{"answer_id":"praxikon:eu:ai-act:answer:bewijs-gpai-aanbieder-ai-act","canonical_page":"https://www.praxikon.com/en/antwoord/bewijs-gpai-aanbieder-ai-act","query":"What evidence does a provider of a GPAI model have to be able to show under the AI Act?","lang":"en","view":"full","mode":"form","question":"What evidence does a provider of a GPAI model have to be able to show under the AI Act?","situation":"To show that a provider of a GPAI model complies with the AI Act, 2 dossiers are required. Below is what belongs in each dossier and which obligation it follows from.","likely_role":"provider of a GPAI model","note":null,"matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.1.0","schema_version":"1.4.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-08-14T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-53-gpai","label":"Article 53: GPAI model providers","summary":"Documentation, information, copyright and transparency duties for providers of general-purpose AI models.","legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/article-53-gpai","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","citations":[{"kind":"official_fact","statement":"Article 53 applies since 2 August 2025 to new GPAI models. Providers maintain technical documentation, provide information to downstream providers, operate a Union copyright policy and publish a sufficiently detailed summary of training content.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53(1), Annex XI and Annex XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"Providers of GPAI models placed on the market before 2 August 2025 must comply with the applicable obligations by 2 August 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113(3)(b)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"An organisation merely using an external GPAI model does not thereby automatically become a GPAI model provider. First determine its role in the value chain.","source_id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","source_locator":"Scope and provider qualification guidance","source_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null},{"kind":"recommended_action","statement":"Record model versions, role qualification, documentation owners, downstream information, copyright policy and training summary in one change-controlled file.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 53 and Annexes XI-XII","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-55-gpai-systemic-risk","label":"Article 55: GPAI models with systemic risk","summary":"Additional duties for the most capable general-purpose AI models, on top of Article 53.","legal_status":"applicable","deadline_at":"2025-08-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 55(1)-(2) with Article 51 and Article 52","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-gpai-guidelines","title":"Guidelines for GPAI model providers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers","eli":null,"source_version":"checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Maintain GPAI documentation and transparency information","summary":"Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content."},{"label":"Perform model evaluations and risk mitigation","summary":"Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model."}],"evidence":[{"label":"GPAI compliance file","summary":"Current technical documentation, downstream information, copyright policy and public training summary.","url":null},{"label":"Systemic-risk file","summary":"Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.","url":null}],"guidance":[{"label":"When a downstream party that fine-tunes becomes a GPAI provider itself","statement":"The Commission guidelines of 18 July 2025 (C(2025) 5045 final) on the scope of the obligations for providers of general-purpose AI models state in point (61) that it is not necessary for every modification of such a model to lead to the downstream modifier being considered the provider of the modified model, in line with the Blue Guide, which states that a product subject to important changes or overhauls aiming to modify its original performance, purpose or type may be considered a new product. Point (62) states that the Commission considers a downstream modifier to become the provider of the modified model only if the modification leads to a significant change in the model's generality, capabilities or systemic risk. Point (63) sets the indicative criterion: a downstream modifier is considered to be the provider where the training compute used for the modification is greater than a third of the training compute of the original model. Point (64) states that where the downstream modifier cannot be expected to know that value, for example because it has not been communicated by the provider of the original model, and cannot estimate it, the threshold is replaced by a third of 10 to the power of 25 FLOP where the original model is a model with systemic risk, and otherwise by a third of 10 to the power of 23 FLOP. Point (65) explains that a modification of that size is expected to display a significant change justifying the transparency obligations of Article 53(1)(a) and (b), that such a modification can be expected to have used a significant amount of data relevant to the copyright policy and the public summary of training content under Article 53(1)(c) and (d), and that where the original model has systemic risk the modified model can be expected to present significantly different systemic risk. Point (67) notes that currently few modifications meet this criterion, that the number of downstream modifiers becoming providers may increase over time, and that the criterion is thus primarily forward-looking. Point (68) states that in the case of a modification the obligations are limited to that modification: the documentation under Article 53(1)(a) and (b) is limited to information on the modification, and the copyright policy under point (c) and the summary of training content under point (d) are limited to the data used as part of the modification. Point (69) states that a downstream modifier who becomes a provider must also comply with Article 54, which means appointing an authorised representative established in the Union to the extent that the modifier is itself established outside the Union. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities and is therefore considered a model with systemic risk, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1).","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)"}],"examples":[{"label":"Heavy fine-tuning makes you the model provider","situation":"A European scale-up fine-tunes an existing general-purpose AI model for its own product, using more compute than one third of the compute used to train the original model.","outcome":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","lesson":"Estimate your fine-tuning compute against the original model before you start, because exceeding one third of it makes you the provider, with documentation, copyright and training-content duties limited to your modification.","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","provenance":"official"},{"label":"Light fine-tuning does not make you a model provider","situation":"A bank fine-tunes an existing general-purpose AI model on its own product documentation and customer questions, using a fraction of the original compute, and builds a customer chatbot around it that it offers under its own name.","outcome":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","lesson":"If your fine-tuning stays well below one third of the original compute you do not become the model provider, but the obligations for the AI system you offer under your own name still apply.","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","provenance":"official"},{"label":"Modifying a systemic-risk model pulls the heaviest duties to you","situation":"A downstream actor modifies an existing systemic-risk model so substantially that the change exceeds the threshold, and publishes the result as its own model.","outcome":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","lesson":"Where a modification of a systemic-risk model crosses the threshold, the result is presumed to have high-impact capabilities, so estimate the compute in advance and notify the Commission within two weeks.","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","provenance":"official"},{"label":"Open source in name, but not within the meaning of the Regulation","situation":"Three providers call their model open source. The first licence allows non-commercial research only. The second requires a separate commercial licence once monthly active users pass a threshold. The third gives the model away for free but hosts it exclusively on its own platform where visitors are served paid advertisements.","outcome":"The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.","lesson":"A usage restriction is not automatically fatal: you may include specific, proportionate and non-discriminatory safety terms, whereas a monthly active user threshold or a separate commercial licence disqualifies the licence.","source_locator":"Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers","provenance":"official"}],"standards":[],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/bewijs-gpai-aanbieder-ai-act","follow_up_questions":[{"question":"We train or publish our own AI model. Which GPAI rules apply?","url":"https://www.praxikon.com/en/antwoord/gpai-model-aanbieden"},{"question":"What fines and enforcement does the AI Act have and who supervises?","url":"https://www.praxikon.com/en/antwoord/boetes-handhaving"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}