SkarpSkarp

Chapter 7 of 11

General-Purpose and Foundation Models: New Duties for the AI Stack

Foundation models and general-purpose AI sit underneath many applications; uncover the special rules the EU AI Act creates for these models and how they ripple through the AI supply chain.

15 min readen

Step 1 – Why General-Purpose AI Has Its Own Rules

Why GPAI Gets Special Rules

The EU AI Act adds special rules for general-purpose AI and foundation models because they sit at the bottom of the AI stack and can be reused across many applications.

Beyond Providers and Deployers

You already know providers place AI systems on the EU market and deployers use them. GPAI models complicate this because one model can power hundreds of different apps, some high-risk.

New Focus: The AI Stack

The Act now targets: providers of GPAI models, including foundation models, and downstream providers and deployers who fine-tune, integrate, or rely on those models.

What You Will Learn

You will learn how the Act defines GPAI, what systemic risk is, the core and extra obligations for GPAI providers, and how these rules affect downstream businesses.

Step 2 – What Is a General-Purpose AI Model Under the EU AI Act?

Defining GPAI Models

A general-purpose AI model is trained on broad data at scale, can perform a wide range of tasks, and can be integrated into many downstream systems or apps.

Foundation Models and More

This includes many large language models and multimodal foundation models. The law focuses on the model itself, not only the final application.

Open vs Proprietary

Both open-source and proprietary models can be GPAI. The key is general-purpose capability and broad reusability, not the license model.

Who Is the Provider?

You are a GPAI provider if you develop and place a GPAI model on the EU market, or substantially modify such a model and release it under your own name.

Provider vs Deployer

If you only use a GPAI model internally or embed it in products without offering the model itself, you are typically a deployer or provider of an AI system, not a GPAI model provider.

Step 3 – Systemic Risk: When a GPAI Model Triggers Stricter Rules

What Is Systemic Risk?

Systemic-risk GPAI models are so powerful, widely used, or potentially harmful that failures in one model can affect many sectors and users across the AI ecosystem.

How Risk Is Determined

Systemic risk is based on quantitative thresholds, such as very large compute for training, and qualitative assessments of capabilities and deployment scale.

Types of Harms Considered

Authorities look at potential impacts on health and safety, fundamental rights, the environment, democracy, and the rule of law.

Who Makes the Call?

The European Commission and the AI Office identify systemic-risk models and can require providers to self-assess and notify if they reach the thresholds.

Why It Matters

Once a model is classified as systemic-risk GPAI, its provider must follow stricter rules, in addition to the baseline obligations for all GPAI models.

Step 4 – Core Obligations for All GPAI Model Providers

Baseline Duties for All GPAI Providers

All GPAI providers placing models on the EU market must meet baseline obligations on documentation, transparency, copyright, and safety, regardless of systemic risk.

Technical Documentation

Providers must document model architecture, training, capabilities, limitations, foreseeable misuse, and evaluation methods, and share this with authorities and downstream users.

Supporting Downstream Users

Model cards, API docs, and policies must give downstream providers enough information to integrate the model safely and perform their own risk assessments.

Copyright and Training Data

Providers must respect EU copyright in training and publish a meaningful summary of training data sources and categories, not necessarily the full dataset.

Safety and Security Policies

Providers must maintain policies to identify and mitigate risks, and protect against security threats like model theft, tampering, or malicious fine-tuning.

Step 5 – Example: Baseline GPAI Compliance in Practice

Meet AlphaText

AlphaText offers a large language model via API and chat. It is clearly a GPAI model but, for now, does not reach systemic-risk thresholds.

Technical Documentation in Practice

AlphaText documents architecture, training data types, evaluation benchmarks, and known failure modes like hallucinations and bias.

Informing Downstream Users

A public model card explains intended uses, discouraged uses, limitations, and integration tips such as human review and user disclaimers.

Handling Copyright

AlphaText creates a copyright policy and publishes a training data summary listing major datasets and categories rather than raw data.

Safety and Security

The company monitors abuse, applies rate limits and filters, and protects model weights with access controls and logging.

Step 6 – Extra Obligations for Systemic-Risk GPAI Models and Codes of Practice

When Extra Rules Apply

Once a GPAI model is designated as systemic risk, its provider must meet stricter obligations on evaluation, mitigation, cybersecurity, and transparency.

Advanced Evaluation and Risk Assessment

Providers must run state-of-the-art evaluations, assess dangerous capabilities, document safety margins, and update risk assessments over time.

Mitigation and Incident Response

They must implement tailored risk mitigations and have processes to report serious incidents or new systemic risks to authorities.

Cybersecurity and Integrity

Systemic-risk GPAI models need strong protections against model theft, tampering, and data poisoning, plus secure release strategies.

Energy and Codes of Practice

Providers must be transparent about training energy use and are expected to follow EU codes of practice that define concrete, state-of-the-art safety measures.

Step 7 – Thought Exercise: Mapping Duties Across the AI Stack

Use this thought exercise to connect GPAI model obligations with the provider and deployer roles you learned earlier.

Scenario

A startup, MediAssist, builds a clinical decision-support tool for hospitals. It uses:

  • A third-party systemic-risk GPAI model (large multimodal model) via API.
  • Its own fine-tuning on de-identified medical notes.
  • A web dashboard used by doctors.

MediAssist sells the tool to hospitals in several EU countries.

Reflect on the questions below. You do not need to write formal answers, but think through them carefully.

