The EU AI Act's general-purpose AI obligations became applicable in August 2025, marking a key milestone in the regulation of artificial intelligence within the European Union. The AI Act, which entered into force on 1 August 2024, establishes a risk-based framework for AI systems, with provisions phased in over 6 to 36 months. The general-purpose AI (GPAI) obligations, part of this timeline, target providers of foundation models such as large language models and generative AI systems, requiring them to meet transparency, copyright, and safety standards.
These obligations apply to any provider offering GPAI models within the EU market, including those based outside the bloc, reflecting the regulation's extraterritorial reach. The August 2025 date specifically triggers duties for providers of general-purpose AI models, including publishing training data summaries, adopting copyright policies, and providing technical documentation. High-impact models with systemic risk face additional evaluation and adversarial testing requirements.
Background and Legislative Timeline
The European Commission proposed the AI Act on 21 April 2021, but the rapid rise of generative AI systems like ChatGPT prompted revisions to address general-purpose capabilities that did not fit the original risk categories. The European Parliament passed the Act on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The regulation entered into force on 1 August 2024, with obligations phased in over the following months. The GPAI obligations, originally scheduled for August 2025, were part of this staggered implementation, allowing providers time to adapt.
Scope of GPAI Obligations
The AI Act defines general-purpose AI models as those trained on broad data at scale, designed for generality of output, and adaptable to a wide range of tasks. This includes models like ChatGPT, built on transformer architectures, and other foundation models. Providers must comply with several core duties:
- Publish a detailed summary of the training data used, including sources and selection criteria.
- Adopt a policy to respect EU copyright law, particularly regarding text and data mining.
- Provide technical documentation to downstream providers and supervisory authorities, enabling them to understand the model's capabilities and limitations.
For open-source models, where weights and design are made publicly available, the requirements are reduced: they must publish a training data summary and a copyright policy, but are exempt from broader transparency duties. Closed-source models must meet the full set of obligations.
High-Impact Models and Systemic Risk
Models that require more than 10^25 floating-point operations to train are designated as posing systemic risk. These high-impact models must undergo additional evaluations, including model evaluations and adversarial testing, to assess and mitigate risks such as bias, security failures, and other societal harms. They must also report serious incidents to authorities and ensure an adequate level of cybersecurity. This category captures the largest and most capable models, such as those developed by OpenAI, Anthropic, and Google DeepMind.
Code of Practice and Compliance
To help providers demonstrate compliance, the European Commission facilitated the development of a General-Purpose AI Code of Practice, published on 10 July 2025. The code outlines three main chapters on transparency, copyright, and safety and security. Participation is voluntary, but providers can use it to show adherence to the AI Act's requirements. The code was developed with input from industry, academia, and civil society, and reflects best practices for responsible AI development.
Relationship to the Risk-Based Framework
The GPAI obligations sit alongside the Act's four risk categories: unacceptable, high, limited, and minimal. Unacceptable risk applications are banned, high-risk applications face strict security and quality obligations, limited-risk applications have transparency duties, and minimal-risk applications are unregulated. General-purpose AI models, due to their versatility, are treated as a separate category, with obligations that scale based on capability. This structure ensures that oversight focuses on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.
Enforcement and Extraterritoriality
Like the EU's General Data Protection Regulation, the AI Act can apply extraterritorially. Providers outside the EU must comply if they offer GPAI models to users within the EU. Enforcement is coordinated through the European Artificial Intelligence Board, which promotes national cooperation and ensures consistent application. National supervisory authorities are responsible for monitoring compliance and can impose penalties for violations. The August 2025 date marked the start of these obligations, with providers expected to have systems in place by then.
Impact on the AI Industry
The August 2025 GPAI obligations have significant implications for AI developers worldwide. Companies like OpenAI, Anthropic, and Google DeepMind must ensure their models meet EU transparency and safety standards. Open-source initiatives, such as those from Meta or Mistral AI, benefit from reduced requirements, potentially encouraging more open development. The obligations also affect downstream providers who integrate GPAI models into their products, as they must rely on documentation from upstream providers.
Future Developments
As of August 2025, the GPAI obligations are in effect, but the regulatory landscape continues to evolve. The European Commission may update the list of high-risk applications and refine the systemic risk criteria. The Code of Practice will likely be revised based on implementation experience. Providers are expected to adapt their practices, and the AI Act's influence is likely to extend beyond the EU, shaping global standards for AI governance. The August 2025 date is a pivotal moment in the regulation of general-purpose AI, balancing innovation with the need to protect fundamental rights and safety.