The chapter nobody outside the frontier labs read
Since 2 August 2026 the European Commission has been able to fine providers of general-purpose AI models. The obligations are older, applying since 2 August 2025, but Article 113 of Regulation (EU) 2024/1689 held back Article 101, the fining power, for a further year. Most businesses skipped Chapter V on the assumption that it governs a handful of frontier laboratories. That assumption is wrong at the edges, and the edges are where ordinary companies sit.
Article 101 allows fines of up to 3 per cent of total worldwide annual turnover or EUR 15 million, whichever is higher. They can follow not only from breaching the GPAI provisions but from failing to answer a documentation request under Article 91, refusing the AI Office model access for an evaluation under Article 92, or ignoring a measure requested under Article 93.
What is a general-purpose AI model, and who provides one?
A general-purpose AI model displays significant generality, performs a wide range of distinct tasks competently, and can be integrated into downstream systems. The Commission’s guidelines on the scope of GPAI obligations, published on 18 July 2025, give an indicative threshold of 10 to the power of 23 floating point operations of training compute for when a model is likely to qualify. The provider is whoever places it on the market under their own name or trademark. The interesting question for a Swedish business is not whether it trained a model from scratch, but whether what it did to somebody else’s model was enough to inherit the role.
When fine-tuning makes you the provider
The Commission’s guidelines answer this with a threshold rather than a vibe. A downstream party that modifies an existing GPAI model becomes a provider where the modification causes a significant change in the model’s generality, capabilities or systemic risk, and the guidelines state that this is expected to be met where the training compute used for the modification exceeds one third of the compute used to train the original model. Where the original model’s compute is unknown, the fallback is one third of the relevant indicative threshold. The saving grace is proportionality: a modifier that crosses the line is expected to comply only in respect of its own modification, not to document a model it did not build. Routine fine-tuning on a modest dataset sits nowhere near this. A serious continued pre-training run on an open weight model can.
What Article 53 requires of every GPAI provider
Four duties apply to all providers, systemic risk or not. You must keep technical documentation of the model, covering training and testing, in the form set out in Annex XI and make it available to the AI Office on request. You must make information available to downstream providers integrating the model, in the form set out in Annex XII, so they can meet their own obligations. You must put in place a policy to comply with Union copyright law, in particular to identify and respect reservations of rights made under Article 4(3) of Directive (EU) 2019/790. And you must publish a sufficiently detailed summary of the content used for training, following the template the AI Office published on 24 July 2025.
The systemic risk tier, and the Code of Practice
A model is presumed to carry systemic risk where cumulative training compute exceeds 10 to the power of 25 floating point operations. Providers in that tier owe more under Article 55: documented adversarial testing, assessment and mitigation of systemic risks at Union level, serious incident reporting to the AI Office, and adequate cybersecurity. Most Swedish businesses will never reach it. The General-Purpose AI Code of Practice, published on 10 July 2025, is voluntary and functions under Article 56 as a way of demonstrating compliance with Articles 53 and 55.
A worked example
A Swedish company takes an open weight model and runs a substantial continued pre-training job on Nordic language legal and financial text, spending well beyond a third of the compute that produced the base model, then offers the result to customers under its own brand. On the Commission’s guidance it has become a provider of a general-purpose AI model. It owes Annex XI documentation and a public training content summary for what it added, a copyright policy that respects text and data mining reservations in the corpus it used, and Annex XII information to any customer integrating the model.
Change the compute and the answer changes. The same company instead fine-tunes on a few thousand curated examples to adjust tone and format. That is nowhere near a third of the original training compute, no significant change in generality or capability follows, and it remains a downstream deployer with the far lighter obligations that go with it. The compute ratio is doing real legal work here, which is why it belongs in the engineering record and not only in the lawyer’s memory.
Common mistakes
The most common error is assuming Chapter V is somebody else’s problem because your company is not a laboratory. The second is not recording the compute used in a modification, which makes the threshold question unanswerable after the fact. The third is treating an open weight licence as a compliance position, when it governs your relationship with the original developer and says nothing about your duties to the AI Office. The fourth is forgetting Article 111(3), under which models placed on the market before 2 August 2025 must comply by 2 August 2027.
Recommended actions
Identify every model your business has modified rather than merely called through an API, and for each one record what compute the modification consumed and what the base model’s training compute was. Where the ratio is anywhere near a third, get the analysis done before the model ships rather than after. Build the Annex XI and Annex XII material into the engineering workflow, because reconstructing training documentation later is expensive and often impossible. Review the corpus you trained on against text and data mining reservations and write the copyright policy down. Finally, look at what you licence in, because your suppliers’ Chapter V position determines what documentation you can obtain and therefore what you can promise your own customers.
Frequently asked questions
We only call a model through an API, does Chapter V apply to us?
No. Calling a model as a service makes you a downstream deployer, not a provider of a GPAI model. Your obligations sit elsewhere in the Act, principally the transparency duties in Article 50 and, where relevant, the high-risk regime.
Has the AI Office actually fined anyone yet?
Not publicly. The fining power became available on 2 August 2026 and the Commission has signalled that it will open with technical compliance dialogues. At the time of writing no formal proceedings against a named provider had been made public.
Do we have to sign the Code of Practice?
No, it is voluntary. Signing gives a recognised route to demonstrating compliance with Articles 53 and 55 under Article 56. Not signing is lawful but means showing your compliance another way, in more detail, if the AI Office asks.
Conclusion
Chapter V was written with frontier developers in mind, but its boundary is a compute ratio, and open weight models put that boundary within reach of ordinary companies. Since 2 August 2026 the wrong side of it carries a real number. The practical step is unglamorous: measure your modifications and keep the record. At Lawgent, we help companies work out whether what they have built makes them a GPAI provider, assemble the Annex XI and Annex XII documentation if it does, and get the copyright policy and training content summary right. Get in touch if you are modifying models and are not certain which side of the line you are on.