A large AI model — like the ones behind chatbots or image generators — that is versatile enough to be used in many different applications and products.
A large AI model — like the ones behind chatbots or image generators — that is versatile enough to be used in many different applications and products.
Chapter V of the EU AI Act introduces a distinct regulatory layer for GPAI models. Providers of GPAI models must maintain technical documentation, publish a summary of training content, and comply with EU copyright law. GPAI models presenting systemic risk (training compute above 10²⁵ FLOPs) face additional obligations including adversarial testing, incident reporting, and cybersecurity measures. The GPAI provisions reflect the upstream nature of foundation models: a single model may power thousands of downstream AI systems, amplifying both capabilities and risks.
API providers, open-source model developers, and enterprises fine-tuning foundation models must assess whether their upstream activities trigger GPAI obligations distinct from those applying to downstream deployers.
A general-purpose industrial robot arm that a manufacturer produces and sells to be integrated into assembly lines, medical labs, and logistics warehouses — the robot maker must document capabilities and safety properties because it cannot foresee every application.
A large AI model — like the ones behind chatbots or image generators — that is versatile enough to be used in many different applications and products.
Chapter V of the EU AI Act introduces a distinct regulatory layer for GPAI models. Providers of GPAI models must maintain technical documentation, publish a summary of training content, and comply with EU copyright law. GPAI models presenting systemic risk (training compute above 10²⁵ FLOPs) face additional obligations including adversarial testing, incident reporting, and cybersecurity measures. The GPAI provisions reflect the upstream nature of foundation models: a single model may power thousands of downstream AI systems, amplifying both capabilities and risks.
API providers, open-source model developers, and enterprises fine-tuning foundation models must assess whether their upstream activities trigger GPAI obligations distinct from those applying to downstream deployers.