  1. Who is the GPAI model provider?
  • Is it MediAssist, the third-party model company, or both? Under what conditions could MediAssist itself become a GPAI provider?
  1. Who is the AI system provider?
  • For the clinical decision-support tool as a system, who is the provider under the AI Act? How do the high-risk rules from earlier modules apply?
  1. Who is the deployer?
  • Are hospitals just deployers, or do they take on any provider-like roles (for example, if they heavily customize the system)?
  1. Which GPAI obligations cascade downstream?
  • What information and documentation should the GPAI provider give MediAssist?
  • What additional documentation and transparency does MediAssist owe to hospitals?
  1. Risk allocation
  • If the GPAI model has a systemic-risk designation, how might that affect MediAssist’s own risk management, testing, and incident reporting?

Try to map each element of the stack to the relevant duties:

  • GPAI model provider duties (baseline and systemic risk).
  • AI system provider duties for high-risk systems.
  • Deployer duties for hospitals.

This mental mapping exercise will help you quickly identify who is responsible for what in real-world GPAI-based products.

Step 8 – Quick Check: GPAI and Systemic Risk

Test your understanding of the key distinctions and duties.

Which statement best describes a systemic-risk GPAI model under the EU AI Act?

  1. Any AI model that is used in a high-risk application, regardless of its general-purpose capabilities.
  2. A general-purpose AI model whose capabilities or deployment scale can create significant risks across sectors, and that meets thresholds set by the EU.
  3. Any open-source AI model trained on internet-scale data, regardless of size or impact.
  4. Any AI model that uses copyrighted data in training.
Show Answer

Answer: B) A general-purpose AI model whose capabilities or deployment scale can create significant risks across sectors, and that meets thresholds set by the EU.

A systemic-risk GPAI model is a general-purpose AI model whose capabilities or deployment scale pose significant cross-sector risks, according to thresholds and assessments defined by the EU. High-risk applications alone do not automatically make a model systemic risk, and systemic risk is not limited to open-source models or copyright use.

Step 9 – Quick Check: Downstream Implications

Check how well you understand downstream duties when using GPAI.

A company integrates a third-party GPAI model into a recruitment screening tool that will be sold to EU employers. Which statement is most accurate?

  1. Only the GPAI model provider has obligations; the integrator is just a user.
  2. The integrator is an AI system provider and must comply with high-risk rules for recruitment, while relying on information from the GPAI provider.
  3. The integrator automatically becomes a GPAI model provider and must comply with systemic-risk obligations.
  4. Neither party has obligations under the AI Act because the GPAI model is not high-risk by itself.
Show Answer

Answer: B) The integrator is an AI system provider and must comply with high-risk rules for recruitment, while relying on information from the GPAI provider.

Recruitment tools are typically high-risk under the AI Act. The company integrating the GPAI model into a recruitment system becomes the AI system provider and must follow high-risk obligations, using documentation from the GPAI provider to support its own compliance.

Step 10 – Flashcards: Key Terms Review

Flip through these cards to reinforce core concepts about GPAI and systemic risk.

General-purpose AI model (GPAI model)
An AI model trained on broad data at scale, capable of performing a wide range of tasks, and reusable across many downstream systems and applications.
GPAI model provider
An entity that develops and places a GPAI model on the EU market, or substantially modifies such a model and releases it under its own name or trademark.
Systemic-risk GPAI model
A GPAI model whose capabilities or deployment scale create significant cross-sector risks to health, rights, the environment, democracy, or the rule of law, based on thresholds and assessments set by the EU.
Technical documentation (GPAI context)
Documentation describing a GPAI model’s architecture, training process, capabilities, limitations, evaluation methods, and reasonably foreseeable misuse, shared with authorities and downstream users.
Training data summary
A public, meaningful description of the main datasets, sources, and categories of data used to train a GPAI model, supporting copyright transparency without disclosing full datasets.
Codes of practice (GPAI)
EU-endorsed documents that translate GPAI obligations, especially for systemic-risk models, into concrete technical and organizational measures; following them can help demonstrate compliance.

Key Terms

Deployer
An organization or person that uses an AI system under its authority in the course of its activities, such as a hospital using a clinical AI tool or a company using an HR screening system.
Foundation model
A large, versatile AI model (often a subtype of GPAI) trained on broad data at scale and adaptable to many downstream tasks, such as large language models or multimodal models.
Codes of practice
Non-binding but influential documents that specify practical measures to comply with the AI Act; for GPAI, they outline state-of-the-art safety, testing, and transparency practices.
AI system provider
Any natural or legal person that develops an AI system or has it developed and places it on the market or puts it into service under their own name or trademark.
GPAI model provider
An organization or person that develops and places a GPAI model on the EU market, or substantially modifies such a model and releases it under their own name or trademark.
Training data summary
A public description of the main datasets, sources, and categories of data used for training a model, supporting transparency and copyright compliance.
Technical documentation
Detailed internal documentation describing an AI model’s design, training, capabilities, limitations, testing, and foreseeable misuse, used by authorities and downstream providers.
Systemic-risk GPAI model
A general-purpose AI model whose capabilities or deployment scale create significant risks across sectors, as defined by thresholds and qualitative assessments under the EU AI Act.
AI Office (European AI Office)
An EU body established to oversee implementation and enforcement of the AI Act, including supervision of GPAI and systemic-risk models.
General-purpose AI model (GPAI model)
An AI model trained on broad data at scale that can perform a wide range of distinct tasks and be integrated into many downstream systems or applications.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself