Direct answer
Which AI Act obligations apply to a provider of a GPAI model?
2 obligations under the AI Act bear on this, of which 2 apply today.
First step: Maintain GPAI documentation and transparency information.
The knowledge base holds 2 obligations for which a provider of a GPAI model is the duty holder. Of those, 2 apply today and 0 arrive later. Every obligation below points back to the official text, with the version and the date on which we verified it. Likely role: provider of a gpai model.
This applies now
- Article 53: GPAI model providersApplicable
- Article 55: GPAI models with systemic riskApplicable
Your first actions
- Maintain GPAI documentation and transparency information. Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.
- Perform model evaluations and risk mitigation. Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.
Record this
- GPAI compliance file
- Systemic-risk file
Heavy fine-tuning makes you the model provider
A European scale-up fine-tunes an existing general-purpose AI model for its own product, using more compute than one third of the compute used to train the original model.
Provenance: The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.
Estimate your fine-tuning compute against the original model before you start, because exceeding one third of it makes you the provider, with documentation, copyright and training-content duties limited to your modification.
Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers
financial services
Light fine-tuning does not make you a model provider
A bank fine-tunes an existing general-purpose AI model on its own product documentation and customer questions, using a fraction of the original compute, and builds a customer chatbot around it that it offers under its own name.
Provenance: The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.
If your fine-tuning stays well below one third of the original compute you do not become the model provider, but the obligations for the AI system you offer under your own name still apply.
Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers
Modifying a systemic-risk model pulls the heaviest duties to you
A downstream actor modifies an existing systemic-risk model so substantially that the change exceeds the threshold, and publishes the result as its own model.
Provenance: The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.
Where a modification of a systemic-risk model crosses the threshold, the result is presumed to have high-impact capabilities, so estimate the compute in advance and notify the Commission within two weeks.
Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers
technology and software
Open source in name, but not within the meaning of the Regulation
Three providers call their model open source. The first licence allows non-commercial research only. The second requires a separate commercial licence once monthly active users pass a threshold. The third gives the model away for free but hosts it exclusively on its own platform where visitors are served paid advertisements.
Provenance: The Commission guidelines on the scope of the GPAI obligations address this case when determining when someone becomes a model provider themselves. The document is non-binding.
A usage restriction is not automatically fatal: you may include specific, proportionate and non-discriminatory safety terms, whereas a monthly active user threshold or a separate commercial licence disqualifies the licence.
Commission Guidelines C(2025) 5045 final, 18.7.2025, scope of the obligations for GPAI model providers
When a downstream party that fine-tunes becomes a GPAI provider itself
The Commission guidelines of 18 July 2025 (C(2025) 5045 final) on the scope of the obligations for providers of general-purpose AI models state in point (61) that it is not necessary for every modification of such a model to lead to the downstream modifier being considered the provider of the modified model, in line with the Blue Guide, which states that a product subject to important changes or overhauls aiming to modify its original performance, purpose or type may be considered a new product. Point (62) states that the Commission considers a downstream modifier to become the provider of the modified model only if the modification leads to a significant change in the model's generality, capabilities or systemic risk. Point (63) sets the indicative criterion: a downstream modifier is considered to be the provider where the training compute used for the modification is greater than a third of the training compute of the original model. Point (64) states that where the downstream modifier cannot be expected to know that value, for example because it has not been communicated by the provider of the original model, and cannot estimate it, the threshold is replaced by a third of 10 to the power of 25 FLOP where the original model is a model with systemic risk, and otherwise by a third of 10 to the power of 23 FLOP. Point (65) explains that a modification of that size is expected to display a significant change justifying the transparency obligations of Article 53(1)(a) and (b), that such a modification can be expected to have used a significant amount of data relevant to the copyright policy and the public summary of training content under Article 53(1)(c) and (d), and that where the original model has systemic risk the modified model can be expected to present significantly different systemic risk. Point (67) notes that currently few modifications meet this criterion, that the number of downstream modifiers becoming providers may increase over time, and that the criterion is thus primarily forward-looking. Point (68) states that in the case of a modification the obligations are limited to that modification: the documentation under Article 53(1)(a) and (b) is limited to information on the modification, and the copyright policy under point (c) and the summary of training content under point (d) are limited to the data used as part of the modification. Point (69) states that a downstream modifier who becomes a provider must also comply with Article 54, which means appointing an authorised representative established in the Union to the extent that the modifier is itself established outside the Union. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities and is therefore considered a model with systemic risk, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1).
Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation