When a downstream party that fine-tunes becomes a GPAI provider itself
Not every modification makes you a provider. The indicative threshold is a modification using more than a third of the original model's training compute, and your obligations are then limited to the modification.
The official source remains authoritative. This is general information about obligations and not legal advice. See this object on the map
Address and citation
This object has an address of its own that is never renamed or reused. Store the identifier in your own file, not the title or the link.
- Identifier
praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider- Payload hash (sha256)
0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188
Citation line
Praxikon, "When a downstream party that fine-tunes becomes a GPAI provider itself", praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-14T00:00:00.000Z, sha256 0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188- Version
- 1.0.0
- Legal time (effective_at)
- 8 August 2026
- Knowledge time (known_at)
- 8 August 2026
- Closed on
- Not closed
- Topics
- guidance
Review status: Placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
What this object links to
Every relation appears below as a path: from the source with its locator, through the conditions and exceptions of the object carrying the relation, to the consequence. A locator belongs to a statement in the data and not to a relation, so the source is the source anchor of the carrying object.
The obligation this hangs off
1 of 1 shown
The object belongs to this obligation. The source line it hangs off sits there.
Source
Official fact on this object, with its locator.
Guidelines for GPAI model providers
Locator: Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)
praxikon:eu:ai-act:source:commission-gpai-guidelines
Open official source
Via
- Condition | allApplies to downstream actors distinct from the original provider and not acting on its behalf, who modify or fine-tune a general-purpose AI model, with or without integrating it into an AI system.
- ExceptionIf you become the provider of the modified model, obligations remain limited to the modification itself: the technical documentation covers the change, and the copyright policy and training-content summary cover only the data used in the modification.
As long as this exception is not ruled out, the outcome stays conditional and you have to establish it yourself.
Consequence
ObligationArticle 53: GPAI model providers
praxikon:eu:ai-act:obligation:article-53-gpai
What this object is about
2 of 2 shown
The object is about this role. Undifferentiated: it does not follow that the duty rests on this role.
Source
Official fact on this object, with its locator.
Guidelines for GPAI model providers
Locator: Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)
praxikon:eu:ai-act:source:commission-gpai-guidelines
Open official source
Via
- Condition | allApplies to downstream actors distinct from the original provider and not acting on its behalf, who modify or fine-tune a general-purpose AI model, with or without integrating it into an AI system.
- ExceptionIf you become the provider of the modified model, obligations remain limited to the modification itself: the technical documentation covers the change, and the copyright policy and training-content summary cover only the data used in the modification.
As long as this exception is not ruled out, the outcome stays conditional and you have to establish it yourself.
Consequence
praxikon:eu:ai-act:actor:gpai-model-provider
praxikon:eu:ai-act:actor:provider
What this object states
Official fact
Attributable to a named primary source, with a locator. Where they differ, the official source prevails.
The Commission guidelines of 18 July 2025 (C(2025) 5045 final) on the scope of the obligations for providers of general-purpose AI models state in point (61) that it is not necessary for every modification of such a model to lead to the downstream modifier being considered the provider of the modified model, in line with the Blue Guide, which states that a product subject to important changes or overhauls aiming to modify its original performance, purpose or type may be considered a new product. Point (62) states that the Commission considers a downstream modifier to become the provider of the modified model only if the modification leads to a significant change in the model's generality, capabilities or systemic risk. Point (63) sets the indicative criterion: a downstream modifier is considered to be the provider where the training compute used for the modification is greater than a third of the training compute of the original model. Point (64) states that where the downstream modifier cannot be expected to know that value, for example because it has not been communicated by the provider of the original model, and cannot estimate it, the threshold is replaced by a third of 10 to the power of 25 FLOP where the original model is a model with systemic risk, and otherwise by a third of 10 to the power of 23 FLOP. Point (65) explains that a modification of that size is expected to display a significant change justifying the transparency obligations of Article 53(1)(a) and (b), that such a modification can be expected to have used a significant amount of data relevant to the copyright policy and the public summary of training content under Article 53(1)(c) and (d), and that where the original model has systemic risk the modified model can be expected to present significantly different systemic risk. Point (67) notes that currently few modifications meet this criterion, that the number of downstream modifiers becoming providers may increase over time, and that the criterion is thus primarily forward-looking. Point (68) states that in the case of a modification the obligations are limited to that modification: the documentation under Article 53(1)(a) and (b) is limited to information on the modification, and the copyright policy under point (c) and the summary of training content under point (d) are limited to the data used as part of the modification. Point (69) states that a downstream modifier who becomes a provider must also comply with Article 54, which means appointing an authorised representative established in the Union to the extent that the modifier is itself established outside the Union. Point (70) states that where a downstream actor modifies a model classified as having systemic risk in such a way that they become the provider of the modified model, the resulting model is presumed to have high-impact capabilities and is therefore considered a model with systemic risk, and point (71) states that the modifier must then comply with the obligations for providers of models with systemic risk and notify the Commission in line with Article 52(1).
