DEFINITION
What is GPAI?
The chapter of the AI Act that governs your foundation.
Almost every organisation builds on a model somebody else trained. The AI Act has a separate chapter for that, with two roles and very different obligations. The question is which of the two you are in.
GPAI, in full general-purpose AI, is an AI model trained on vast amounts of data, broadly applicable and used as the basis for a wide range of applications. The EU AI Act deals with these models in a separate chapter, apart from the four familiar risk classes, and places the heaviest obligations on the provider of the model. Organisations using such a model carry lighter obligations, but can become a provider themselves the moment they substantially modify it or release it under their own name. W69 AI Consultancy in Amstelveen maps that division of roles for organisations.
Regulation (EU) 2024/1689, the AI Act. Obligations for providers of general-purpose AI models have applied since 2 August 2025; the Article 50 transparency obligations since 2 August 2026. The 7 per cent ceiling applies to prohibited practices; for other infringements the maxima are lower. Have your own situation reviewed legally.
The part of the AI Act that governs your foundation
Most explanations of the AI Act deal with high-risk use: which risk class does your system fall into. But almost every organisation now builds on top of a model somebody else trained. There is a separate chapter about that, and it is rarely explained.
You are building on somebody else’s model
Nearly every AI system in use runs on a model from a handful of providers. That model is not yours, you do not know its training data and you do not decide when it changes. The legislator wrote separate rules for exactly that, because the risks land downstream.
There are two roles, not one
The regulation distinguishes the provider of a model from the organisation that uses it. Those two carry very different obligations. Which role you are in is not a matter of what you call yourself but of what you do with the model.
You can slide into it unnoticed
If you substantially modify a model, or place it on the market under your own name or brand, you can become a provider yourself. Documentation and information duties then apply that you had not counted on. This is where organisations get into trouble.
Deployer or provider?
On the left what is expected of you when you use a model as it is. On the right what is added the moment you substantially adapt it or release it under your own name.
Four steps to work it out
This is fact-finding, not a legal project. You can establish most of it yourself; only for the last step do you want someone with legal expertise involved.
List the models you use
Not just the models you choose yourself, but also those inside the software you buy. Many organisations use more than they think, hidden in tools acquired as features. Without this list you cannot answer any of the questions.
Keep what the provider gives you
Providers of these models must supply technical documentation, maintain a copyright policy and publish a summary of their training data. Collect it and record it. It is your only evidence that you purchased with due care.
Arrange transparency on your side
Since 2 August 2026 people must know they are dealing with AI, and AI-generated content must be marked in a machine-readable way. That touches almost every organisation, including those with no high-risk use case. Configure it once at platform level rather than per tool.
Establish whether you have become a provider
Fine-tuning, further training or releasing under your own brand can push you into the provider role. Exactly where the line sits between adapting and substantially modifying is a legal question, not a technical one. Get it answered before you roll something out, not after.
What people ask about this
GPAI stands for general-purpose AI: an AI model for general purposes. It is a model trained on vast amounts of data, broadly applicable and used as the basis for all sorts of applications. The large language models nearly everyone builds on fall into this category. The AI Act devotes a separate chapter to them, apart from the familiar four risk classes.
If you use a model as the supplier offers it, you are a deployer: you handle transparency towards your users, oversight, and AI literacy inside your organisation. If you substantially modify the model or place it on the market under your own name or brand, you can become a provider yourself, with documentation and information duties attached. Exactly where that line sits is a legal question.
The obligations for providers of general-purpose AI models have applied since 2 August 2025. The Article 50 transparency obligations, which touch almost every organisation, have applied since 2 August 2026. The remaining obligations are phased in through 2027.
The AI Act has a tiered penalty regime. For prohibited practices it runs up to 35 million euros or 7 per cent of global annual turnover, whichever is higher. For most other infringements, including the obligations around general-purpose AI models, the maximum is lower. The practical risk is usually not the fine but the contract you lose because you cannot answer the buyer’s questions.
Yes, and that is precisely where it goes wrong. Many organisations use more models than they realise, hidden inside tools acquired as features. You remain responsible for transparency towards your own users and for oversight of what those systems do. So start with a list of everything containing AI, including what you did not build yourself.
Do you know which role you are in?
The AI Navigator™ maps where your organisation stands, including which models you use and what the AI Act asks of you as a result.