Operational notes Regulation

General-purpose AI models: from 2 August, you can demand more from your vendor

4 min read

Machine room of a data centre
Whoever builds the model must now document it. Whoever adopts it can hold them to account.

On 2 August 2026 — just days away — Chapter V of the EU AI Act (Regulation (EU) 2024/1689) becomes fully applicable and enforceable for providers of general-purpose AI models, the so-called GPAI: the large “foundation” models on which almost all corporate generative AI runs. The story has mostly been told from the side of those who build the models. But there is a side that matters far more to most organisations: that of those who adopt them. Because from that date you are entitled to information that nobody was previously obliged to give you — and you can use it as a filter in your contracts.

What takes effect, in brief

The GPAI obligations have formally been in force since 2 August 2025, but it is from 2 August 2026 that the Commission acquires enforcement powers: from requirements with no immediate consequences, they become rules that can trigger penalties. The regulation distinguishes two categories: standard GPAI models, subject to transparency and documentation obligations (Article 53), and GPAI models with systemic risk — the most powerful models — subject to reinforced risk assessment and mitigation obligations (Article 55). The penalty regime under Article 99 reaches up to €15 million or 3% of worldwide turnover for breaches of the GPAI obligations.

What the vendor must now produce (and you can ask for)

The regulation provides for four documents:

  1. Technical documentation of the model (Annex XI): capabilities, limitations, architecture in summary form.
  2. Information for downstream providers (Annex XII): what those integrating the model into their own product need in order to use it compliantly — and “downstream” means you, if you build a service on top of a third party’s model.
  3. Copyright compliance policy: how the vendor respects copyright in training.
  4. Summary of the content used for training: the public summary of what went into the model.

For those adopting AI, this changes the conversation with the vendor: no longer “trust us”, but “show me the document”. It is the same principle of reversibility and transparency that public procurement specifications are already adopting, now with an explicit legal basis.

The Code of Practice: how to read it from the customer’s side

The Commission has published a Code of Practice for GPAI: signatories benefit from a presumption of conformity that reduces exposure in the event of a review. It is not an absolute safe conduct, but a vendor that has signed the Code and complies with its content starts from a stronger position. For you as a buyer, signing up to the Code becomes a simple, verifiable selection criterion: ask whether the vendor has signed up, and get it in writing. It is the quickest way to tell those who have done their homework from those who are stalling.

Why it also concerns those who “don’t develop AI”

If your company uses an assistant, a copilot or a service built on a frontier model, you are a deployer — and part of the obligations fall on you (use in accordance with the instructions, human oversight, informing data subjects). The vendor’s GPAI documentation is exactly what you need to do your part: without the model card, you cannot demonstrate that you have used it correctly. This is why mapping where AI touches people and collecting vendor documentation need to be done now, not after the first inspection. And the principle we build in by design still holds: every critical action remains under human control, whatever model is under the bonnet.

What to do before 2 August

  1. List the GPAI models you use, both direct (a vendor’s API) and indirect (embedded in third-party software).
  2. Request in writing from vendors: technical documentation, information for deployers, copyright policy, training summary, Code of Practice sign-up.
  3. File the responses: in an inspection, “they never sent it to us” is not a defence if you never asked for it.
  4. Build these requirements into your next contracts: vendor compliance becomes a contractual obligation, not a courtesy.

Want to know which GPAI obligations affect the systems you use — and what to ask your vendors before 2 August? Half an hour with one of our experts for the map.

Sources