General-purpose AI model
A large AI model, like the ones behind chatbots or image generators, that is versatile enough to be used in many different applications and products.
The Simple Version
A large AI model, like the ones behind chatbots or image generators, that is versatile enough to be used in many different applications and products.
Detailed Explanation
Chapter V of the EU AI Act introduces a distinct regulatory layer for GPAI models. Providers of GPAI models must maintain technical documentation, publish a summary of training content, and comply with EU copyright law. GPAI models presenting systemic risk (training compute above 10²⁵ FLOPs) face additional obligations including adversarial testing, incident reporting, and cybersecurity measures. The GPAI provisions reflect the upstream nature of foundation models: a single model may power thousands of downstream AI systems, amplifying both capabilities and risks.
Key Characteristics
- Defined by general capability, not by a specific task or deployment
- Subject to transparency and copyright-compliance obligations on providers
- GPAI models above the systemic-risk compute threshold face enhanced obligations
- Codes of practice may substitute for direct compliance in certain areas
Why It Matters
API providers, open-source model developers, and enterprises fine-tuning foundation models must assess whether their upstream activities trigger GPAI obligations distinct from those applying to downstream deployers.
Real-World Analogy
A general-purpose industrial robot arm that a manufacturer produces and sells to be integrated into assembly lines, medical labs, and logistics warehouses, the robot maker must document capabilities and safety properties because it cannot foresee every application.
Common Misconceptions
- Open-source GPAI models are fully exempt, open-source providers still face copyright transparency obligations; only systemic-risk obligations are relaxed for open-source models.
- GPAI obligations replace high-risk obligations, providers who subsequently deploy a GPAI model in a high-risk application must meet both GPAI and high-risk requirements.