EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · GPAI · MODEL PROVIDERS · SYSTEMIC RISK
IF YOUR MODEL POWERS MANY SYSTEMS, YOUR EVIDENCE HAS TO TRAVEL DOWNSTREAM.
General-purpose AI providers sit at the top of a long compliance chain. The obligation is not only to know how the model was built, but to maintain the documentation, copyright controls, training-content transparency, downstream information and—where applicable—systemic-risk evidence that other actors need to govern their own AI systems.
BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR
European Commission · Guidelines for Providers of General-Purpose AI Models
The Commission states that GPAI provider obligations have applied since 2 August 2025 and that full Commission enforcement powers apply from 2 August 2026. Article 53 covers documentation, downstream information, copyright policy and training-content summaries; Article 55 adds evaluation, systemic-risk mitigation, incident reporting and cybersecurity for GPAI models with systemic risk.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
ARE YOU A PROVIDER OF A GENERAL-PURPOSE AI MODEL?
The first question is whether the model qualifies as GPAI and whether your organisation is the provider placing it on the EU market. Significant modifications can also move an actor into provider obligations under current Commission guidance.
02
CAN DOWNSTREAM PROVIDERS UNDERSTAND YOUR MODEL?
Article 53 requires providers to maintain technical documentation and make sufficient information available to downstream AI-system providers so they can understand capabilities, limitations and relevant compliance conditions.
03
ARE COPYRIGHT AND TRAINING-CONTENT DUTIES COVERED?
Providers must put in place a policy to comply with Union copyright and related-rights law and publish a sufficiently detailed summary of the content used for training according to the AI Office template.
04
DOES THE MODEL PRESENT SYSTEMIC RISK?
Providers of GPAI models with systemic risk face additional Article 55 duties, including model evaluation, adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and adequate cybersecurity protection.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Determine whether the model and organisation fall within GPAI provider scope
Separate the model from the downstream AI system, identify who places the model on the market, and preserve the basis for whether the organisation is a provider, modifier, integrator, distributor or downstream system provider.
02
Build and maintain the Article 53 evidence package
Preserve technical documentation, training and testing information, evaluation results, downstream documentation, copyright-policy evidence, training-content summary, version history and authorised-representative information where applicable.
03
Assess systemic-risk status and notification duties
Determine whether the model meets or may meet systemic-risk criteria, preserve the assessment, and document notifications, requests for reassessment, safety and security evidence, and any reliance on the GPAI Code of Practice or alternative compliance method.
04
Revalidate after material model or release changes
A major model update, new capabilities, changed training process, new release terms, significant modification, changed downstream use profile or new systemic-risk evidence can alter the provider’s obligations and prior documentation.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
When did GPAI provider obligations start applying?
The Commission states that obligations for providers of general-purpose AI models entered into application on 2 August 2025. From 2 August 2026, the Commission’s enforcement powers apply, including the ability to enforce compliance through fines.
What does Article 53 require from GPAI providers?
Article 53 requires technical documentation, information and documentation for downstream AI-system providers, a policy to comply with Union copyright and related-rights law, and a sufficiently detailed public summary of the content used for training.
Are open-source GPAI models exempt?
There is a limited exemption from certain Article 53 documentation duties for qualifying free and open-source models whose relevant parameters and information are publicly available. That exemption does not apply to GPAI models with systemic risk.
What extra obligations apply to GPAI models with systemic risk?
Article 55 adds model evaluation, documented adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting, and adequate cybersecurity protection for the model and relevant physical infrastructure.
Does integrating a GPAI model into a product remove model-provider obligations?
No. The Regulation distinguishes model obligations from downstream AI-system obligations. When a provider places its own GPAI model on the market as part of an AI system, model-level obligations can continue to apply alongside system-level duties.
Does TA-14 certify a GPAI provider as compliant?
No. TA-14 can preserve the provider-role analysis, documentation state, evidence, gaps, systemic-risk assessment, changes and revalidation history. It does not itself provide legal advice, certification, conformity assessment or regulatory approval.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.