Don’t do SECURITY. Do business SECURELY.

EU AI Act: general-purpose AI obligations apply

Obligations for providers of general-purpose AI models under the EU AI Act apply from today.

From today, obligations for providers of general-purpose AI (GPAI) models under the EU AI Act apply, together with the Act’s governance and penalty provisions.

GPAI providers must

  • Maintain technical documentation and provide information to downstream providers.
  • Put in place a policy to comply with EU copyright law.
  • Publish a summary of the content used for training.

Providers of GPAI models with systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents and ensure adequate cybersecurity. A voluntary General-Purpose AI Code of Practice provides a route to demonstrating compliance.

Most organisations are deployers rather than GPAI providers, but they should expect more information from their AI suppliers, and should use it in their own AI risk and impact assessments.

Source: Regulation (EU) 2024/1689 – AI Act (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights