Direct answerA general-purpose AI model displays significant generality, can competently perform a wide range of distinct tasks and can be integrated into many downstream systems. The EU AI Act imposes model-level duties on GPAI providers, with additional obligations for GPAI models with systemic risk.

Provider and deployer responsibilities

GPAI providerMaintains technical documentation, supplies information to downstream providers, adopts an EU copyright-compliance policy and publishes a sufficiently detailed training-content summary.
Systemic-risk providerAlso evaluates the model, assesses and mitigates systemic risk, tracks and reports serious incidents and provides adequate cybersecurity protection.
Downstream providerUses the model to build or place an AI system on the market and needs sufficient model information to meet system-level duties.
DeployerUses an AI system under its authority and manages obligations created by the actual context of use, including transparency or high-risk duties where applicable.

What organisations using GPAI should evidence

  • The model, provider, version, integration route, use case, users and geography.
  • The documented role of each organisation in the supply chain and the reasoning supporting it.
  • Supplier information on intended uses, limits, evaluation, security, incidents and material changes.
  • System-level risk classification, human oversight, disclosure and monitoring decisions.
  • What happens when the provider changes the model, terms, data practices or safety controls.

A practical role example

A company using a hosted language-model API inside an internal assistant may be a deployer of the resulting system, while the API supplier is the GPAI provider. If the company materially modifies the model, brands and supplies a downstream system or places it on the EU market, additional provider analysis may be needed. Record the actual technical and commercial arrangement instead of assigning roles by job title.

The GPAI Code of Practice

The European Commission’s Code of Practice supports demonstration of compliance with relevant GPAI obligations through chapters on transparency, copyright, and safety and security. It is a compliance tool for providers, not a blanket certificate for every downstream use. Deployers should still conduct supplier due diligence and system-level risk assessment.

Frequently asked questions

What is a GPAI model?

It is a model with significant generality that performs many distinct tasks and can be integrated into a variety of systems.

What must GPAI providers do?

Core duties cover documentation, downstream information, copyright policy and a public training-content summary, with extra duties for systemic-risk models.

What should a business request?

Request model and version information, limits, evaluation and security evidence, incident and change routes, and the provider’s role position.

Does using GPAI make the user a provider?

Usually not, but fine-tuning, relabelling, material modification or supply-chain activity can alter the role analysis.

Map your GPAI role and evidence gaps

Start with the free exposure check or use the GPAI deployer briefing to structure supplier and use-case evidence.

Related guidance

Official sources

Last reviewed 14 August 2026. General information, not legal advice.