Why general-purpose AI now has its own rulebook
Most businesses do not build artificial intelligence from scratch. They buy access to a large model – a chatbot, a coding assistant, an image generator – and put it to work. The EU AI Act calls the technology behind these tools general-purpose AI (GPAI), and since 2 August 2025 the providers of these models have had to follow a dedicated set of rules. For companies that deploy such models, understanding what the provider must do – and what they in turn must document – has become part of ordinary compliance.
What counts as a general-purpose AI model
A general-purpose AI model is one trained on a large amount of data that can perform a wide range of tasks and be integrated into many different applications. Foundation models that power well-known assistants fall squarely within the definition. The obligations sit primarily with the provider that develops and places the model on the market, not with every business that uses it. But once you fine-tune or substantially modify a model, you may step into the provider role yourself.
The obligations that apply from August 2025
Providers of general-purpose AI models must draw up and keep technical documentation, provide information and documentation to businesses that integrate the model, put in place a policy to respect EU copyright law, and publish a sufficiently detailed summary of the content used for training. These duties took effect on 2 August 2025. Models already on the market before that date have until 2 August 2027 to come into full compliance.
Models with systemic risk face stricter duties
The most capable models – those that could pose systemic risk – carry additional obligations, including model evaluation, adversarial testing, tracking and reporting of serious incidents, and cybersecurity protection. These duties reflect the greater potential impact of the largest models and are supervised by the European Commission’s AI Office.
The GPAI Code of Practice
To help providers meet their obligations, the AI Office published the final General-Purpose AI Code of Practice on 10 July 2025, endorsed by the Commission and Member States on 1 August 2025. The Code is voluntary but offers a practical route to demonstrating compliance across three chapters: transparency, copyright, and safety and security. Signing up signals good faith and eases cooperation with the AI Office.
Practical example
A Swedish software company builds a customer-service assistant on top of a third-party foundation model. As a deployer it is not the model provider, but it should obtain the provider’s technical documentation, confirm the copyright and training-data summary are in place, and keep its own records of how the tool is used. If the company later fine-tunes the model on its own data in a way that significantly changes it, it may itself become a provider – and inherit the corresponding obligations.
Common mistakes companies make
The most frequent error is assuming the rules only apply to large technology firms. In practice, buyers of AI tools need the provider’s documentation to run their own risk assessments and to comply with the broader AI Act obligations that apply to high-risk uses. A second mistake is ignoring the copyright dimension – using a model whose training data was gathered unlawfully can create downstream exposure. A third is missing the point at which fine-tuning turns a deployer into a provider.
Recommended actions
Map which AI tools your organisation uses and identify the underlying models. Ask each provider for the technical documentation, copyright policy and training-data summary. Check whether any provider has signed the Code of Practice. Assess whether your own use qualifies as high-risk under the AI Act, and record your reasoning. Finally, set a review point before 2 August 2026, when the Commission’s enforcement powers – and fines of up to 3% of global turnover or €15 million – take effect.
Frequently asked questions
Does my company have to comply if we only use ChatGPT-style tools?
The GPAI obligations fall on the provider, but as a user you should obtain and retain the provider’s documentation and assess your own use against the AI Act’s wider rules.
When can the Commission start issuing fines?
Enforcement powers over general-purpose AI providers apply from 2 August 2026, with penalties up to 3% of worldwide annual turnover or €15 million, whichever is higher.
Is the Code of Practice mandatory?
No. It is voluntary, but adhering to it is the simplest way for providers to show they meet their transparency, copyright and safety duties.
Conclusion
General-purpose AI is now a regulated category, and the obligations ripple out from model providers to every business that builds on them. Knowing what to demand from your provider – and when your own use crosses a line – is the practical core of compliance. Lawgent helps companies map their AI use, review provider documentation and prepare for the AI Act’s coming enforcement milestones. Get in touch to make sure your AI adoption rests on solid legal ground.