AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001EU AI Act deep dive · Lesson 5 of 17
General-purpose AI models and the codes of practice
Video lecture
General-purpose AI models and the codes of practice
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 General-purpose AI models
You probably don't train foundation models. So why should you care about the EU's rules for general-purpose AI? Because those rules decide what documentation you can demand from the models under every AI tool you use. And in some cases, building on or fine-tuning a model can create obligations for you. In this lesson, you'll learn what a general-purpose AI model is, what its providers must do, what changes at the systemic-risk level, how the Code of Practice works, and how to use all of it in vendor due diligence.
0:39 Why it matters to you
Why should a marketer or small business owner care about rules for model developers? Three reasons. First, leverage: these rules create documentation, copyright policies and training summaries you can request and compare when choosing vendors. Second, risk: if your content engine sits on a model with unclear copyright practices, that uncertainty flows downstream to your client work. Third, role clarity: understanding where model duties end helps you see exactly which system-level duties are yours, like disclosure, data handling and human review.
1:14 Definitions
A general-purpose AI model is trained on large amounts of data, shows significant generality, and can competently perform a wide range of tasks. Think large language models and big image or video generators. A system built on one, like a chatbot app, is a general-purpose AI system. And a model with high-impact capabilities is a model with systemic risk. The Act presumes that when training compute exceeds ten to the power of twenty-five floating point operations, and the Commission can designate models on other criteria too.
1:51 Analogy: engine and car
Here's an analogy. A general-purpose model is like a powerful engine sold to many car makers. The engine maker must document how the engine performs, what fuel it needs, and its limits, so car makers can build safe cars. If the engine is exceptionally powerful, the maker must also stress-test it and report serious failures. But the car maker is still responsible for the brakes, the seatbelts and the dashboard warnings on their own car. In AI terms, the model provider documents the model; you, building the app, are responsible for how your app behaves with users.
2:33 Duties for all GPAI providers
Every general-purpose model provider has four core duties. Keep technical documentation for the AI Office and authorities. Give downstream providers the information they need to understand capabilities and limits. Have a policy to comply with EU copyright law, including respecting text and data mining opt-outs. And publish a public summary of the content used for training, using the AI Office template. Open-source models with public weights are exempt from the first two, unless they carry systemic risk. The copyright policy and training summary still apply.
3:10 Systemic risk and timing
Systemic-risk models carry more. Their providers must run model evaluations including adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office, and ensure strong cybersecurity. On timing: these obligations have applied since August twenty twenty-five. Models already on the market before then have until August twenty twenty-seven. And the Commission's power to fine providers, up to fifteen million euros or three percent of worldwide turnover, applies from August twenty twenty-six.
3:42 GPAI Code of Practice (July 2025)
Now the Code of Practice. Published in July twenty twenty-five, it's a voluntary tool providers can sign to show compliance. It has three chapters. Transparency, with a model documentation form. Copyright, covering copyright policy, respecting machine-readable opt-outs like robots dot text, and handling complaints. And safety and security, for systemic-risk models. Most major developers signed, some only certain chapters, and some declined. For you, signatory status is a useful data point in due diligence, but not a guarantee. Always check the Commission's current list.
4:19 Could you become a GPAI provider?
Could you become a general-purpose model provider? If you fine-tune or modify a model and place the result on the market, possibly, for the modification. Commission guidelines published in July twenty twenty-five limit modifier duties to the modification and give an indicative compute threshold. A small adapter trained on your brand voice and used internally is unlikely to count. Far more common is building a system on top of a model, like a support chatbot. Then you're a system provider or deployer, and system-level duties like chatbot disclosure are yours, no matter how compliant the model is.
5:01 Worked example: Riyadh fintech
Here's how a fintech in Riyadh picked a model for its marketing assistant. They compared three vendors on five questions. Did they sign the Code of Practice, and which chapters? Is a public training content summary available? How good is the downstream documentation? Is training on customer data off by default? And what data residency options exist? Two vendors passed; one had minimal documentation and unclear data terms. They shortlisted the two and wrote down why they rejected the third. That record becomes evidence for clients and for their own AI policy.
5:41 Example 2: internal brand-voice adapter
A simple example. An agency in Lahore trains a small adapter on top of an open-weight model to write in a client's brand voice, and uses it only internally to draft social posts. Are they now a general-purpose model provider? Very likely not: it's a modest modification used internally, not placed on the market as a model. They document that reasoning in their inventory, keep the model version on record, and apply their normal content review and disclosure rules to the posts. Clear, proportionate, and done in an afternoon.
6:20 Common mistakes
Three mistakes are common here. Assuming open-weight models come with no documentation duties at all, when the copyright policy and training summary still apply to their providers. Treating a model's compliance as covering your whole system, when your chatbot's disclosure and your data handling are your duties. And forgetting that model versions change. Tie your due diligence to specific versions, and review it whenever a vendor upgrades or swaps the model under your tool.
6:52 Watch me do it: model due diligence tab
Watch me do it. I'm adding a tab called Model due diligence. Columns: Tool, Underlying model and version, Provider, Code of Practice status, Training summary link, Downstream documentation, Data terms, Reviewed on. Row one, our chat assistant. I open the vendor's model documentation page and copy the model name and version shown there. Provider: the model developer. I check the Commission's signatory list and note which chapters they signed. I paste the link to the public training content summary. Downstream documentation: link to the model card and usage policy. Data terms: business plan, no training on inputs by contract, thirty-day retention. Row two, the image generator. This one's harder: the vendor doesn't name the underlying model. I write unknown and add an action: email the vendor using the seven-point request from the lesson text. Row three, our internal brand-voice adapter on an open-weight base. I note: modification is small and internal, so we're very likely not a GPAI provider, with the reasoning linked. Finally, I set a review trigger: any model version change reopens the row.
8:09 Recap and next step
Recap. General-purpose model rules bind the model developers, but they give you leverage: documentation, copyright policies, training summaries and incident processes you can request. Systemic-risk models carry extra duties. The Code of Practice is a useful signal, not a guarantee. And building your own app on a model makes the system duties yours. Next step: send the seven-point request in the lesson text to your main model or platform vendor, and file the answers with the model version they apply to.
Why GPAI rules matter to people who don't train models
The obligations for general-purpose AI (GPAI) models in Articles 51 to 56 bind the companies that develop foundation models: OpenAI, Anthropic, Google, Meta, Mistral and others. So why should an agency or SME care? Because these rules determine what documentation and assurances you can demand from the models underneath your tools, and because fine-tuning or building on a model can, in some cases, create obligations for you.
Key definitions
- GPAI model: a model trained with a large amount of data, displaying significant generality and able to competently perform a wide range of distinct tasks, which can be integrated into downstream systems. Large language models and large image or video generation models are the typical examples.
- GPAI system: an AI system based on a GPAI model, such as a chatbot app.
- GPAI model with systemic risk: a model with high-impact capabilities. A model is presumed to have them when the cumulative compute used for training exceeds 10^25 floating-point operations; the Commission can also designate models based on other criteria.
Obligations for all GPAI model providers (Article 53)
- Draw up and keep up to date technical documentation of the model, including training and testing process and evaluation results, for the AI Office and national authorities on request.
- Provide information and documentation to downstream providers who integrate the model, so they understand its capabilities and limitations and can meet their own obligations.
- Put in place a policy to comply with EU copyright law, in particular to identify and respect reservations of rights (opt-outs from text and data mining) expressed under the Copyright Directive.
- Publish a sufficiently detailed public summary of the content used for training, using the template provided by the AI Office.
Providers of models released under free and open-source licenses with publicly available weights are exempt from items 1 and 2, unless the model has systemic risk. Copyright policy and the training summary still apply.
Extra obligations for systemic-risk models (Article 55)
- Perform model evaluations, including adversarial testing (red-teaming).
- Assess and mitigate systemic risks at Union level.
- Track, document and report serious incidents to the AI Office without undue delay.
- Ensure adequate cybersecurity for the model and its physical infrastructure.
Timeline and enforcement
- GPAI obligations have applied since 2 August 2025.
- Models placed on the market before that date must comply by 2 August 2027.
- The Commission's enforcement powers over GPAI providers, including fines up to EUR 15 million or 3% of worldwide turnover, apply from 2 August 2026.
The General-Purpose AI Code of Practice
Published by the Commission on 10 July 2025 after a multi-stakeholder drafting process, the GPAI Code of Practice is a voluntary tool that providers can sign to demonstrate compliance. It has three chapters:
| Chapter | Applies to | Content |
|---|---|---|
| Transparency | All GPAI providers | A model documentation form covering what downstream providers and authorities need |
| Copyright | All GPAI providers | Copyright policy, respecting robots.txt and other machine-readable opt-outs, mitigating infringing outputs, complaint handling |
| Safety and security | Systemic-risk providers | Risk assessment framework, evaluations, incident reporting, cybersecurity |
Most major model developers signed; some signed only certain chapters or declined. Signatory status is a useful due-diligence data point, but not a guarantee. Check the Commission's current list rather than relying on news reports.
When could you become a GPAI provider?
If you fine-tune or modify a GPAI model and place the result on the market, you may become a provider of a GPAI model for the modification. Commission guidelines published in July 2025 explain that obligations for modifiers are generally limited to the modification, and set an indicative compute threshold for when a modification is significant enough to count. For typical business fine-tuning (a small adapter trained on your brand voice and used internally), you are unlikely to be a GPAI provider, but document your reasoning.
Much more common: you build a system on top of a model, for example a customer-support chatbot. You are then the provider (or deployer) of an AI system, not of a GPAI model. Your system-level duties (for example Article 50 transparency) still apply.
Worked example: choosing a model for a Riyadh fintech's marketing assistant
The team compares three model vendors. Due-diligence table:
| Question | Vendor A | Vendor B | Vendor C |
|---|---|---|---|
| Signed GPAI Code of Practice (which chapters)? | All three | Transparency and copyright | Not signed |
| Public training content summary available? | Yes | Yes | Not found |
| Downstream documentation (model card, usage policy, limitations) | Detailed | Detailed | Minimal |
| Data processing terms: training on customer data off by default? | Yes (business tier) | Yes | Unclear |
| Regional data residency options | EU, US | EU, US, Middle East | US |
They shortlist A and B and record why C was rejected. That record is valuable evidence for clients and for their own AI policy.
Hands-on: request list for model and platform vendors
Subject: AI model documentation request (EU AI Act Article 53 / GPAI Code of Practice)
Please provide or link:
1. Model documentation for downstream providers (capabilities, limitations, intended and prohibited uses, evaluation results).
2. The public summary of training content for the model(s) we use.
3. Your copyright policy and how you handle rights reservations and infringing-output complaints.
4. Whether you have signed the GPAI Code of Practice, and which chapters.
5. Whether any model we use is classified as a GPAI model with systemic risk, and a summary of your safety and security framework.
6. Your terms on training with our inputs and outputs, retention periods, and data location.
7. How you notify customers of model deprecations and significant behavior changes.Pitfalls
- Assuming open-weight models come with no documentation duties at all.
- Treating a model's "compliance" as covering your system. Your chatbot's disclosure duty is yours.
- Forgetting that model versions change; tie due diligence to specific model versions and review on upgrades.
Key takeaways
- GPAI providers must keep technical documentation, inform downstream providers, maintain a copyright policy and publish a training content summary.
- Models above 10^25 FLOPs of training compute are presumed to have systemic risk and face evaluation, mitigation, incident and cybersecurity duties.
- GPAI obligations applied from 2 August 2025; legacy models must comply by 2 August 2027; Commission fines apply from 2 August 2026.
- The July 2025 Code of Practice (transparency, copyright, safety and security) is a due-diligence signal; your system-level duties remain yours.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Send the seven-point documentation request to your primary model or AI platform vendor. File the response against the specific model version and set a review reminder for the next model upgrade.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.