SkarpSkarp

Chapter 7 of 25

General-Purpose AI Models and Systemic Risk

The recitals introduce a regulatory layer for models capable of serving many downstream purposes, including the most powerful and widely deployed models. Documentation, copyright, evaluations, incident reporting and codes of practice form a proportionate regime that changes when systemic risk emerges.

27 min readen

Recitals (97)-(100): What Is a General-Purpose AI Model?

Model versus system

Recital (97) separates a general-purpose AI model from an AI system. A model needs added components, such as a user interface, before it becomes an AI system.

Core characteristics

The definition rests on "the generality and the capability to competently perform a wide range of distinct tasks." This is the recital's key functional test.

When obligations should apply

Obligations should apply once the model is placed on the market, including where its provider embeds its own model in an AI system made available on the market or put into service.

Research and internal use

The definition should not cover pre-market research, development, or prototyping. Purely internal use may also fall outside model obligations if it is not essential to a third-party product or service and rights are unaffected.

Scale indicator

Recital (98): "models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality".

Typical example

Large generative models are typical general-purpose models because they can generate text, audio, images, and video for many distinct tasks. A system containing one may itself become general-purpose.

Recital (101): Documentation Across the AI Value Chain

A value-chain responsibility

Recital (101) treats the model provider as a crucial value-chain actor because downstream providers may build many later systems on the provider's model.

Proportionate transparency

The recital says proportionate transparency measures should include drawing up and keeping documentation up to date, plus providing model information for downstream providers.

Two audiences

Information assists downstream providers with integration and compliance. Technical documentation should be available, upon request, to the AI Office and national competent authorities.

What the recital does not list

The recital says annexes should specify the minimum documentation elements. It does not itself provide a complete checklist of those elements.

Recitals (102)-(104): Open Source Does Not Mean No Rules

Open-source licence

Recital (102) uses the formulation "allows users to run, copy, distribute, study, change and improve software and data, including models".

Transparency and openness

For the recital, public availability of parameters including weights, architecture information, and model-usage information supports high transparency and openness.

A boundary on exceptions

Paid or otherwise monetised components generally should not receive free-and-open-source exceptions. Availability through an open repository alone is not monetisation.

Systemic-risk exception

Open-source transparency exceptions apply "unless they can be considered to present a systemic risk". Open weights do not neutralise systemic-risk obligations.

Still required

Even where the open-source exception applies, it should not cover the copyright policy or the public summary of content used for training.

Recitals (105)-(109): Copyright Policy, Training Summary, and Proportionate Compliance

Training and protected works

Recital (105) says training may use text-and-data mining on protected content. Authorisation is needed unless a relevant copyright exception or limitation applies.

Rights reservations

Where a rightsholder has appropriately and expressly reserved rights under Article 4(3) of Directive (EU) 2019/790, a provider needs authorisation to mine those works.

Copyright policy

Recital (106): "providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights".

Public training summary

Recital (107): providers should "draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model."

Comprehensive, not source-code-level detail

The summary should be generally comprehensive but not technically detailed, while protecting trade secrets and confidential business information.

Monitoring and proportionality

The AI Office should monitor fulfilment without a work-by-work copyright assessment. Compliance should be proportionate, with simplified routes for SMEs and start-ups.

Quiz 1: Open Source and Copyright

Choose the answer that best reflects Recitals (102)-(108).

A general-purpose model releases its weights, architecture information, and usage information under a qualifying free and open-source licence. Which statement is most accurate under Recital (104)?

  1. It is automatically exempt from every obligation applicable to general-purpose AI models.
  2. It may receive exceptions from transparency-related requirements, but not from the training-content summary or copyright-policy obligations; systemic risk also prevents reliance on the exception.
  3. It is exempt only if its developer is a microenterprise.
  4. It is exempt whenever its model is hosted in an open repository.
Show Answer

Answer: B) It may receive exceptions from transparency-related requirements, but not from the training-content summary or copyright-policy obligations; systemic risk also prevents reliance on the exception.

