Annex XI technical-documentation and Annex XII downstream-information duties — but not for systemic-risk models, and the copyright policy and training-data summary always survive. Open source is a narrowing of two duties, not a free pass. (Note this is separate from the Article 2(12) open-source carve-out for AI systems.)


Timeline and penalties

GPAI obligations under Chapter V have applied since 2 August 2025. GPAI models already on the market before that date have until 2 August 2027 to comply. The Digital Omnibus high-risk deferral (adopted — European Parliament 16 June 2026, Council 29 June 2026) does not touch Chapter V — GPAI timing is unchanged.

Fines on GPAI model providers are imposed by the Commission under Article 101 — up to €15 million or 3% of total worldwide annual turnover — not under the Article 99 regime that applies to providers and deployers of AI systems.


How Confir helps

Confir classifies the AI systems your organisation builds or deploys on GPAI models — by intended purpose, under Articles 5, 6 and 50 — and records which model sits underneath each, so you can see where the GPAI provider's duties end and yours begin. The engine is deterministic and rule-based: the same intake always yields the same cited finding. (Confir's coverage of GPAI provider obligations is partial and on the roadmap; its focus is the deployer and system-provider side that fits the SMB user.)


Frequently asked questions

What is a GPAI model under the EU AI Act?

A general-purpose AI model is defined in Article 3(63) as a model — often trained on large data with self-supervision at scale — that shows significant generality, performs a wide range of distinct tasks, and can be integrated into many downstream systems. Large language and image models are the typical examples. It is a cross-cutting category under Chapter V, not a risk tier.

Is a GPAI model the same as a high-risk AI system?

No. GPAI is not a risk tier. You classify the AI system built on a model by its intended purpose under Articles 5, 6 and 50; the model itself carries Chapter V obligations. The same GPAI model can power a minimal-risk tool and a high-risk system, so never label a model high-risk in itself.

Who has to comply with the GPAI obligations?

The GPAI model provider, under Articles 51–55 — not downstream deployers who use the model through an API. Providers maintain technical documentation, supply downstream information, keep a copyright policy, and publish a training-data summary. Systemic-risk models carry added duties under Article 55.

When did GPAI obligations start applying?

Since 2 August 2025. Models already on the market before then have until 2 August 2027 to comply. The Digital Omnibus deferral of high-risk dates does not affect Chapter V, so GPAI timing is unchanged.

Does open source exempt a GPAI model?

Only partially. Article 53(2) relieves open-source GPAI models of the Annex XI and Annex XII documentation duties, but not systemic-risk models, and the copyright policy and training-data summary always survive. Open source narrows two duties; it is not a full exemption.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →