EU AI Act GPAI Rules: Duties, Risk Thresholds & Fines

The EU's general-purpose AI rules took effect on August 2, 2025, requiring model documentation, training-content summaries and copyright policies.

What counts as a general-purpose AI model, and what took effect

The AI Act defines a general-purpose AI model by training scale and function rather than by product category: a model trained on more than 10^23 floating-point operations that can perform a wide range of tasks and be integrated into downstream systems, most obviously large language models. Three obligations under Article 53 became binding on August 2, 2025: providers must maintain technical documentation of the model and its testing, give downstream developers information needed to integrate it, and put in place a copyright policy that respects EU copyright law, including the reservations rightsholders can register under the Digital Single Market Directive's text-and-data-mining exception. [1][6]

A fourth obligation, publishing a public summary of training content, has a specific tool behind it: the European Commission released a mandatory template on July 24, 2025, structured in three parts covering model identification and modalities, a list of data sources including web-scraped domains and licensed or synthetic data, and a data-processing section describing copyright compliance and content-moderation steps. The obligation to publish under this template also started August 2, 2025, and it applies to open-source model providers as well, unlike the technical-documentation duty, which open-source providers are exempted from unless their model is designated as carrying systemic risk. [7][6]

The systemic-risk threshold and what it adds

A model is presumed to carry systemic risk if it was trained using more than 10^25 floating-point operations of compute, roughly two orders of magnitude above the baseline GPAI threshold. The Commission can also designate a model below that line if evidence points to comparable capability. Providers of a systemic-risk model take on obligations beyond the baseline four: they must evaluate the model against standardized protocols, assess and mitigate systemic risks, report serious incidents to the AI Office, and maintain adequate cybersecurity protections, and they must notify the Commission before or without undue delay after the training run crosses the threshold. [1][3]

Atlas interpretation: The 10^25 FLOP line is a scale filter, not a capability test: it catches models built by the handful of organizations with the compute budgets to train at that size, currently on the order of a dozen or so labs worldwide, while leaving the much larger population of GPAI providers under Article 53's lighter, documentation-and-transparency regime. That is a deliberate compute-as-proxy design choice, and it means the extra obligations track training spend rather than anything measured about what the resulting model can actually do. [3]

The Code of Practice, and who did not sign it

The GPAI Code of Practice is a voluntary document the Commission endorsed and the AI Board approved in July 2025, with signatories published August 1, 2025, a day before the statutory obligations took effect. It has three chapters: transparency and copyright, open to every GPAI provider, and a safety-and-security chapter that applies only to systemic-risk model providers. Signing does not create a new legal duty; it creates a presumption of conformity with Article 53 and, for the safety chapter, Article 55, so the Commission's enforcement attention on a signatory concentrates on whether it is following its own Code commitments rather than on requiring the provider to demonstrate compliance by other means. [3][5]

OpenAI, Microsoft, Google, Anthropic, Amazon and Mistral AI were among the early signatories. Meta declined. Its chief global affairs officer, Joel Kaplan, said on July 18, 2025 that the Code introduces legal uncertainties that go beyond the AI Act's own text and would "throttle the development and deployment of frontier AI models in Europe." Reporting into 2026 continued to describe Meta as the most notable holdout among major Western labs, alongside China-based model developers that are not represented among the signatories at all. Declining to sign does not exempt Meta from Article 53; it means Meta has to satisfy the Commission of its compliance directly rather than by pointing to Code adherence. [4]

When enforcement actually has teeth

The August 2, 2025 obligations were binding from that date, but the Commission's power to investigate GPAI providers and issue fines under Article 101 did not start until a year later, August 2, 2026. Article 101 caps fines for GPAI infringements at 3% of a provider's global annual turnover or 15 million euros, whichever is higher, for negligent or intentional violations of the Article 53-55 obligations, supplying misleading information, or failing to cooperate with an AI Office evaluation. That is a materially lower ceiling than the up to 7% or 35 million euro fines the Act allows for prohibited practices such as social scoring. [6][5]

Atlas interpretation: The summary's grandfathering point is really two separate delays stacked on top of each other: a model already on the market before August 2, 2025 gets until August 2, 2027 to come into compliance at all, and even a brand-new model launched the day the rules applied could not actually be fined for noncompliance before August 2, 2026. A law that starts applying on paper in August 2025 and cannot be enforced with money on the table until a year later, with the largest population of existing models exempted for two full years, is a law that arrives in installments by design, not by drift. [6][2]

Industry pushback and the 2026 simplification package

Ahead of the August 2025 start date, a number of companies, including Alphabet and Microsoft, had pushed the Commission to delay the GPAI rules; the Commission declined and kept the date. Nearly a year later, the EU adopted a broader deregulatory package, the Digital Omnibus on AI, published in the Official Journal on July 24, 2026 and applying from July 27, 2026. Its major changes deferred deadlines for high-risk AI systems, standalone systems from August 2026 to December 2027 and embedded systems to August 2028, extended the deadline for AI-content watermarking under Article 50, and created new prohibitions covering AI-generated child sexual abuse material and non-consensual intimate imagery. [4][6]

Atlas interpretation: The Digital Omnibus targeted the Act's high-risk-system track, not the general-purpose-model obligations described here. Nothing in the reporting on the package changes the August 2025 start date, the training-data-summary duty, the copyright-policy requirement, or the August 2027 grandfathering deadline for GPAI providers; the political pressure that produced a two-year deferral for high-risk systems did not extend to rolling back what had already applied to model providers for nearly a year. [6]

Sources

  1. EU rules on general-purpose AI models start to apply, bringing more transparency, safety and accountability

    European Commission · Aug 1, 2025

  2. Implementation Timeline

    EU Artificial Intelligence Act

  3. An Introduction to the Code of Practice for General-Purpose AI

    EU Artificial Intelligence Act · Sep 8, 2026

  4. Meta refuses to sign EU's AI code of practice

    TechCrunch · Jul 18, 2025

  5. Article 101: Fines for Providers of General-Purpose AI Models

    EU Artificial Intelligence Act · Sep 8, 2026

  6. EU AI Act News: Digital Omnibus on AI, New Guidance on Risk Classification, GPAI, and Transparency Obligations

    Mayer Brown · Jul 31, 2026

  7. European Commission Releases Mandatory Template for Public Disclosure of AI Training Data

    WilmerHale · Aug 13, 2025