AI Guide

General-Purpose AI Model (GPAI): The EU AI Act's category for foundation-scale models

A General-Purpose AI Model (GPAI) is the EU AI Act's legal category for AI models that display significant generality and can perform a wide range of distinct tasks across downstream applications. GPT-4-class systems, Gemini, Claude, and Llama all qualify, and their providers have faced binding obligations since 2 August 2025. This article explains how GPAI is defined and classified, what the systemic-risk tier requires, and what German Mittelstand companies must check before they build products on top of one.

Key Facts
  • GPAI obligations under EU AI Act Articles 51 to 56 have applied since 2 August 2025.
  • A GPAI model is presumed to carry systemic risk once training compute exceeds 10^25 floating-point operations (FLOPs).
  • The European Commission's AI Office gains full enforcement and fining powers over GPAI providers on 2 August 2026.
  • GPAI providers face fines of up to 15 million euros or 3% of global annual turnover for non-compliance.
  • Bitkom's 2024 survey found close to three in four German companies already use generative AI tools such as ChatGPT, nearly all built on third-party GPAI models.

Definition: General-Purpose AI Model (GPAI)

A General-Purpose AI Model (GPAI) is an AI model trained on broad data at scale that displays significant generality and can competently perform a wide range of distinct tasks, regardless of how it is placed on the market.

Core characteristics of General-Purpose AI Model (GPAI)

GPAI is a legal classification created by the EU AI Act, not a technical architecture. Any provider that trains a model meeting this description takes on obligations once the model is placed on the EU market.

  • Trained on broad datasets rather than a single narrow task
  • Capable of being integrated into many downstream applications
  • Typically a large-scale large language model
  • Regulated at model level, separate from any high-risk use case built on top

General-Purpose AI Model (GPAI) vs. Foundation Model

“Foundation model” is an industry term for any model trained on broad data that can be adapted to many tasks. GPAI is the narrower legal term the EU AI Act uses to trigger obligations: transparency documentation, copyright compliance, and, above a compute threshold, systemic-risk controls. Every GPAI model is a foundation model technically, but not every foundation model automatically counts as GPAI.

Importance of GPAI in enterprise AI

Nearly every enterprise AI deployment sits on a GPAI model accessed via API rather than a custom-trained system. Bitkom’s 2024 survey found close to three in four German companies already use generative AI tools such as ChatGPT, virtually all powered by third-party GPAI models, which makes GPAI compliance a procurement question for nearly every company building on AI.

Methods and procedures for GPAI

Three structured checks determine what obligations apply to a GPAI model and its deployers.

Systemic-risk classification

The EU AI Act presumes a GPAI model carries systemic risk once cumulative training compute exceeds 10^25 FLOPs, a threshold current frontier models from OpenAI, Google, Anthropic, and Meta already cross.

  • Check the provider’s technical documentation for compute figures
  • Confirm formal systemic-risk designation under the EU AI Act
  • Flag in-house fine-tuning that could push a model past the threshold

Provider documentation review

Every GPAI provider must publish a model card, a training-data summary, and technical documentation sufficient for deployers to understand capabilities and limitations. Reviewing this before procurement is now standard practice, alongside the conformity assessment required for systems built on the model. Missing documentation is increasingly treated as a disqualifying vendor signal.

Downstream obligation mapping

Deploying a GPAI model inside a high-risk AI system, such as one used in hiring, adds obligations on top of the provider’s duties. Mapping which use cases sit on GPAI, and which qualify as high-risk, determines whether a company needs its own conformity assessment.

Important KPIs for GPAI

Tracking GPAI exposure requires operational, strategic, and quality indicators.

Vendor compliance tracking

  • Documentation coverage: share of GPAI vendors with published technical documentation on file
  • Systemic-risk flags: number of in-use models above the 10^25 FLOP threshold
  • Contract review completion: share of GPAI vendor contracts reviewed for Act obligations

Strategic exposure

Gartner projects more than 80% of enterprises will have used generative AI APIs or GenAI-enabled applications by 2026, up from under 5% in 2023, so GPAI vendor risk now touches nearly every department. Tracking how many business units depend on a single provider gives leadership a concentration-risk figure for board reporting.

Output quality and drift

Because GPAI models update over time, output behavior can shift without a company changing anything on its side. Regular sampling of outputs against a fixed test set catches silent drift before it reaches customers or regulators.

