General-Purpose AI Model Obligations and the Code of Practice
The two-tier regime the EU AI Act applies to general-purpose AI models, how a training-compute number triggers the systemic-risk tier, and what signing the July 2025 Code of Practice does and does not buy a provider now that enforcement has begun.
A dense transformer trained on \(D\) tokens with \(N\) parameters costs roughly \(C \approx 6ND\) floating-point operations. At 70 billion parameters and 15 trillion tokens that is \(6 \times 7\times10^{10} \times 1.5\times10^{13} \approx 6.3\times10^{24}\) FLOP. Scale to 400 billion parameters on the same data and you get about \(3.6\times10^{25}\). Under the EU AI Act, that difference moves a model from one legal regime to another: past \(10^{25}\) FLOP, a model is presumed to have "high impact capabilities" and becomes a general-purpose AI (GPAI) model with systemic risk (AI Act, Article 51).
The AI Act regulates GPAI models separately from the use-based risk tiers covered in the EU AI Act risk tiers. The regime attaches to the model, whoever ends up deploying it, which makes it the one part of the Act where a technical quantity decides the obligations.
Two tiers of obligation
Every GPAI provider owes four things under Article 53(1): technical documentation of the model, including training, testing and evaluation results (Annex XI), kept for the AI Office; information and documentation for downstream providers integrating the model (Annex XII); a policy to comply with EU copyright law, including honouring machine-readable text-and-data-mining opt-outs; and a public, "sufficiently detailed summary" of training content on the AI Office template (Article 53). Models released under a free and open-source licence with public weights are exempt from the first two, unless they carry systemic risk.
Systemic-risk providers add four more under Article 55(1): evaluate the model with standardised protocols, including adversarial testing; assess and mitigate systemic risks at Union level; track, document and report serious incidents to the AI Office; and ensure adequate cybersecurity for the model and its infrastructure (Article 55).
The trigger is procedural. A provider must notify the Commission "without delay and in any event within two weeks" of meeting the threshold, and may argue that its model, despite the compute, does not present systemic risk (Article 52). The Commission can also designate a model below \(10^{25}\) on the Annex XIII criteria, and it can amend the threshold by delegated act as hardware and algorithms improve.
Who counts as a provider
The Commission's July 2025 guidelines put numbers on two boundaries. A model trained with more than \(10^{23}\) FLOP that can generate language, text-to-image or text-to-video is indicatively a GPAI model. A downstream party that modifies a model becomes the provider of the modified model if it uses more than one third of the original training compute; where that is unknown, the reference is one third of \(10^{23}\), about \(3.3\times10^{22}\) FLOP (summary of the guidelines, artificialintelligenceact.eu). Fine-tuning the \(3.6\times10^{25}\) model above would need more than \(1.2\times10^{25}\) FLOP to shift provider status, so ordinary fine-tuning leaves the duties with the original developer.
The Code of Practice
The Commission published the General-Purpose AI Code of Practice on 10 July 2025. It has three chapters: Transparency and Copyright, which apply to all GPAI providers, and Safety and Security, which applies only to systemic-risk models. Together they hold twelve commitments, ten of them in the safety chapter (European Commission, The General-Purpose AI Code of Practice). The Commission and the AI Board assessed it as an adequate voluntary tool. The Commission's signatory list names 21 full signatories, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI. xAI signed only the Safety and Security chapter, and Meta publicly declined to sign.
What signing buys is legal as well as reputational. Article 55(2) lets providers rely on codes of practice to demonstrate compliance "until a harmonised standard is published"; a provider that does not adhere must show "alternative adequate means of compliance" for the Commission to assess. For signatories, the Commission has said it will focus enforcement on monitoring adherence to the Code and may treat commitments as mitigating when setting fines.
The timing now matters. GPAI obligations applied from 2 August 2025. The Commission's enforcement powers, including information requests, model evaluations, mandated mitigations, market restrictions and fines, applied from 2 August 2026. Fines reach the higher of €15 million or 3% of worldwide annual turnover, so for a provider with €2 billion in turnover the ceiling is €60 million. Models placed on the market before 2 August 2025 have until 2 August 2027. As of September 2026 these dates stand: the Digital Omnibus on AI, in force since 27 July 2026, deferred high-risk obligations but left the GPAI schedule alone and widened the AI Office's supervisory powers (Regulation (EU) 2026/1744, EUR-Lex).
When it breaks
Compute is a proxy, and the field disagrees about how good a proxy. Training FLOP says nothing directly about capability after distillation, better data or inference-time scaling. Supporters value a threshold that is predictable and cheap to check; critics point out that a well-distilled model under \(10^{25}\) can match an older one above it. The designation power and the delegated-act clause exist because the drafters expected the number to age.
Signing is not complying. The Code is a route to demonstrating compliance, not a certificate of it. A signatory whose safety framework exists on paper while its evaluations lag its release cadence has made a commitment the AI Office can now test.
The open-source exemption is narrower than it sounds. It removes documentation duties, not the copyright policy or training-content summary, and it disappears entirely at the systemic-risk tier.
Downstream integrators inherit a dependency. A company building a high-risk system on a GPAI model needs the Annex XII information to write its own technical file. If the upstream provider's documentation is thin, the downstream provider's compliance is thin too, which is why provider and deployer obligations treats the contract as load-bearing.
7 flashcards for this concept
Click a card to reveal the answer.