GPAI Model: where foundation model providers meet binding EU obligations
GPAI models face EU AI Act Articles 53-55 since August 2025. Zertia audits GPAI compliance with ISO 42001.
Definition
What is a GPAI Model under the EU AI Act?
A General Purpose AI (GPAI) model is an AI model that displays significant generality and is capable of performing a wide range of distinct tasks. Under the EU AI Act, GPAI models are defined in Article 3(63) as AI models trained on large amounts of data that demonstrate strong performance across diverse tasks and can be integrated into a variety of downstream systems or applications. Large Language Models (LLMs) such as GPT-4, Claude, Gemini, and Llama are the paradigmatic examples of GPAI models.
The EU AI Act introduces a dedicated regulatory regime for GPAI models in Chapter V. All GPAI model providers must comply with baseline transparency and documentation obligations: maintaining technical documentation, providing model cards and usage policies, ensuring copyright compliance in training data, and publishing summaries of training data. GPAI models classified as presenting systemic risk, those trained with compute exceeding 10^25 FLOPs, face additional obligations including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures.
The structural significance of the GPAI regime is that it regulates the upstream layer of the AI stack. Most prior AI regulation, including the high-risk regime of the EU AI Act itself, focused on the deployment context. GPAI rules instead address the foundation models that hundreds or thousands of downstream applications depend on. This is the first time that foundational AI infrastructure is regulated as such, independent of how it is later applied.
Why it matters operationally
Why does GPAI regulation matter operationally?
GPAI regulation matters because it extends EU AI Act obligations to the upstream layer of the AI stack. Companies developing or distributing foundation models and LLMs face direct regulatory obligations, not only the enterprises deploying them. This creates a dual exposure: developers of GPAI models face provider obligations, and enterprises integrating GPAI models into products face deployer obligations. The two are independent, and compliance with one does not satisfy the other.
For enterprises using GPAI models in high-risk applications, HR automation, customer credit decisioning, medical assistance, the integration of a GPAI model does not transfer regulatory responsibility to the model provider. The deploying organization remains accountable for the system-level compliance of the application: risk management, human oversight, technical documentation, conformity assessment. The model is a component; the regulated artifact is the system that uses it.
This split has direct procurement implications. Buyers of GPAI-based applications need to verify two distinct compliance perimeters: that the underlying GPAI model meets Chapter V obligations, and that the application built on top of it meets the relevant deployer obligations. Vendors that conflate the two, treating provider compliance as if it covered system compliance, expose buyers to regulatory risk that surfaces only under enforcement.
Regulatory framework
Which frameworks govern GPAI models?
| Framework | GPAI obligations |
|---|---|
| EU AI Act — Chapter V | All GPAI providers: technical documentation, usage policies, training data copyright compliance, public training data summary. Additional obligations for systemic risk GPAI models (adversarial testing, incident reporting, cybersecurity). |
| European AI Office | Oversees compliance with systemic risk GPAI model obligations at EU level. Issues guidance on thresholds, classifications, and enforcement priorities. |
| ISO/IEC 42001 | ISO 42001 certification covers model lifecycle governance, including GPAI when developed or deployed by the organization. Provides a certifiable management system that integrates GPAI obligations into the organization’s broader AI governance. |
| GPAI Code of Practice | Voluntary framework developed under the European AI Office to operationalize Chapter V obligations. Adherence functions as evidence of compliance until harmonized standards are published. |
How Zertia evaluates it
How does Zertia evaluate GPAI model compliance?
Zertia evaluates GPAI model compliance through the EU AI Act Audit, which covers GPAI-specific obligations: technical documentation adequacy, usage policy compliance, training data copyright measures, and, for systemic risk models, adversarial testing and incident reporting mechanisms. The EU AI Act Assessment provides the diagnostic classification and gap analysis that precedes formal audit, including the determination of whether a model qualifies as GPAI and whether it crosses the systemic risk threshold.
For organizations integrating GPAI models into high-risk applications, Zertia coordinates the GPAI-level evaluation with the system-level conformity assessment. The integrated approach ensures that the dual compliance perimeter (provider + deployer) is documented coherently, avoiding the most common procurement and regulatory failures that emerge when the two are treated as a single obligation.
Definitions that hold up under audit.
Does this term apply to your certification project? Let's talk 30 minutes, no commercial pressure.