Risk factors and controls for GPAI

Undocumented high-risk use

Deploying a GPAI model for a use case the provider has not documented, such as automated candidate screening, shifts compliance responsibility onto the deployer.

  • Confirm intended use scope in provider documentation before deployment
  • Log any use case that extends beyond documented scope
  • Require legal sign-off before repurposing a model for a new department

Systemic-risk provider dependency

Relying on a single systemic-risk GPAI provider concentrates technical and regulatory exposure. If that provider faces enforcement action or withdraws a model version, downstream applications can break with little notice. Multi-model architectures that can swap providers reduce this single point of failure.

GPAI providers must summarize training data and respect EU copyright law, but training-data disputes are still being litigated internationally. Companies building customer-facing products on a GPAI model should track the provider’s copyright indemnification terms, since liability language varies between vendors.

Practical example

A 140-employee precision-tooling manufacturer in Baden-Württemberg wanted an AI assistant to draft technical responses to customer RFQs based on historical quotes. Before selecting a vendor, the IT lead ran a GPAI documentation check across three candidate providers and found only one had published a complete model card covering training data scope and systemic-risk status. The company mapped the assistant against the EU AI Act’s risk tiers and confirmed the use case fell outside high-risk categories.

  • GPAI vendor shortlist filtered to providers with complete documentation
  • Written record confirming the quoting assistant is not high-risk
  • Quarterly review process for tracking provider risk-designation changes
  • Fallback provider identified in case the primary model is withdrawn

Current developments and effects

Enforcement of GPAI rules is entering its active phase in 2026.

Code of Practice adoption

Major providers signed the voluntary GPAI Code of Practice published in mid-2025 to demonstrate compliance ahead of binding enforcement.

  • Signatories gain a presumption of conformity for transparency obligations
  • Non-signatories must demonstrate compliance through other documented means
  • The Commission is expected to update the Code as case law develops

Commission enforcement powers activate

The European Commission’s AI Office gains full investigative and fining powers over GPAI providers on 2 August 2026, a year after the obligations took effect. The first enforcement actions and clarifying guidance are expected shortly after that date.

Digital Omnibus adjustments

The Digital Omnibus proposal under review in 2026 includes targeted adjustments to GPAI documentation burdens for smaller downstream deployers, though core provider obligations for systemic-risk models remain unchanged in current drafts.

Conclusion

GPAI has moved from a niche legal definition to a procurement checklist item for nearly every company building on AI. The obligations that took effect in August 2025 already apply, and Commission enforcement powers activate in August 2026, narrowing the window for Mittelstand companies to verify vendor documentation before it becomes an audit finding. Treating GPAI compliance as part of standard AI vendor evaluation, alongside AI governance, avoids the scramble reactive compliance programs face. Companies that build this checking discipline now will procure AI faster and with less legal exposure once enforcement intensifies.

Frequently Asked Questions

What counts as a General-Purpose AI Model under the EU AI Act?

Any AI model trained on broad data that displays significant generality and can perform a wide range of distinct tasks across many downstream applications. GPT-4-class systems, Gemini, Claude, and Llama all qualify, whether accessed via API or run on a company’s own infrastructure.

Does a small Mittelstand company have direct GPAI obligations?

Usually not as a provider. Most Mittelstand companies are deployers accessing GPAI models through a vendor’s API, which places core documentation and systemic-risk obligations on the provider, though deployers must still confirm their use case matches the documented scope.

How does GPAI relate to the EU AI Act’s risk tiers?

GPAI is regulated separately from the Act’s four risk tiers for AI systems; a GPAI model itself is not classified as minimal, limited, or high-risk. A company can still build a high-risk AI system on top of a GPAI model, which triggers system-level obligations on top of the model-level ones.

What does GPAI compliance cost a company with under 250 employees?

For deployers, the direct cost is mainly staff time spent reviewing vendor documentation and confirming use-case scope. This typically takes a few days of legal and IT time per vendor, since the heavier documentation obligations sit with the provider, not the deployer.

How long does it take to set up a GPAI vendor review process?

A basic review covering documentation checks, systemic-risk tracking, and use-case mapping can be running within two to four weeks for a company with a handful of AI vendors. The main effort is mapping use cases against provider documentation.

Is there funding available to help with EU AI Act compliance work?

Some German state and federal digitalization programs, administered through KfW and regional Wirtschaftsförderung agencies, cover consulting costs related to regulatory compliance, including AI Act readiness work. Eligibility varies by program and company size.

Building better software Contact us together