Recital (104) limits the transparency-related exception. It says the exception does not cover the public training-content summary or the copyright-compliance policy, and it does not apply where the model can be considered to present systemic risk. Recital (103) also says repository availability alone is not monetisation.

Recital (110): Understanding Systemic Risks

The governing idea

Recital (110): "Systemic risks should be understood to increase with model capabilities and model reach". Both dimensions matter.

Lifecycle conditions

Risk can arise throughout the lifecycle and may depend on misuse, reliability, fairness, security, autonomy, tool access, release strategy, and removable guardrails.

Illustrative harms

Examples include major accidents, disruption of critical sectors, serious public-health and safety effects, threats to democratic processes, and illegal, false, or discriminatory content.

Specific concerns

The recital highlights CBRN risks, offensive cyber capability, critical-infrastructure interference, self-replication, harmful bias, disinformation, privacy harms, and cascading events.

Combine the factors

A systemic-risk assessment should not isolate a single feature. Capability, reach, autonomy, tool access, safeguards, security, and foreseeable misuse can interact.

Recital (111): Classifying Models With Systemic Risk

Classification logic

Recital (111) describes systemic-risk classification through high-impact capabilities or significant internal-market impact due to a model's reach.

High-impact capabilities

"High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models."

Compute is an approximation

Cumulative training computation in floating point operations is described as a relevant approximation. It includes pre-training, synthetic-data generation, and fine-tuning.

Not a permanent numerical rule here

This recital says an initial FLOP threshold should create a presumption, but this source slice does not give its number. Thresholds should be adjusted and supplemented over time.

Individual designation

The Commission should be able to designate an equivalent model individually, considering factors such as data, users, modalities, autonomy, scalability, and tool access.

Recitals (112)-(113): Notification, Rebuttal, and Qualified Alerts

Presumption

A model meeting the applicable high-impact-capabilities threshold should be presumed to be a general-purpose AI model with systemic risk.

Exact notification timing

"The provider should notify the AI Office at the latest two weeks after the requirements are met" or after it becomes known they will be met.

Rebutting the presumption

A provider should be able to show that its model's specific characteristics exceptionally mean it does not present systemic risks.

Why early notice matters

The source highlights planned open-source releases: after release, measures needed for compliance may be more difficult to implement.

Alerts and designation

Where a provider did not notify, or facts were unknown, the Commission should be empowered to designate. Qualified alerts from the scientific panel support AI Office monitoring.

Quiz 2: Systemic-Risk Classification

Test the classification procedure described in Recitals (111)-(113).

According to Recital (112), when should a provider notify the AI Office about a model that meets, or is known will meet, the applicable high-impact-capabilities threshold?

  1. Only after the model has been publicly released.
  2. At the latest two weeks after the requirements are met or it becomes known that they will be met.
  3. Within six months of the first downstream deployment.
  4. Only if the AI Office first sends a formal request.
Show Answer

Answer: B) At the latest two weeks after the requirements are met or it becomes known that they will be met.

Recital (112) expressly gives the two-week outer deadline. It also covers the point at which it becomes known that the model will meet the requirements, reflecting the advance planning involved in large-scale training.

Recitals (114)-(115): Evaluation, Incident Reporting, and Cybersecurity

More than baseline obligations

Recital (114) adds systemic-risk duties to the general provider obligations: identify and mitigate risks and maintain adequate cybersecurity for standalone or embedded models.

Evaluation before first placement

Necessary evaluations should occur, particularly before first market placement, "including conducting and documenting adversarial testing of models".

Continuous mitigation

Examples include governance and accountability processes, post-market monitoring, lifecycle measures, and cooperation across the AI value chain.

Serious incidents

For a serious incident, "the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures".

Cybersecurity scope

Protection should address leakage, unauthorised releases, safety-measure circumvention, cyberattacks, unauthorised access, and theft of models.