- Locator: Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)praxikon:eu:ai-act:source:commission-gpai-guidelinesOpen official source
Our interpretation
Our own reading. It can change without the law changing, and it is not the position of a supervisory authority.
The practical message is more reassuring than most organisations expect, with one catch. Ordinary fine-tuning on your own documents, RAG, prompt engineering or a LoRA adapter comes nowhere near a third of the training compute of a large base model. The Commission itself says that few modifications currently meet the criterion. Anyone adapting a model for their own use therefore generally does not become a GPAI provider. The catch sits in point (64): if you do not know the original model's training compute and cannot estimate it, you fall back on an absolute threshold of a third of 10 to the power of 23 FLOP. That is a considerably lower bar than a third of a large model, and with closed models whose compute is not published, that is exactly the scenario you are in. The second trap is the systemic-risk chain: if you modify a model already designated as having systemic risk and thereby become a provider, you inherit that label and the duty to notify the Commission. On the positive side, obligations in that case remain limited to your own modification: you do not have to reproduce the original model's documentation or training-content summary.
- Locator: Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)praxikon:eu:ai-act:source:commission-gpai-guidelinesOpen official source
Recommended step
A practical step we consider appropriate. Not an obligation following from the Regulation.
Record per modified model which base model you use, which modification method you apply and how much compute that modification consumed, so you can test the criterion rather than speculate about it. Ask the base model's provider for the training compute and document the answer, because if you cannot know that value you fall back on the considerably lower absolute threshold. Also check whether the base model is designated as having systemic risk, because that changes both the threshold and the consequences of crossing it. Reassess this judgement at every substantial retraining, since the Commission itself indicates that the number of downstream modifiers becoming providers is expected to grow.
- Locator: Commission Guidelines C(2025) 5045 final, 18.7.2025, Section 3.2 points (60) to (67) and Sections 3.2.1 and 3.2.2, points (68) to (71)praxikon:eu:ai-act:source:commission-gpai-guidelinesOpen official source
When this applies
- 1Applies to downstream actors distinct from the original provider and not acting on its behalf, who modify or fine-tune a general-purpose AI model, with or without integrating it into an AI system.
When this does not apply
- If you become the provider of the modified model, obligations remain limited to the modification itself: the technical documentation covers the change, and the copyright policy and training-content summary cover only the data used in the modification.
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "When a downstream party that fine-tunes becomes a GPAI provider itself", praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0 (schema 1.4.0), effective_at 2026-08-08T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z, sha256 0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188, https://www.praxikon.com/en/verkenner/guidance/guidance-gpai-downstream-modifier-becomes-provider (https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aguidance%3Aguidance-gpai-downstream-modifier-becomes-provider&effective_at=2026-08-08&known_at=2026-08-08&lang=en, accessed 2026-08-25)
Short form
praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider@1.0.0 (sha256 0ed9f341)
BibTeX
@misc{praxikon-eu-ai-act-guidance-guidance-gpai-downstream-modifier-becomes-provider-1-0-0,
author = {{Praxikon}},
title = {When a downstream party that fine-tunes becomes a GPAI provider itself},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.1.0, schema 1.4.0},
note = {effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188},
url = {https://www.praxikon.com/en/verkenner/guidance/guidance-gpai-downstream-modifier-becomes-provider},
urldate = {2026-08-25},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider@1.0.0",
"type": "dataset",
"title": "When a downstream party that fine-tunes becomes a GPAI provider itself",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:guidance:guidance-gpai-downstream-modifier-becomes-provider",
"URL": "https://www.praxikon.com/en/verkenner/guidance/guidance-gpai-downstream-modifier-becomes-provider",
"language": "en",
"issued": {
"date-parts": [
[
2026,
8,
8
]
]
},
"accessed": {
"date-parts": [
[
2026,
8,
25
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.1.0; schema 1.4.0; effective_at 2026-08-08T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 0ed9f3418998c47b4bff2f13773c624f63b3fbf0f6fd82dcb2624899df6d5188; retrieved_from https://www.praxikon.com/api/v1/entities?id=praxikon%3Aeu%3Aai-act%3Aguidance%3Aguidance-gpai-downstream-modifier-becomes-provider&effective_at=2026-08-08&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
For agents and integrations
This page and the machine output come from the same object and the same two time axes.