Compliance under the EU AI Act for General‑Purpose AI
A Practical Guide for U.S. Businesses
General‑purpose AI models—often referred to as foundation models or large language models—sit at the center of today’s artificial intelligence ecosystem. They are embedded in enterprise software, consumer products, decision‑support tools, content creation systems, and a growing array of industrial and public‑sector applications. For U.S. companies that develop or deploy such models, the EU Artificial Intelligence Act (EU AI Act) represents a profound shift in regulatory expectations.
Unlike earlier sector‑specific rules or voluntary governance frameworks, the EU AI Act establishes binding, horizontal obligations specifically tailored to general‑purpose AI (GPAI). These obligations apply regardless of where a model is developed, if it is placed on the EU market or integrated into systems used in the European Union.
This page explains what qualifies as General‑Purpose AI under the EU AI Act, which U.S. businesses are in scope, what obligations apply, how systemic‑risk classification changes compliance expectations, and what practical compliance steps U.S. organizations should be taking now.
- The EU AI Act’s Structural Approach to General‑Purpose AI
GPAI as a Distinct Regulatory Category
The EU AI Act treats general‑purpose AI models as a separate regulatory object, distinct from downstream AI “systems.” This reflects the recognition that large, general‑capability models create upstream risks that cannot be fully controlled at the application layer.
Chapter V of the AI Act is devoted entirely to GPAI. It establishes:
- classification rules (Articles 51–52),
- baseline obligations for all GPAI providers (Article 53),
- additional obligations for GPAI models with systemic risk (Article 55), and
- mechanisms for codes of practice (Article 56).
This structure is unprecedented in U.S. law and is central to understanding compliance exposure for American AI developers and platform providers.
- What Is a General‑Purpose AI Model under the EU AI Act?
Statutory Definition
The EU AI Act defines a general‑purpose AI model as an AI model that:
- is trained with a large amount of data using self‑supervision at scale,
- displays significant generality, and
- is capable of competently performing a wide range of distinct tasks,
- regardless of how it is placed on the market or integrated into downstream systems.
Large generative models—text, image, audio, or video—are expressly contemplated as typical examples of GPAI, including large language models used as the base layer for multiple applications.
Compute Thresholds and Technical Criteria
The European Commission’s GPAI Guidelines further clarify that a model is considered general‑purpose if it exceeds a training compute threshold of approximately 10²³ FLOPs and exhibits functional generality across tasks. Models that exceed the compute threshold but are narrowly specialized (e.g., transcription or image upscaling) may fall outside scope if they lack generality.
For U.S. developers, this means that many foundation models—even where released through APIs rather than as standalone products—are squarely within scope.
- Territorial Reach: Why U.S. Companies Are Directly Affected
The EU AI Act applies extraterritorially. Providers of GPAI models do not need a European presence to be regulated. If a GPAI model is:
- placed on the EU market, or
- integrated into AI systems used in the EU,
its provider is subject to Chapter V obligations.
For U.S. companies supplying models to EU‑based customers, enterprise clients, or application developers, this creates direct compliance exposure similar to—but broader than—the GDPR.
- Timeline for GPAI Obligations
Entry into Application
Obligations for GPAI providers entered into application on 2 August 2025 for:
- GPAI models placed on the market on or after that date.
GPAI models already on the market before that date have a transition period until 2 August 2027 to comply with the new obligations.
Enforcement
While core obligations apply from August 2025, the Commission’s enforcement powers fully activate in August 2026. The European Commission and the EU AI Office have made clear that compliance preparation should not be delayed.
- Baseline Obligations for All GPAI Providers (Article 53)
Article 53 sets out mandatory obligations that apply to every GPAI provider, regardless of model risk level.
5.1 Technical Documentation
GPAI providers must maintain comprehensive technical documentation covering:
- training processes,
- testing and evaluation results,
- known capabilities and limitations.
This documentation must be made available:
- to the EU AI Office and national authorities upon request, and
- in a summarized form to downstream AI system providers, enabling them to comply with their own AI Act obligations.
The level of detail is specified in Annex XI and Annex XII of the AI Act.
5.2 Downstream Transparency Obligations
Providers must supply sufficient information to enable downstream system providers to:
- understand model behavior,
- anticipate risks,
- meet high‑risk AI system obligations if applicable.
This duty applies even where the provider does not control downstream use, reflecting the Act’s supply‑chain governance logic.
5.3 Copyright Compliance Policies
GPAI providers must implement a copyright‑compliance policy addressing:
- EU copyright law,
- reservations of rights under the EU Copyright in the Digital Single Market Directive.
This obligation requires the adoption of state‑of‑the‑art measures to respect rights holders, marking a significant departure from U.S. copyright approaches to training data.
5.4 Public Summary of Training Content
Providers must publish a publicly available summary of the content used to train the GPAI model, using a template issued by the EU AI Office.