Assets to secure

The recital gives examples: model weights, algorithms, servers, and data sets, supported by operational security, cybersecurity policies, technical measures, and access controls.

Recitals (116)-(120): Codes of Practice and the Digital Services Context

Who develops codes?

Recital (116) says the AI Office should encourage and facilitate codes of practice, working with national authorities and, where appropriate, consulting civil society, experts, and the Scientific Panel.

What codes should cover

Codes should cover provider obligations for general-purpose models and systemic-risk models. For systemic risk, they should help establish a Union-level risk taxonomy and focused mitigation measures.

Central compliance tool

"The codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models."

Other compliance routes

The Commission may approve codes or issue common rules. Suitable harmonised standards should grant a presumption of conformity, but alternative adequate means remain possible.

Digital Services Act context

For designated very large online platforms and search engines, corresponding obligations should be presumed fulfilled unless uncovered significant systemic risks emerge in the models.

Search-chatbot example

Recital (119) describes a chatbot that searches, in principle, all websites, incorporates results into knowledge, and produces one output combining information from different sources.

External currency note

PE-CONS 30/26 was signed on July 8, 2026 but is pending publication and not in force on July 22, 2026. Its Article 56-60a changes do not yet alter this lesson's source rules.

Flashcards: Essential Recall

Flip each card and state the related recital before checking your answer.

General-purpose model characteristics
Recital (97): "the generality and the capability to competently perform a wide range of distinct tasks."
One-billion-parameter indicator
Recital (98): "models with at least a billion of parameters and trained with a large amount of data using self-supervision at scale should be considered to display significant generality".
Open-source licence formulation
Recital (102): "allows users to run, copy, distribute, study, change and improve software and data, including models".
Open-source systemic-risk limit
Recital (104): transparency-related exceptions apply "unless they can be considered to present a systemic risk".
Copyright policy
Recital (106): "providers of general-purpose AI models should put in place a policy to comply with Union law on copyright and related rights".
Public training-content summary
Recital (107): providers should "draw up and make publicly available a sufficiently detailed summary of the content used for training the general-purpose AI model."
Systemic risks
Recital (110): "Systemic risks should be understood to increase with model capabilities and model reach".
High-impact capabilities
Recital (111): "High-impact capabilities in general-purpose AI models means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models."
Notification deadline
Recital (112): "The provider should notify the AI Office at the latest two weeks after the requirements are met" or after it becomes known they will be met.
Model evaluation
Recital (114) requires necessary evaluations, particularly before first market placement, "including conducting and documenting adversarial testing of models".
Serious incident response
Recital (115): "the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures".
Codes of practice
Recital (117): "The codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models."

Key Terms

AI model
A component that can perform model functions but does not, on its own, constitute an AI system; further components such as a user interface are needed.
AI system
A system that may contain an AI model together with additional components. Under Recital (100), a system integrating a general-purpose model should be considered general-purpose where the integration gives it a variety of purposes.
systemic risk
Actual or reasonably foreseeable harmful effects that may increase with a model's capabilities and reach and may arise across its lifecycle.
qualified alert
A mechanism through which the scientific panel should make the AI Office aware of models that may require systemic-risk classification.
adversarial testing
Testing intended to probe model weaknesses or harmful behaviour; Recital (114) says it should be conducted and documented as part of necessary evaluations.
downstream provider
A provider later in the AI value chain that may integrate a general-purpose model into a product or system.
general-purpose AI model
A model characterised by generality and the capability to competently perform a wide range of distinct tasks.
high-impact capabilities
Capabilities that match or exceed those recorded in the most advanced general-purpose AI models.
presumption of conformity
A status that suitable published European harmonised standards should grant to providers for the relevant obligations, as described in Recital (117).
free and open-source licence
For these recitals, a licence that allows users to run, copy, distribute, study, change and improve software and data, including models, potentially subject to attribution and comparable distribution terms.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself