WHAT THE ARTICLE IS ABOUT
The baseline compliance requirements for all GPAI model providers
Article 53 establishes what every provider of a general-purpose AI model must do — the floor of GPAI compliance before any systemic risk classification. These obligations reflect the Act’s recognition that GPAI models are foundational infrastructure that many downstream AI systems depend on, and that their providers have unique responsibilities toward both regulators and the businesses building on top of them.
WHAT IT SAYS
Documentation, copyright, training transparency, and downstream support
- GPAI model providers must draw up and maintain technical documentation as specified in Annex XI — covering model architecture, training data, training methodology, capabilities, limitations, and performance evaluations
- They must provide information and documentation to downstream providers who integrate the GPAI model into their AI systems — enabling those providers to understand the model’s capabilities and limitations and meet their own compliance obligations
- They must establish and implement a policy to respect EU copyright law — specifically the Text and Data Mining exception under the Copyright Directive, ensuring they have respected rights holders’ opt-outs
- They must publish a sufficiently detailed summary of the content used to train the GPAI model — enabling transparency about what the model has learned from
- Free and open-licence GPAI models — where parameters, weights, architecture and usage are publicly available — only need to comply with the copyright and training summary obligations, unless they present systemic risk
- Providers may demonstrate compliance by adhering to a code of practice until harmonised standards are published
WHO IS AFFECTED
Every GPAI model provider serving the EU market
- Commercial GPAI model providers — OpenAI, Anthropic, Google, Meta, Mistral, and all similar companies whose models are used in the EU
- Open-source GPAI model providers publishing models for others to use — subject to lighter obligations
- Downstream providers building AI products on top of GPAI models — they have a right to receive the information GPAI providers must supply
- The AI Office which monitors compliance with these obligations
WHAT IT MEANS FOR SMES
Your right to information from your AI vendor — and a compliance chain implication
- If you build products or services on top of a GPAI model — using an API, embedding a model in your application, or fine-tuning — your GPAI provider has a legal obligation to give you the documentation and information you need to meet your own compliance obligations under the Act
- Ask your GPAI vendor directly for their Annex XI technical documentation and the downstream provider information they are obliged to supply — this is your legal entitlement under Article 53
- The copyright policy obligation matters for SMEs using GPAI for content generation — your vendor’s compliance with copyright law affects the legal status of AI-generated content you produce using their model
- The training data summary is a transparency tool — read it to understand what data the model was trained on and what biases or limitations that might introduce
- Free and open-source models have lighter obligations — if you use an open-source GPAI model, the documentation and downstream support requirements are less comprehensive, meaning you may need to do more of your own due diligence
Related Articles
- Article 51 — Systemic risk classification (determines whether Article 55 additional obligations also apply)
- Article 55 — Systemic risk obligations (the additional layer on top of Article 53 for high-compute models)
- Article 25 — Value chain responsibilities (downstream providers building on GPAI may become providers themselves)
- Annex XI — Technical documentation for GPAI models (the specific documentation Article 53 requires)
