Governance · 5 minute read
EU AI Act GPAI Obligations: What Model Providers Owe
General-purpose AI model providers under the EU AI Act must keep technical documentation, give downstream providers information sufficient to meet their own obligations, maintain a copyright policy, and publish a summary of training content. Models with systemic risk carry additional evaluation and reporting duties.
General-purpose AI model obligations under the EU AI Act sit on the providers of the models themselves rather than on most organisations building with them. For builders, the practical significance is twofold: the documentation you need should now exist, and fine-tuning may put you on the wrong side of the line. This guide covers both, drawing on FISTA Solutions' AI enablement work. This article is general guidance, not legal advice.
Who counts as a GPAI provider?
Whoever places a general-purpose AI model on the EU market, including under their own name or trademark.
The part that surprises teams is that fine-tuning or substantially modifying a model can make you the provider of the resulting model. Whether a given modification crosses that line depends on the facts, and it is worth establishing before a programme is well advanced rather than after.
What are the baseline obligations?
| Obligation | Purpose |
|---|---|
| Technical documentation | Enable assessment of the model |
| Downstream information | Let builders meet their own duties |
| Copyright policy | Compliance with EU copyright law |
| Training content summary | Sufficiently detailed public summary |
The downstream information duty is the one that matters most to everyone else, because it is what makes a model usable in regulated contexts.
What changes for systemic-risk models?
Models designated as presenting systemic risk carry additional duties: evaluation using standardised protocols, adversarial testing, assessment and mitigation of systemic risks, tracking and reporting serious incidents, and adequate cybersecurity for the model and its infrastructure.
Designation turns on criteria including capability thresholds. In practice, the largest frontier models are the population in scope, and most organisations will encounter these obligations as consumers rather than as providers.
Do open-weight models have exemptions?
Some obligations are relaxed for models released under free and open-source licences with publicly available parameters, subject to conditions. Copyright policy and training content summary duties generally still apply, and systemic-risk models are not exempt.
If open-weight licensing is part of your strategy, confirm what the relaxation actually covers rather than assuming it removes the obligations. See what is open-weight ai.
What does this mean for companies building on models?
Mostly that the documentation you need should exist, and you should ask for it.
Capability and limitation information, evaluation results, intended and excluded uses, and the training content summary are all things a downstream provider needs to meet its own obligations. A supplier who cannot produce them is a supply chain risk in any regulated deployment.
When does fine-tuning make you a provider?
When the modification is substantial enough that the resulting model is materially different. Light adaptation for a narrow task is generally a different matter from significant further training that changes capabilities.
The practical advice is to establish the position with counsel before committing to an approach, because the engineering consequences differ considerably. This is general guidance, not legal advice.
How does this interact with high-risk system obligations?
They stack rather than substitute. A high-risk system built on a general-purpose model carries the high-risk obligations, and the model provider's documentation is an input to meeting them.
That is precisely why the downstream information duty exists: without it, builders could not produce the technical documentation their own obligations require. See EU AI Act high-risk obligations.
When do these obligations apply?
The Act applies in phases, with general-purpose model obligations taking effect ahead of most high-risk system obligations, and transitional arrangements for models already on the market.
Confirm current dates for your situation rather than relying on a summary.
What should you ask a model supplier?
Whether they publish the training content summary, what capability and limitation documentation they provide, what evaluation results they share, whether the model is designated as presenting systemic risk, and what their position is on downstream provider support.
Those five questions separate suppliers who have prepared from those who have not.
What evidence should you keep?
Which model version you used, when, what documentation the provider supplied, what evaluation you ran on top of it, and what limitations you communicated to your own users.
Model versions change, and a system evaluated against one version is not evidence about another. See what is a regression suite for ai.
What are the common mistakes?
Assuming fine-tuning is always safe. Assuming open weights remove all obligations. Not asking suppliers for documentation until an audit does. And failing to record which model version was in use when.
Who owns this internally?
Whoever owns the model relationship, with legal support. In most organisations that is engineering or a platform team, and the documentation obligation is a supplier management question as much as a technical one.
What should you do first?
List the models you use, in which systems, and whether you have the provider documentation for each. Most organisations find at least one model in production that nobody can name a supplier contact for.
How FISTA Solutions helps
FISTA Solutions builds on foundation models with the supply chain documented: model versions recorded per system, provider documentation collected as part of onboarding, evaluation run on top of supplier claims rather than in place of it, and fine-tuning decisions taken with the provider-status question settled first. Delivery runs through AI enablement, AI agents, and forward deployed engineers. The record is 150+ projects for 50+ companies across 12+ countries, and Anthropic is an official partner.
To review a model supply chain, message FISTA on WhatsApp, or read EU AI Act high-risk obligations.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Who counts as a GPAI provider?
Whoever places a general-purpose AI model on the EU market, including under their own name. Organisations that fine-tune or substantially modify a model can become providers of the resulting model, which surprises teams who assumed they were only users. This is general guidance, not legal advice.
02What are the baseline obligations?
Technical documentation of the model, information enabling downstream providers to understand capabilities and limitations and meet their own obligations, a policy to comply with EU copyright law, and a sufficiently detailed public summary of training content.
03What changes for systemic-risk models?
Additional duties including model evaluation with standardised protocols, adversarial testing, assessing and mitigating systemic risks, tracking and reporting serious incidents, and ensuring adequate cybersecurity protection for the model and infrastructure.
04Do open-weight models have exemptions?
Some obligations are relaxed for models released under free and open-source licences with publicly available parameters, subject to conditions, though copyright policy and training content summary duties generally still apply, and systemic-risk models are not exempt.
05What does this mean for companies building on models?
Mostly that the documentation you need should exist. Ask suppliers for capability and limitation information, evaluation results, and the training content summary, and check whether your fine-tuning makes you a provider.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.