Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
EUDEEP coverage1 enforcement action

EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice: AI Compliance Requirements

As of August 2, 2025, the EU AI Act's obligations for General-Purpose AI (GPAI) model providers and deployers are in full effect (Chapter V, Articles 50-55). Organizations that integrate GPAI models (LLMs, image generators, multimodal AI) into their products must maintain technical documentation, implement copyright compliance policies, publish training data transparency summaries, and disclose AI-generated content to users. Providers of GPAI models with systemic risk (trained with >10²⁵ FLOPs) must conduct adversarial testing and report serious incidents.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

August 2, 2025

Maximum Penalty

€15,000,000 or 3% of global annual turnover (for GPAI model provider violations)

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

AI-Generated Content Disclosure (Art. 50)

Critical

When deploying GPAI models (ChatGPT, Claude, Gemini, Copilot, etc.) to generate content for end users, implement technical solutions to mark outputs as AI-generated (watermarking, metadata, disclosure notices). Users must be informed they are interacting with AI-generated content.

Deadline: August 2, 2025

Art. 50

GPAI Technical Documentation (Art. 53 + Annex XI)

High Priority

Maintain technical documentation covering: the GPAI models used in your products, their intended use cases, known limitations, testing results, and how they were evaluated for safety. Keep this documentation updated when models are changed. For deployers: maintain records of which GPAI model versions your product uses and update documentation when upgrading.

Deadline: August 2, 2025

Art. 53, Annex XI

Systemic Risk Model Obligations (Art. 51-55)

High Priority

If your product deploys GPAI models trained with >10²⁵ FLOPs (GPT-4, Gemini Ultra, Claude 3 Opus-class and above): (1) Register with the EU AI Office as a systemic risk model deployer; (2) Conduct adversarial testing (red-teaming) before deployment and after major model updates; (3) Implement serious incident reporting to the EU AI Office within 72 hours of discovering a serious incident (harm to persons, critical infrastructure impact, large-scale misinformation events); (4) Implement cybersecurity measures commensurate with systemic risk. GPAI Code of Practice (final, published 2025-07-10) participation creates a rebuttable presumption of compliance, not an absolute safe harbor — and does not apply to non-signatories such as Meta.

Deadline: August 2, 2025

Art. 51-55

Copyright Compliance Policy for AI Training (Art. 53(1)(c))

Medium Priority

If you train or fine-tune AI models, implement and document a policy for complying with EU copyright law, including opt-out mechanisms for rights holders under the Text and Data Mining exception (DSM Directive Article 4). Publish a summary of training data sources.

Deadline: August 2, 2025

Art. 53(1)(c)

GPAI Code of Practice Alignment (EU AI Office)

Medium Priority

The EU AI Office published the final GPAI Code of Practice on 2025-07-10. Participation is voluntary but creates a rebuttable presumption of compliance with Art. 51-55 obligations. Key CoP requirements: (1) Model capability disclosures (model cards); (2) Safety benchmarks publication; (3) Copyright policy transparency; (4) Incident reporting procedures. As of June 2026 roughly 24 organizations had signed (Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, among others) — Meta explicitly declined (2025-07-18). For deployers using a NON-signatory provider (e.g. Meta), the presumption does not apply and full independent compliance documentation is needed.

Art. 56 (Codes of Practice)

Who Does This Apply To?

The GPAI provisions create a two-tier compliance structure. Tier 1 — GPAI Model Providers: organizations that train or fine-tune foundation models (LLMs, multimodal models) and make them available to downstream integrators via API or open weights. Providers must maintain full technical documentation (Annex XI) and publish model cards. Tier 2 — GPAI Deployers (Downstream Integrators): businesses that use GPAI model APIs (OpenAI, Anthropic, Google, Mistral) to build products and services. Deployers inherit the disclosure obligation (Art. 50) and must ensure their product-level documentation references the underlying GPAI model. Key distinction: pure deployers using third-party GPAI APIs are NOT the GPAI "provider" — they are downstream users with lighter obligations unless they fine-tune the model (in which case they become a provider for their fine-tuned variant). Systemic risk threshold: GPAI models trained with >10²⁵ FLOPs trigger Article 51-55 enhanced obligations regardless of whether the organization is a provider or deployer of the specific model. Open-source GPAI models below the systemic risk threshold benefit from an exemption from technical documentation and copyright requirements but NOT from prohibited AI rules.