While the summary is not required to disclose trade secrets or full datasets, it must be sufficiently detailed to support transparency and accountability. This is one of the most visible compliance obligations and an area of heightened scrutiny by regulators and civil society.
5.5 Cooperation with Authorities
GPAI providers must cooperate with:
- the European Commission,
- the EU AI Office, and
- national competent authorities.
This includes responding to requests for information and participating in regulatory dialogue regarding model risks and mitigation.
- Open‑Source GPAI: Limited but Conditional Exemptions
The AI Act provides narrow exemptions for open‑source GPAI models:
- Certain documentation and disclosure obligations under Article 53 may not apply,
- unless the model is classified as posing systemic risk.
Importantly, “open source” is interpreted narrowly, and the form of release alone does not determine exemption status. Many open‑source foundation models used commercially may still fall within scope, particularly where compute thresholds or downstream integration suggest high impact.
- GPAI Models with Systemic Risk (Articles 51–55)
7.1 What Is Systemic Risk?
A GPAI model is classified as posing systemic risk if:
- it exhibits “high‑impact capabilities” identified through benchmarks or evaluation methodologies, or
- it exceeds a computational training threshold of 10²⁵ FLOPs, creating a presumption of systemic risk.
The European Commission may also designate a model as systemic risk based on emerging evidence, even if thresholds are not met.
7.2 Additional Obligations for Systemic‑Risk GPAI
Providers of systemic‑risk GPAI must comply with enhanced obligations, including:
- Lifecycle‑wide risk assessment and mitigation, addressing foreseeable systemic harms;
- Serious incident reporting, including prompt notification to the Commission;
- Robust cybersecurity safeguards protecting model integrity and misuse;
- Evaluation of model capabilities and emergent risks, including misuse potential.
These obligations are intended to address large‑scale societal risks that cannot be mitigated at the application level alone.
- Notification to the European Commission
Providers of systemic‑risk GPAI models must formally notify the European Commission within a defined timeframe after:
- reasonably foreseeing reaching the systemic‑risk threshold, or
- crossing the compute threshold.
Failure to notify constitutes a standalone compliance failure under the AI Act.
- Codes of Practice (Article 56)
9.1 The General‑Purpose AI Code of Practice
The EU AI Act introduces codes of practice as a core compliance tool. The General‑Purpose AI Code of Practice, published in July 2025, was formally endorsed by the Commission as an adequate voluntary mechanism for demonstrating compliance with GPAI obligations.
The Code includes chapters on:
- transparency,
- copyright, and
- safety and security (for systemic‑risk models).
Providers that sign and implement the Code benefit from:
- reduced administrative burden,
- increased legal certainty,
- a rebuttable presumption of compliance with Articles 53 and 55.
9.2 Strategic Implications for U.S. Businesses
For U.S. organizations, signing the Code of Practice is rapidly emerging as the default compliance pathway, particularly for large model providers with EU exposure.
Non‑signatories remain fully subject to the same legal obligations but must demonstrate compliance through alternative means—often a more resource‑intensive route.
- Interaction with High‑Risk AI Systems and Downstream Liability
GPAI obligations exist alongside, not instead of, high‑risk AI system obligations.
A U.S. company may simultaneously be:
- a GPAI provider under Chapter V, and
- a provider or deployer of high‑risk AI systems under Chapter III.
The Act’s value‑chain approach allocates responsibility at each layer, requiring careful internal mapping of roles, contracts, and information flows.
- Enforcement, Penalties, and Reputational Risk
Non‑compliance with GPAI obligations can trigger:
- administrative fines,
- corrective orders,
- market access restrictions.
For systemic‑risk GPAI providers, penalties can reach up to 7% of global annual turnover, making compliance a board‑level issue for large U.S. technology companies.
- Practical Compliance Steps for U.S. Businesses
U.S. companies developing or distributing GPAI models should be:
- Inventorying models to assess GPAI status.
- Evaluating compute thresholds and systemic‑risk exposure.
- Preparing technical documentation required under Annex XI/XII.
- Drafting and publishing training‑content summaries using the EU template.
- Implementing copyright‑compliance programs.
- Assessing whether to sign the GPAI Code of Practice.
- Establishing governance and incident‑response mechanisms aligned with EU expectations.
Early engagement with compliance is essential due to the phased but binding nature of enforcement.
Conclusion
The EU AI Act’s approach to General‑Purpose AI marks a decisive shift in global AI governance. For the first time, foundation‑model providers face direct, mandatory obligations tied to transparency, copyright, safety, and systemic‑risk mitigation—obligations that apply irrespective of national borders.
For U.S. businesses, GPAI compliance under the EU AI Act is not optional, not theoretical, and not confined to European subsidiaries. It demands strategic planning, technical investment, and legal governance at a global scale.
Those companies that engage early, adopt structured compliance frameworks, and integrate EU requirements into core AI lifecycle management will be far better positioned to operate, innovate, and compete in an AI‑regulated world.
