Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter V · Articles 51–56

General-purpose AI model obligations

Chapter V has applied since 2 August 2025 and the Digital Omnibus did not change it in substance. What did change is who supervises you: the AI Office now holds exclusive competence in defined cases, including over AI systems built on your own model.

Arts. 51–56Art. 101 — €15M / 3%in force since 2 Aug 2025

The base obligations

Providers of general-purpose AI models placed on the EU market must:

  1. Technical documentation of the model, drawn up and kept up to date, made available to the AI Office and national competent authorities on request.
  2. Information for downstream providers who integrate the model into their own AI systems, enough for them to understand its capabilities and limitations and to meet their own obligations.
  3. A copyright policy to comply with Union law on copyright and related rights, including respecting reservations of rights expressed under the text and data mining exception.
  4. A sufficiently detailed summary of the content used for training, published according to a template provided by the AI Office.

Providers established outside the Union must appoint an authorised representative in the Union.

Open-source relief is real but partial

Models released under free and open-source licences get relief from some Chapter V obligations, subject to conditions, but not where the model presents systemic risk, and the copyright policy and training-data summary duties are treated differently from the documentation duties. Read the conditions rather than assuming the exemption.

Systemic risk

A general-purpose AI model is classified as presenting systemic risk where it has high impact capabilities, assessed by appropriate technical tools and methodologies including indicators and benchmarks, or by a Commission decision. The Regulation sets a presumption based on cumulative compute used for training, and the Commission may amend the thresholds by delegated act as the state of the art moves.

Providers of models with systemic risk additionally must:

  • Notify the Commission without delay when the model meets the classification.
  • Perform model evaluation, including adversarial testing, to identify and mitigate systemic risks.
  • Assess and mitigate possible systemic risks at Union level, including their sources.
  • Track, document and report serious incidents and possible corrective measures to the AI Office and, as appropriate, national competent authorities, without undue delay.
  • Ensure an adequate level of cybersecurity protection for the model and its physical infrastructure.
Arts. 51, 53, 55Reg. (EU) 2024/1689

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What the Omnibus actually changed for you

Articles 51 to 55 are untouched in substance. The amendment sequence in Regulation (EU) 2026/1744 skips from Article 50 to Article 56. What moved is the supervisory architecture.

The AI Office now has exclusive competence in two cases

  1. AI systems based on a general-purpose AI model developed by the same provider or the same group of undertakings. If you build both the model and the application on top of it, your application is supervised by the AI Office rather than by a national market surveillance authority.
  2. AI systems that are, or are integrated into, services designated as VLOPs or VLOSEs under the Digital Services Act.

The AI Office also gained a consolidated set of investigative and enforcement powers equivalent to those of a market surveillance authority, and receives serious incident reports from providers within its exclusive jurisdiction.

Practical consequence. A vertically integrated model provider now deals with one regulator across the stack rather than with the AI Office for the model and 27 national authorities for the applications. Whether that is simpler depends on your view of the AI Office, but it is materially different from what most GPAI compliance plans written in 2025 assumed. Expert analysis.

The Code of Practice

Article 56 provides for codes of practice as a route to demonstrating compliance with Chapter V. Adherence is a route, not the route: a provider may demonstrate compliance by other adequate means. A code of practice is not a harmonised standard and does not confer the Article 40 presumption of conformity, which applies to high-risk systems rather than to general-purpose models. Standards landscape →

Penalties

Article 101: up to €15 million or 3% of total worldwide annual turnover, whichever is higher, imposed by the Commission rather than by a national authority. Separate from the Article 99 regime that applies to AI systems. Penalties in detail →

Status labels on this page

Verified fact: The Chapter V base and systemic-risk obligations, the Art. 101 penalty, the Art. 56 code of practice mechanism, and the AI Office competence changes made by Reg. (EU) 2026/1744.

Expert analysis: The 'practical consequence' analysis of vertical integration and the reading of the open-source relief.

Unsettled: The compute threshold for systemic risk is subject to amendment by delegated act; verify the current figure against the consolidated text before relying on it.

Next step

Downstream providers need what you produce

Your Article 53 information package is an input to every downstream provider's Annex IV file. Making it genuinely usable is a commercial advantage as well as an obligation, and it determines whether your customers can build on you inside the Regulation.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What are the EU AI Act obligations for general-purpose AI models?

Chapter V applies to providers of general-purpose AI models placed on the EU market. Core obligations include drawing up and keeping up to date technical documentation of the model, making information available to downstream providers who integrate the model, putting in place a policy to comply with Union copyright law, and publishing a sufficiently detailed summary of the content used for training. Models classified as presenting systemic risk carry additional obligations including model evaluation, adversarial testing, systemic risk assessment and mitigation, serious incident tracking and reporting, and cybersecurity protection.

Did the Digital Omnibus change the general-purpose AI rules?

Not in substance. Articles 51 to 55 have applied since 2 August 2025 and the amending Regulation (EU) 2026/1744 left them as they were. What changed is supervision: the AI Office gained a consolidated set of supervisory and enforcement powers, and exclusive supervisory competence over AI systems based on a general-purpose AI model developed by the same provider or the same group of undertakings, and over AI systems that are integrated into services designated as very large online platforms or very large online search engines under the Digital Services Act.

What is the GPAI Code of Practice?

A voluntary instrument under Article 56 intended to allow providers of general-purpose AI models to demonstrate compliance with their Chapter V obligations. Adherence is one route to demonstrating compliance rather than the only one; a provider may demonstrate compliance by other adequate means. It is not a harmonised standard and does not confer the Article 40 presumption of conformity, which applies to high-risk systems rather than to general-purpose models.

Who enforces the general-purpose AI obligations?

The European Commission, through the AI Office, rather than national market surveillance authorities. Fines for general-purpose AI model providers are set by Article 101 at up to 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher.