# EU AI Act General-Purpose AI

The EU AI Act is a European Union regulation establishing a risk-based legal framework for artificial intelligence, including specific rules for general-purpose AI models. It entered into force on 1 August 2024, with obligations phased in over 6 to 36 months.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. It entered into force on 1 August 2024, with provisions becoming applicable gradually over the following 6 to 36 months. The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.

The Act classifies non-exempt AI applications by their risk of causing harm, with four levels – unacceptable, high, limited, and minimal – plus an additional category for general-purpose AI. For general-purpose AI, transparency requirements are imposed, with reduced requirements for open source models, and additional evaluations for high-capability models. The Act also creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

## Legislative History

The European Commission proposed the AI Act on 21 April 2021. The draft was revised to address the rise in popularity of generative AI systems, such as [ChatGPT](https://www.wikiprompt.org/wiki/chatgpt), whose general-purpose capabilities did not fit the main framework. The European Parliament passed the Act on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The regulation entered into force on 1 August 2024, with a phased implementation: prohibitions on unacceptable-risk systems applied from February 2025, general-purpose AI obligations from August 2025, and most high-risk provisions from August 2026.

## Risk Categories

The Act's risk-based scheme follows a product-safety model in which regulatory duties are assigned to providers and deployers of AI systems, becoming more demanding as potential impact on health, safety, or fundamental rights increases. This structure ensures oversight focuses on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.

### Unacceptable Risk

AI applications in this category are banned, except for specific exemptions. When no exemption applies, this includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring (ranking individuals based on personal characteristics, socio-economic status, or behaviour).

### High Risk

High-risk AI applications are those expected to pose significant threats to health, safety, or fundamental rights. Notably, AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice fall into this category. They are subject to quality, transparency, human oversight, and safety obligations, and in some cases require a Fundamental Rights Impact Assessment (FRIA) before deployment. A FRIA is an ex ante review to identify and mitigate potential impacts on fundamental rights. Earlier work on algorithmic impact assessments suggested that such tools should identify affected individuals and communities, describe possible harms, and provide a basis for public and institutional scrutiny. High-risk systems must be evaluated both before placement on the market and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act itself. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.

### Limited Risk

AI systems in this category have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices. This includes AI applications that generate or manipulate images, sound, or videos, such as deepfakes.

### Minimal Risk

This category includes AI systems used for video games or spam filters. Most AI applications are expected to fall into this category. These systems are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules. Existing national laws regarding the design or use of such systems are overridden. However, a voluntary code of conduct is suggested.

## General-Purpose AI Provisions

Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks, such as [large language models](https://www.wikiprompt.org/wiki/large-language-model) like ChatGPT. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks (requiring more than 10^25 floating-point operations to train) must undergo extra evaluation.

A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary.

Beyond basic transparency duties, the Act sets a common list of obligations for providers of general-purpose AI models. They must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.

## Exemptions

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for scientific research. Non-professional use is also exempt, meaning personal AI applications are not covered.

## Enforcement and Extraterritoriality

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the GDPR, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU. This means companies based in the United States, Asia, or elsewhere must comply when offering AI services to EU residents. National supervisory authorities in each member state are responsible for enforcement, with penalties for non-compliance reaching up to 7% of global annual turnover for prohibited practices, though specific figures are not detailed in the source.

## Impact on AI Development

The AI Act's general-purpose AI rules have significant implications for developers of [generative AI](https://www.wikiprompt.org/wiki/generative-ai) systems. For example, [OpenAI](https://www.wikiprompt.org/wiki/openai), [Anthropic](https://www.wikiprompt.org/wiki/anthropic), and [Google DeepMind](https://www.wikiprompt.org/wiki/google-deepmind) must ensure their models meet transparency and documentation requirements when deployed in the EU. Open-source models, such as those from [Meta](https://www.wikiprompt.org/wiki/meta) (not in the provided list, but implied), benefit from reduced obligations, encouraging transparency in model development. The Act also influences global standards, as other jurisdictions may adopt similar risk-based approaches. The phased implementation gives providers time to adapt, but the systemic-risk evaluations for high-capability models could affect the pace of AI research and deployment.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-general-purpose-ai
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:52:10.874689+00:00
