GPAI Provider Compliance — Articles 53–55
EU AI Act compliance for general-purpose AI model providers. Annex XI transparency obligations, capability evaluation, systemic risk assessment, and model card requirements.
A general-purpose AI (GPAI) model is an AI model trained on broad data that can perform a wide range of tasks. Under EU AI Act Articles 53–55, GPAI model providers have mandatory transparency, documentation, and copyright compliance obligations. These obligations became enforceable on August 2, 2025 — one year ahead of high-risk AI system obligations. Providers of GPAI models with systemic risk (threshold: 10^25 FLOPs training compute) face additional safety evaluation, adversarial testing, and incident reporting obligations under Article 55. Fines reach €15 million or 3% of turnover.
What Is a GPAI Model?
Article 3(63) defines a GPAI model as an AI model trained on large amounts of data using self-supervision at scale, displaying significant generality, and capable of competently performing a wide range of distinct tasks. Large language models (LLMs), foundation models, and multimodal models generally fall within this definition. The Act distinguishes between GPAI models and GPAI systems — a GPAI system is a GPAI model integrated into an AI system and placed on the EU market by the model provider.
Standard GPAI models (Art 53)
- →Technical documentation (Annex XI)
- →Copyright compliance policy
- →Summary of training data (Art 53(1)(d))
- →Model cards and transparency information
- →Pass obligations downstream to providers using the model
Systemic risk GPAI models (Art 55)
- →All Art 53 obligations PLUS:
- →Adversarial testing and red-teaming (Art 55(1)(a))
- →Serious incident reporting to European AI Office
- →Cybersecurity protection measures
- →Energy efficiency reporting
- →Model evaluation against Art 55 benchmarks
Annex XI Technical Documentation Requirements
Annex XI specifies the technical documentation GPAI model providers must maintain and make available to downstream providers who integrate the model. The documentation must be kept up to date throughout the model's lifecycle.
General description of the GPAI model
Training, fine-tuning, and RLHF methodology
Architecture and parameter count
Training data sources and data governance
Compute resources used for training (FLOPs)
Training data modalities and formats
Results of capability evaluations
Applicable safety measures and alignment techniques
Known or foreseeable risks and mitigations
Performance benchmarks and evaluation results
Model Card Requirements
Under Article 53(1)(b), GPAI model providers must draw up and publicly release a model card with information about the model's intended uses, limitations, evaluation results, and how downstream providers can use it safely. The model card must cover: intended tasks and use cases, languages supported, input/output modalities, context window size, performance benchmarks, known limitations and failure modes, and safety and alignment measures applied.
The European AI Office has developed code of practice guidelines (ongoing in 2025) that provide more detailed specifications for model card format and content to assist with compliance.
Systemic Risk Threshold and Additional Obligations
GPAI models trained with more than 10^25 floating point operations are presumed to have systemic risk under Article 51(1)(a). This threshold covers state-of-the-art frontier models.
Adversarial testing, incident reporting to the European AI Office, cybersecurity protection, and energy efficiency reporting apply to systemic-risk GPAI models from August 2025.
Self-assessment: Providers who believe their model does not pose systemic risk despite exceeding the compute threshold may notify the European AI Office and request an assessment. The presumption of systemic risk can be rebutted through capability evaluations demonstrating the model does not have systemic risk characteristics under Article 51(2).
GPAI Obligations: Already in Force (August 2025)
GPAI model obligations under Articles 53–55 became enforceable on August 2, 2025 — one full year ahead of high-risk AI system obligations. Providers who were already placing GPAI models on the EU market on the date of entry into force had until August 2, 2025 to bring their models into compliance. New GPAI models placed on the market after this date must comply from the outset.
How Scanara Supports GPAI Provider Compliance
Annex XI documentation generation
Scanara scans your model repository and generates a pre-populated Annex XI technical documentation template — covering architecture, training data governance, capability evaluations, and safety measures.
Model card scaffolding
Auto-generate a compliant model card from your codebase scan — covering intended use, limitations, evaluation results, and downstream integration guidance per Article 53(1)(b).
Systemic risk assessment
Scanara calculates training compute estimates from your training configuration files and flags when the 10^25 FLOPs systemic risk threshold is approached, triggering Article 55 obligation checklist.
Frequently Asked Questions
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.