Provider and deployer responsibilities
| GPAI provider | Maintains technical documentation, supplies information to downstream providers, adopts an EU copyright-compliance policy and publishes a sufficiently detailed training-content summary. |
|---|---|
| Systemic-risk provider | Also evaluates the model, assesses and mitigates systemic risk, tracks and reports serious incidents and provides adequate cybersecurity protection. |
| Downstream provider | Uses the model to build or place an AI system on the market and needs sufficient model information to meet system-level duties. |
| Deployer | Uses an AI system under its authority and manages obligations created by the actual context of use, including transparency or high-risk duties where applicable. |
What organisations using GPAI should evidence
- The model, provider, version, integration route, use case, users and geography.
- The documented role of each organisation in the supply chain and the reasoning supporting it.
- Supplier information on intended uses, limits, evaluation, security, incidents and material changes.
- System-level risk classification, human oversight, disclosure and monitoring decisions.
- What happens when the provider changes the model, terms, data practices or safety controls.
A practical role example
A company using a hosted language-model API inside an internal assistant may be a deployer of the resulting system, while the API supplier is the GPAI provider. If the company materially modifies the model, brands and supplies a downstream system or places it on the EU market, additional provider analysis may be needed. Record the actual technical and commercial arrangement instead of assigning roles by job title.
The GPAI Code of Practice
The European Commission’s Code of Practice supports demonstration of compliance with relevant GPAI obligations through chapters on transparency, copyright, and safety and security. It is a compliance tool for providers, not a blanket certificate for every downstream use. Deployers should still conduct supplier due diligence and system-level risk assessment.
Frequently asked questions
What is a GPAI model?
It is a model with significant generality that performs many distinct tasks and can be integrated into a variety of systems.
What must GPAI providers do?
Core duties cover documentation, downstream information, copyright policy and a public training-content summary, with extra duties for systemic-risk models.
What should a business request?
Request model and version information, limits, evaluation and security evidence, incident and change routes, and the provider’s role position.
Does using GPAI make the user a provider?
Usually not, but fine-tuning, relabelling, material modification or supply-chain activity can alter the role analysis.
Map your GPAI role and evidence gaps
Start with the free exposure check or use the GPAI deployer briefing to structure supplier and use-case evidence.
Related guidance
Official sources
Last reviewed 14 August 2026. General information, not legal advice.