# EU AI Act General-Purpose AI

The EU AI Act's general-purpose AI provisions impose transparency, copyright, and safety obligations on foundation models, with stricter rules for high-impact systems. The regulation entered into force on 1 August 2024, with graduated implementation over 6 to 36 months.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence within the EU. It entered into force on 1 August 2024, with provisions coming into operation gradually over the following 6 to 36 months. The Act covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and on organisations that use AI in a professional context.

The Act classifies non-exempt AI applications by their risk of causing harm, with four levels - unacceptable, high, limited, and minimal - plus an additional category for general-purpose AI. The general-purpose AI category was added in 2023 to address the rise of generative AI systems such as ChatGPT, whose broad capabilities did not fit the main framework. Proposed by the European Commission on 21 April 2021, the Act passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024.

## Risk Categories

The Act's risk-based scheme follows a product-safety model in which regulatory duties are assigned to providers and deployers of AI systems, becoming more demanding as potential impact on health, safety, or fundamental rights increases. Applications with unacceptable risks are banned, except for specific exemptions. This includes AI that manipulates human behaviour, real-time remote biometric identification in public spaces, and social scoring. High-risk applications must comply with security, transparency, and quality obligations, and undergo conformity assessments. Limited-risk applications only have transparency obligations, while minimal-risk applications are not regulated.

## General-Purpose AI Obligations

For general-purpose AI models, the Act imposes transparency requirements, with reduced requirements for open source models and additional evaluations for high-capability models. Providers must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements.

## Systemic Risk Models

High-impact models that pose systemic risks - defined as requiring more than 10^25 floating-point operations to train - must undergo extra evaluation. These models must carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity. The threshold aims to capture the most powerful [large language models](https://www.wikiprompt.org/wiki/large-language-model) and other foundation models that could have widespread societal impact.

## Code of Practice

A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary. The code provides practical guidance for providers, particularly smaller companies and open-source developers, on how to meet their obligations under the regulation.

## Exemptions

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for those purposes. Non-professional use and research purposes are also excluded from the scope.

## Enforcement and Governance

The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance with the regulation. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU. This means companies such as [openai](https://www.wikiprompt.org/wiki/openai), [anthropic](https://www.wikiprompt.org/wiki/anthropic), and [google-deepmind](https://www.wikiprompt.org/wiki/google-deepmind) must comply with the Act's requirements for models offered to EU users, regardless of where the provider is based.

## Implementation Timeline

The regulation entered into force on 1 August 2024, with provisions phased in over 6 to 36 months. The gradual implementation allows providers time to adapt their systems and documentation. The Act's risk-based approach means that most AI applications, such as video games or spam filters, fall into the minimal-risk category and remain unregulated, while high-risk applications face the most stringent requirements.

## Relationship to Existing Law

Member States cannot impose additional regulations on minimal-risk AI systems due to maximum harmonisation rules, and existing national laws regarding the design or use of such systems are overridden. However, a voluntary code of conduct is suggested for minimal-risk applications. The Act's structure is meant to ensure that oversight focuses on systems likely to create significant risks while allowing lighter approaches for uses considered less sensitive. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.

## Broader Context

The AI Act represents a significant regulatory development for the field of [artificial intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence), affecting how [machine learning](https://www.wikiprompt.org/wiki/machine-learning) models are developed and deployed in the EU. The general-purpose AI provisions specifically target [generative AI](https://www.wikiprompt.org/wiki/generative-ai) systems built on [transformer](https://www.wikiprompt.org/wiki/transformer) architectures, which have become widespread since the introduction of models like ChatGPT. The Act's extraterritorial reach means its influence extends beyond EU borders, potentially shaping global standards for AI governance and [model safety](https://www.wikiprompt.org/wiki/model-pruning) practices.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-gpai
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-13T03:51:35.728519+00:00
