GPAI model obligations · enforcement 2 August 2026

GPAI obligations governance: control over generative and in-house AI models

The GPAI model obligations have applied since 2 August 2025, and from 2 August 2026 the Commission gains full enforcement powers with fines up to 3 percent of global turnover or 15 million euro. We map whether you act as a model provider or as an organization that uses generative AI, which obligations follow from that, and how to set this up demonstrably.

GPAI governance

GPAI readiness

From model use to demonstrable GPAI governance

Role determination: model provider or user of generative AI

Test against the Code of Practice and transparency duties

Approach for copyright summary and technical documentation

Action list toward the 2 August 2026 enforcement

Enforcement starts on 2 August 2026

The GPAI model obligations have applied since 2 August 2025, and the final GPAI Code of Practice was published on 10 July 2025. From 2 August 2026 the Commission, through the AI Office, gains full enforcement powers, with fines up to 3 percent of global turnover or 15 million euro. Existing GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to align. The political agreement on the Digital Omnibus does not affect this timeline and is moreover not yet applicable law.

The core of the GPAI model obligations

GPAI models are general-purpose AI models such as large language models and image generators. We test your situation against the main obligations that follow from the AI Act and the Code of Practice.

Technical documentation and model information

Providers of GPAI models record technical documentation about training, capabilities and limitations, and make information available to downstream providers that integrate the model.

Code of Practice as implementation

The GPAI Code of Practice of 10 July 2025 makes the duties practical: transparency, copyright and safety. Signing it helps demonstrate that you fulfill the obligations.

Copyright policy and summary

Providers run a policy to respect EU copyright law and publish a sufficiently detailed summary of the training data used.

Systemic risk for the largest models

GPAI models with systemic risk carry extra duties around risk evaluation, incident reporting and cybersecurity. For most organizations this does not apply, but the test belongs in scope.

Transition period for existing models: GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to fully align. New models fall under the regime immediately. From 2 August 2026 the Commission can enforce, with fines up to 3 percent of global turnover or 15 million euro.

Model provider or user of generative AI

The difference determines which obligations apply to you. We pin down your role precisely per model and per use case.

1

You build or fine-tune your own model

Whoever trains or substantially modifies a GPAI model can become a model provider themselves, with technical documentation, a copyright policy and a training data summary as a result.

2

You use generative AI from a vendor

As a deployer you integrate an external model into your product or process. The heavy model duties sit with the provider, but you carry downstream responsibility and need the model information.

3

The line shifts with fine-tuning

Substantial fine-tuning can legally make you the provider of the modified model. Determining that line in advance prevents you from unintentionally falling into the heavier role.

What the GPAI readiness delivers

Inventory of generative AI and in-house or fine-tuned models within scope

Role determination per model: model provider or deployer of generative AI

Test against the GPAI Code of Practice and the transparency duties

Approach for technical documentation and information to downstream parties

Approach for copyright policy and the training data summary

Downstream checklist for the use of external generative AI

Action list with owner and priority toward 2 August 2026

Note on the transition period for existing models until 2 August 2027

Approach of the GPAI readiness

1

Scope and intake

We define which generative AI, in-house models and fine-tunes fall within the GPAI scope.

2

Role determination

We establish per model and use case whether you act as a model provider or as a deployer of generative AI.

3

Test against the duties

We connect each role to the right obligations from the AI Act and the GPAI Code of Practice.

4

Documentation and policy

We deliver an approach for technical documentation, copyright policy, the training data summary and downstream information.

5

Action list

You get a concrete list of actions, owners and priorities toward the 2 August 2026 enforcement.

Who this works for

Product and engineering

Teams that build, fine-tune or integrate generative AI or in-house models and must secure the duties technically.

Data science and AI

Teams that manage training data, model choices and documentation and must prepare the copyright summary.

Legal, privacy and compliance

Teams that want to record the provider or deployer role legally and translate the obligations into evidence.

Executive and risk

Teams that want to understand the 3 percent fine exposure and steer a manageable GPAI approach.

Afterwards you know

Whether you are model provider or deployer per model

Which GPAI duties apply to you

Which documentation and summary is still missing

Which downstream agreements you need

Which actions must be done before 2 August 2026

Frequently asked questions

What exactly are the GPAI model obligations?

GPAI stands for general-purpose AI: general AI models such as large language models and image generators. Providers of these models record technical documentation, make information available to downstream providers, run a copyright policy and publish a summary of the training data. The duties have applied since 2 August 2025, and the GPAI Code of Practice of 10 July 2025 makes them practically implementable.

What changes on 2 August 2026?

From 2 August 2026 the Commission, through the AI Office, gains full enforcement powers for the GPAI model obligations, with fines up to 3 percent of global turnover or 15 million euro. The obligations themselves have applied since 2 August 2025; from 2026 they can be actively enforced.

Do these duties apply if we only use generative AI?

The heavy model obligations sit with the provider of the GPAI model. If you only use generative AI from a vendor, you are typically a deployer and carry downstream responsibility: you need the model information and must control your own use. Note: substantial fine-tuning can legally make you the provider of the modified model.

What applies to existing models from before August 2025?

GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to fully align with the obligations. New models fall under the regime immediately.

Does the Digital Omnibus change this timeline?

No. The Digital Omnibus mainly affects the high-risk regime and Article 4 on AI literacy, not the GPAI model timeline. Moreover, as of end June 2026 the Omnibus has not yet been formally adopted, so until publication the original AI Act text and timeline remain legally valid.

Is this legal advice?

No. This is a practical governance approach. We structure models, roles, duties and evidence so product, data science, legal and executives can act in a focused way. Legal interpretation of the AI Act is on the Responsible AI Platform; for formal legal advice, involve legal counsel. AI literacy and training is handled by our sister organization LearnWize.

Get a grip on your GPAI obligations before 2 August 2026.

Start with the GPAI readiness. We determine whether you are model provider or deployer, which duties apply and what is still missing toward enforcement.

Rivium Westlaan 46, Capelle aan den IJsselCoC 90283597