EU AI Act guide · updated 2 August 2026

GPAI under the AI Act: Articles 53 and 55 for model providers

The EU AI Act regulates general-purpose AI at two levels that are easy to conflate: the model (Articles 53–55 — duties for whoever provides the model itself) and the systems built on top of it (the ordinary risk-tier rules). Most companies touching GPAI are downstream users of models — their duties are system-level. But if you train, substantially fine-tune, or release a general-purpose model, the model-level stack is yours.

Article 53: every GPAI provider

  • Technical documentation of the model — training and testing process, evaluation results — kept for the AI Office and national authorities.
  • Downstream documentation — information enabling system builders on top of your model to understand its capabilities, limitations and their own obligations.
  • Copyright policy — a policy to comply with EU copyright law, including respecting text-and-data-mining opt-outs.
  • Training-content summary — a sufficiently detailed public summary of training data, per the AI Office template.

Article 55: models with systemic risk

A model is presumed to carry systemic risk when its training compute exceeds 10²⁵ FLOPs, or when the Commission designates it. On top of Article 53, its provider must run state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents to the AI Office, and ensure adequate cybersecurity for the model and its infrastructure.

The practical question for most product companies is not “do we owe Article 53?” but “what does our model vendor owe us?” — the downstream documentation that your own Annex IV file and deployer diligence should reference. Ask for it; it is their legal duty to have it.

Where companies get the boundary wrong

  • “We use an LLM, so we’re GPAI-regulated” — no; your application’s use context sets your tier. An LLM-powered hiring screener is Annex III high-risk because of what it does, not what powers it.
  • “We fine-tuned it, but it’s the base model’s problem” — a substantial modification placed on the market can make you provider of the modified model.
  • “Open weights means exempt” — the open-source carve-out is partial and vanishes at systemic-risk scale.
  • Forgetting Article 50 — GPAI-powered chatbots and content generators still owe user disclosure and machine-readable marking of synthetic output, enforceable since 2 August 2026.

Map your role — model provider, system provider or deployer — in 10 minutes

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

The GPAI chapter is where roles decide everything: the same model can put four different companies under four different obligation sets. Establish your role per system first — the checklist sequences the rest.

Frequently asked questions

We fine-tune an open model and ship it in our product. Are we a GPAI provider?

You may be. Substantially modifying or fine-tuning a general-purpose model and placing the result on the EU market can make you the provider of that modified model, with Article 53 duties for the modification. Separately, what your product does with the model sets your system-level tier — a fine-tuned model powering CV screening makes you a high-risk system provider too.

Does using GPT, Claude or Gemini via API give us GPAI obligations?

No — API consumption doesn't make you a model provider; those duties sit with the model's provider. Your obligations come from your application: its risk tier (Annex III), transparency duties (Art. 50), and deployer duties if you use vendor AI internally. What you should collect from your model vendor is the downstream documentation Article 53 obliges them to give you.

What about open-source models?

Providers of models released under a free and open-source licence, with weights, architecture and usage documentation public, are exempt from some Article 53 duties (documentation to the AI Office / downstream providers) — but not from the copyright policy and training-content summary, and the exemption disappears entirely for models with systemic risk.

Since when are GPAI duties enforceable?

Article 53/55 obligations have applied since 2 August 2025; models already on the market before that date have until 2 August 2027 to come into compliance. Commission enforcement powers over GPAI providers (fines up to €15M or 3%) became exercisable from August 2026.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.