EU AI Act: What It Actually Requires from General-Purpose AI (GPAI) Model Providers

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~5 minutes

The EU AI Act doesn't just regulate how companies use AI — it also requires specific documentation from whoever builds the model. As of August 2026, that obligation stopped being theoretical: the European Commission can now demand accountability.

The two layers of obligation: all GPAI vs. "systemic risk" models

Article 53 of the EU AI Act applies to every provider of a general-purpose AI (GPAI) model marketed in the EU — from GPT to Claude to Gemini — and requires maintaining up-to-date technical documentation, giving sufficient information to downstream providers integrating the model, publishing a copyright compliance policy, and making public a sufficiently detailed summary of the content used to train the model. Article 55 adds an additional, much stricter layer, only for models classified as "systemic risk."

How a model gets classified as "systemic risk"

Article 51 establishes a presumption: if a model's cumulative training compute exceeds 10²⁵ FLOPs, it's presumed to have high-impact capabilities and therefore systemic risk — it's the yardstick the law uses to identify frontier models without naming specific companies. It's a rebuttable presumption: a provider can present evidence (benchmarks, scaling laws) to argue its model doesn't represent that risk despite crossing the threshold. Anyone who reasonably anticipates reaching the threshold has just two weeks to notify the European Commission.

What extra obligations systemic risk brings

For models that do qualify, Article 55 requires model evaluation including adversarial testing (red teaming), assessment and mitigation of systemic risk across the entire lifecycle, reporting of serious incidents to the EU AI Office, and cybersecurity protection appropriate to the risk level — a list that in practice formalizes what frontier labs were already doing voluntarily (internal evaluations, red teaming, responsible disclosure policies) but now with legal obligation and mandatory reporting.

The Code of Practice: the voluntary path to compliance

The European Commission published the GPAI Code of Practice on July 10, 2025, built with close to 1,000 participants from industry, civil society, and academia. It's voluntary, but functions as the "safe" compliance path: a provider that signs onto the Code and complies with it has a clear way to demonstrate conformity, instead of having to interpret the law article by article. It's organized into three chapters: transparency, copyright, and safety and security — all three signed by most of the relevant frontier labs.

Why August 2026 is the date that actually matters

The Article 53 and 55 obligations came into application on August 2, 2025 — but the Commission gave itself a one-year grace period before actively demanding compliance. As of August 2, 2026, the Commission can now initiate real enforcement actions: requests for information, access to models for evaluation, and in extreme cases, market withdrawal. The sanctions regime is the same as for the rest of the law: up to €15 million or 3% of the company's global annual turnover, whichever is higher.

What it means for companies building on top of these models

None of these obligations fall directly on the company consuming OpenAI's, Anthropic's, or Google's API to build a product — they fall on the model provider. But indirectly, it does matter: the technical documentation and training-data summaries that are now mandatory are, for the first time, a public and auditable source for assessing the risk of depending on a specific model in a regulated architecture (healthcare, finance, public sector). It's worth reviewing that documentation as part of any AI vendor due-diligence process, rather than relying solely on brand reputation.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com