Recent Enforcement Actions

2025-07-18Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2025-07

EU AI Office GPAI Code of Practice — Final Version (2025)

The EU AI Office published the final GPAI Code of Practice on 2025-07-10, covering: (1) Transparency obligations — model cards with capability disclosures, training data summaries, known limitations, benchmark results; (2) Copyright compliance — acceptable TDM opt-out procedures, training data source documentation standards; (3) Systemic risk safety — adversarial testing protocols, red-team methodology standards, incident classification criteria; (4) Incident reporting — 72-hour initial notification, 30-day full report format. Participation creates a rebuttable presumption of compliance (not a full legal safe harbor) with Art. 51-55 obligations. Cycle 8 (2026-08-22) CORRECTION: the prior text claimed "OpenAI, Anthropic, Google DeepMind, Mistral, and Meta have confirmed participation" — verified this cycle that Meta explicitly DECLINED to sign (2025-07-18, Joel Kaplan statement); roughly 24 organizations had signed as of June 2026, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, and Aleph Alpha. Deployers using CoP-signatory providers can reference that participation in their own compliance documentation; deployers using Meta's models cannot.

guidance2025-11

EU AI Office Guidance: Deployer vs. Provider Obligations Under Art. 50-55 (November 2025)

Guidance clarifying deployer obligations for GPAI: (1) Deployers who use GPAI APIs without fine-tuning are NOT GPAI providers — they are "deployers" with Art. 50 disclosure obligations only; (2) Fine-tuning (even minor) makes the deployer a provider for their fine-tuned model — full Annex XI documentation required; (3) Deployers must maintain their own deployment documentation covering: which GPAI model is used, for what purpose, what safeguards are applied, how users are informed of AI-generated content. Guidance includes a practical checklist for B2B SaaS companies using GPAI APIs.

Key Case Law & Precedent

Robert Kneschke v. LAION e.V. (Hamburg Regional Court, Case No. 310 O 227/23, 2024)

· 2024

Outcome: First instance (2024): claim dismissed — use permitted under the §60d scientific-research TDM exception. Confirmed on appeal (OLG Hamburg, Dec 2025).

Case reference

Quarterly Enforcement Digest

Q3 2026: GPAI substantive obligations have been in force since August 2, 2025, but the Commission's actual enforcement powers (audits, fines up to €15M/3% turnover, corrective orders) only became legally active 2026-08-02 — this cycle corrected two uncorroborated "formal inquiry"/"classification" enforcement claims from 2025 that predated real enforcement power and had no independent source. Real, verified developments: Meta declined to sign the GPAI Code of Practice (2025-07-18) and so gets no rebuttable-compliance presumption for LLaMA; ~24 organizations had signed by June 2026 (Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, among others). Models placed on the market before 2025-08-02 (including GPT-4o and LLaMA 3.1) have an extended compliance deadline of 2027-08-02. Hamburg copyright precedent (Kneschke v. LAION) remains the most concrete GPAI-adjacent legal precedent, confirmed on appeal Dec 2025. For Aegis Firma: GPAI obligations apply whenever a customer's AI system uses a foundation model to generate content for EU users — the platform should prompt customers to document which GPAI models they use, whether that provider signed the CoP, and ensure Art. 50 content-disclosure mechanisms are in place.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice

These industry playbooks include jurisdiction-specific checklist items and guidance for EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice.

Frequently Asked Questions

Does EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice apply to my business?

As of August 2, 2025, the EU AI Act's obligations for General-Purpose AI (GPAI) model providers and deployers are in full effect (Chapter V, Articles 50-55). Organizations that integrate GPAI models (LLMs, image generators, multimodal AI) into their… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice is: €15,000,000 or 3% of global annual turnover (for GPAI model provider violations). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with EU AI Act — General-Purpose AI (GPAI) Obligations (Art. 50-55) + GPAI Code of Practice?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan