See what Trussed catches that your current tool misses, live in your stack

    No migration, no commitment, just a direct comparison in your environment.

    Set up a technical evaluation
    EU AI Act Compliance

    EU AI Act GPAI Compliance: Code of Practice and Enforcement Timeline

    General-purpose AI provider obligations under the EU AI Act (Articles 53 to 56) have been enforceable since 2 August 2025, independent of the 2026 and 2027 deadlines for high-risk AI systems. Compliance teams should treat Annex XI technical documentation and Article 55 evidence requirements as ongoing runtime governance obligations rather than one-time filings.

    Compliance Guide · EU AI Act · GPAI Chapter V

    What GPAI Obligations Require Now

    Regulation (EU) 2024/1689 entered into force on 1 August 2024, but its obligations phase in on a staggered schedule. Prohibited AI practices and AI literacy requirements became applicable on 2 February 2025. Provider obligations for general-purpose AI models under Chapter V, including Articles 53 through 56, along with governance rules and penalty provisions, became applicable on 2 August 2025.

    These GPAI duties are already enforceable and should not be confused with the separate 2 August 2026 deadline for most high-risk AI system obligations, or the 2 August 2027 deadline for high-risk AI embedded in regulated products under Annex I.

    Timeline note

    GPAI obligations under Chapter V are active now. The 2026 and 2027 deadlines apply to high-risk AI systems and are governed by separate articles with different triggers and oversight structures.

    Article 53 requires GPAI providers to maintain technical documentation aligned to Annex XI, covering training and testing methodology, model architecture, and data summaries. This documentation is not a one-time deliverable. It functions as an audit trail that regulators and downstream deployers may request to verify compliance, which means the underlying artifacts, model cards, datasheets, and evaluation logs, need consistent version control and retention practices.

    AI Act Enforcement Milestones

    Date Obligation Governing provision
    1 August 2024 Regulation enters into force Regulation (EU) 2024/1689
    2 February 2025 Prohibited AI practices and AI literacy requirements applicable Chapter II; Article 4
    2 August 2025 GPAI provider obligations, governance rules, and penalty provisions applicable Chapter V, Articles 53 to 56; Article 101
    2 August 2026 Most high-risk AI system obligations applicable Chapter III
    2 August 2027 High-risk AI embedded in regulated products (Annex I) applicable Annex I; Chapter III

    Systemic Risk Thresholds and the Code of Practice

    Article 51(2) presumes a GPAI model carries systemic risk when cumulative training compute exceeds 1025 FLOPs. This threshold acts as a quantitative proxy rather than a fixed definition. The Commission retains authority to add qualitative criteria through delegated acts referencing Annex XIII, which means governance processes should periodically reassess a model's status rather than treat the FLOPs figure as permanent.

    The European Commission's AI Office facilitated a voluntary GPAI Code of Practice organized around three chapters: Transparency, Copyright, and Safety and Security. Signing the Code is voluntary and intended to demonstrate compliance with Articles 53 and 55, but it does not replace the statutory obligations themselves. The Copyright chapter requires documentation of training data provenance policies and rightsholder opt-out mechanisms, a workstream distinct from the safety and security controls covered under Article 55.

    For models presumed to carry systemic risk, Article 55 adds obligations for model evaluation, adversarial testing, systemic risk assessment and mitigation, incident reporting to the AI Office, and cybersecurity protections. These are evidentiary requirements that accumulate over the model's operational life, not documentation produced once at release.

    Code of Practice scope

    The voluntary Code offers a compliance presumption for transparency, copyright, and safety and security obligations. It does not substitute for the underlying statutory requirements under Articles 53 to 56, and non-signatories remain subject to the same duties.

    Mapping Article 55 Evidence to Runtime Controls

    Article 55 obligations for systemic-risk models translate into several categories of ongoing operational evidence that compliance teams must be prepared to produce on request to the AI Office.

    Article 55 obligation Evidence type Operational control
    Model evaluation Evaluation logs, benchmark results, methodology documentation Versioned evaluation runs retained per release
    Adversarial testing Red-team reports, test scope and methodology, findings and mitigations Scheduled adversarial exercises before deployment and after significant updates
    Systemic risk assessment Risk register, mitigation records, residual risk documentation Ongoing risk review cadence tied to model updates and incident signals
    Incident reporting Incident records, timelines, corrective actions reported to AI Office Incident detection and escalation workflow with defined reporting thresholds
    Cybersecurity protections Security controls documentation, access logs, vulnerability management records Model weights and infrastructure access controls with audit logging

    Compliance Readiness Checklist

    The following actions reflect the core readiness steps for teams operating or deploying GPAI models subject to Chapter V obligations.

    • Confirm whether any deployed or fine-tuned model approaches or exceeds the 1025 FLOPs systemic-risk threshold under Article 51(2).
    • Map existing model cards and datasheets against Annex XI technical documentation requirements to identify gaps in coverage or version control.
    • Establish an incident-reporting workflow to the AI Office for any systemic-risk models under Article 55.
    • Track Code of Practice signatory status of upstream GPAI providers to determine which evidence is inherited versus internally generated.
    • Verify internal deadlines reflect that GPAI obligations are active now, separate from the 2026 and 2027 high-risk system deadlines.
    • Review training data provenance documentation and rightsholder opt-out mechanisms to satisfy the Copyright chapter requirements.
    • Confirm that model evaluation, adversarial testing, and cybersecurity controls are documented as ongoing runtime activities rather than one-time release artifacts.

    Governance Structure and Penalty Tiers

    Enforcement authority for GPAI models sits with the Commission's AI Office, while national market surveillance authorities handle other AI Act provisions. This split creates two oversight channels that compliance teams need to track separately rather than assuming a single regulator applies across all AI Act obligations.

    Penalties for GPAI provider infringements can reach up to EUR 15 million or 3% of global annual turnover, whichever is higher, under Article 101. This differs from the broader AI Act penalty tier for high-risk system violations, which can reach EUR 35 million or 7% of turnover. Compliance teams should avoid conflating the two penalty structures when assessing exposure, since GPAI and high-risk obligations are governed by distinct articles with different triggers and timelines.

    Obligation type Penalty ceiling Governing article Oversight authority
    GPAI provider infringement EUR 15 million or 3% of global annual turnover Article 101 Commission AI Office
    High-risk AI system violation EUR 35 million or 7% of global annual turnover Chapter III provisions National market surveillance authorities

    Frequently Asked Questions

    Are GPAI obligations already in force?

    Yes. Provider obligations for general-purpose AI models under Chapter V of the EU AI Act became applicable on 2 August 2025. This is independent of the 2026 deadline for high-risk AI systems and the 2027 deadline for high-risk AI in regulated products.

    Does signing the GPAI Code of Practice replace compliance with Articles 53 to 56?

    No. The Code of Practice is voluntary and offers a presumption of compliance for transparency, copyright, and safety and security obligations. It does not substitute for the statutory requirements. Non-signatories remain subject to the same duties and must demonstrate compliance through other means.

    What triggers the systemic risk designation under Article 51?

    Article 51(2) presumes systemic risk when cumulative training compute exceeds 1025 FLOPs. This is a quantitative presumption, not a fixed definition. The Commission may add qualitative criteria through delegated acts referencing Annex XIII, so governance teams should reassess model status periodically rather than treating the initial determination as permanent.

    Who enforces the GPAI provisions?

    The Commission's AI Office holds enforcement authority for GPAI model obligations. National market surveillance authorities handle other parts of the AI Act, including high-risk AI system provisions. These are separate oversight channels that require distinct compliance tracking.

    What is the penalty for GPAI infringement?

    Under Article 101, penalties for GPAI provider infringements can reach EUR 15 million or 3% of global annual turnover, whichever is higher. This is a different penalty tier from high-risk AI system violations, which carry a ceiling of EUR 35 million or 7% of turnover.

    How should Annex XI documentation be maintained?

    Annex XI technical documentation covers training and testing methodology, model architecture, and data summaries. It functions as an ongoing audit trail rather than a one-time release deliverable. Model cards, datasheets, and evaluation logs should be version-controlled and retained in a form that regulators and downstream deployers can access on request.

    Turn Article 55 Requirements Into Operational Evidence

    Runtime governance and audit logging can help enterprise teams produce the ongoing monitoring and incident-reporting evidence that Article 55 requires, without replacing legal review of your specific obligations.

    Request a Demo