The European Union’s first draft guidance for general-purpose AI models, published in November 2024, was only a provisional starting point—not binding law or a final compliance checklist. It has since been followed by a final voluntary Code of Practice, binding obligations for GPAI providers and active European Commission enforcement powers.
The key dates are August 2, 2025, when GPAI obligations began applying, and August 2, 2026, when the Commission’s enforcement powers began applying. Models placed on the EU market before August 2, 2025 generally have until August 2, 2027 to comply.
As an Amazon Associate I earn from qualifying purchases.
What the November 2024 draft guidance was
The item reported on November 14, 2024 was the first draft of a Code of Practice being prepared under the EU AI Act. It was not a new regulation, technical standard or final list of mandatory controls.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The 36-page draft was explicitly high-level and incomplete. It contained provisional measures, open questions and unfinished performance indicators, and invited stakeholder feedback until November 28, 2024. A more detailed final version was expected in 2025.
#1 Best Overall
The draft nevertheless showed the direction of travel for major model developers such as OpenAI, Google, Meta, Anthropic and Mistral AI. It focused on documentation, copyright controls, evaluations, safety and security, incident reporting and risk mitigation. TechCrunch’s original report is useful historical coverage, but it should not be read as a description of the rules that apply today.
What changed after the draft
The European Commission received the final GPAI Code of Practice on July 10, 2025. The Commission and EU AI Board approved it as an adequate voluntary tool for demonstrating compliance. Its three principal chapters cover:
- Transparency, including model documentation and information for downstream providers.
- Copyright, including policies for complying with EU copyright law and a public summary of training content.
- Safety and security, particularly for models presenting systemic risk.
The Code is voluntary, but that does not mean the underlying obligations are optional. A provider can follow the Code as a recognized compliance route or use alternative measures that demonstrate compliance with the AI Act. The Commission may consider adherence when monitoring compliance, but signing the Code does not guarantee immunity from enforcement.
Recommended Free Tools
See the Commission’s announcement of the final Code and its overview of the Code’s contents and status.
What counts as a general-purpose AI model?
A general-purpose AI model is broadly capable rather than designed for one narrow task. It can perform a range of tasks and be integrated into many downstream AI systems—for example, a language model used for writing, coding, analysis, customer service or document processing.
The Commission’s guidance uses an indicative technical criterion of more than 1023 floating-point operations combined with broad generative capability, such as generating language, text-to-image or text-to-video output. This is not the sole legal test, and exceptions may apply. Compute thresholds are screening tools, not complete scientific definitions of capability or danger.
The relevant regulated party is generally the provider placing the model on the EU market. A company merely using an external model through an API is not automatically the GPAI provider, although it may have separate responsibilities as the provider or deployer of a downstream AI system.
The Commission’s scope guidelines and GPAI obligations FAQ explain the classification in more detail.
Which companies may be affected?
Frontier-model developers are the most obvious examples, but the rules are not limited to famous technology companies. Potentially affected providers include:
- Large companies developing broadly capable models.
- Smaller companies placing GPAI models on the EU market.
- Providers established outside the EU and selling models into the EU.
- Organizations making significant modifications to an existing GPAI model.
- Some developers distributing open-weight models, depending on the model, license, transparency conditions and systemic-risk status.
Open-source licensing is not an automatic blanket exemption. The provider’s role, the model’s distribution, the extent of modifications and any systemic-risk classification all matter. Minor changes do not automatically make a company a provider, while significant modifications may create provider obligations.
The baseline obligations for GPAI providers
For most covered providers, the current framework requires more than publishing a marketing page or a basic model card.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →1. Maintain technical documentation
Providers must draw up and maintain documentation about the model and its development process. The material should give regulators and downstream AI-system providers enough information to understand how the model was built, what it can do and where it can fail.
Rank #3
Relevant information can include:
- Intended tasks, capabilities and limitations.
- Training and development processes.
- Evaluation results and relevant testing methods.
- Acceptable-use policies.
- Release date and distribution method.
- Software versions and interfaces where relevant.
- Integration information for downstream providers.
2. Give downstream providers useful information
Companies building products on top of a foundation model need information to assess their own obligations under the AI Act. Model providers therefore need processes for supplying documentation about capabilities, limitations, intended use, known risks, evaluation evidence and relevant changes between model versions.
3. Maintain a copyright-compliance policy
Providers must maintain a policy for complying with EU copyright law and related rights. That includes taking account of rights reservations and machine-readable exclusions, such as applicable robots.txt instructions.
This is distinct from publishing a public training-data summary. A provider may need detailed internal records about data sources, permissions, exclusions and complaints even though the public summary is not a complete list of every training item.
4. Publish a sufficiently detailed training-content summary
The public summary is intended to explain the content used to train the model at an appropriate level of detail. It is not necessarily a public dump of every dataset record, copyrighted work or individual web page.
The framework distinguishes between:
- A public summary of training content.
- More detailed technical documentation for regulators and downstream providers.
- Internal provenance, rights and data-governance records.
5. Appoint an EU representative where required
A provider established outside the EU generally must appoint an authorized representative in the Union before placing the model on the EU market.
The Commission’s obligations FAQ and its GPAI obligations fact page provide the current summary.
Rank #4
Additional duties for models with systemic risk
The AI Act adds requirements for the most advanced or impactful GPAI models. It presumes systemic risk where a model was trained using more than 1025 FLOPs, although the Commission says this threshold is under review. The threshold is not an infallible measure of real-world danger, and a model below it can still create serious risks in a particular context.
The Commission identifies four additional areas of responsibility:
- Notify the Commission.
- Conduct model evaluations.
- Assess and mitigate systemic risks.
- Report serious incidents.
- Maintain adequate cybersecurity protections.
The draft Code proposed practical mechanisms including safety-and-security frameworks, continuous risk identification, red-teaming, adversarial testing, benchmarks, question-and-answer evaluations, human-uplift studies, model-organism testing, simulations and proxy evaluations where classified or inaccessible material cannot be used directly.
It also contemplated serious-incident tracking, corrective-action procedures and forecasts for when future capabilities might cross risk thresholds. These tools can improve evidence and governance, but they do not eliminate the difficult scientific problem of measuring dangerous capabilities.
Timeline: from draft guidance to enforcement
| Date | What happened |
|---|---|
| November 14, 2024 | The first draft of the GPAI Code was reported and opened for feedback. |
| November 28, 2024 | The feedback deadline cited in the original coverage. |
| July 10, 2025 | The Commission received the final GPAI Code of Practice. |
| July 18, 2025 | The Commission published guidelines on the scope of GPAI provider obligations. |
| August 2, 2025 | GPAI obligations began applying. |
| August 2, 2026 | The Commission’s GPAI enforcement powers began applying. |
| August 2, 2027 | Models placed on the market before August 2, 2025 generally must comply by this date. |
As of August 18, 2026, providers of new GPAI models should already be complying. Providers that have not signed the Code need to explain how they will meet the AI Act through alternative measures.
Free tools Windows power users keep installed
One-click scans. No signup required.
Specified submissions to the AI Office use the EU SEND platform. Depending on the provider and model, submissions can include systemic-risk notifications, reassessment requests, serious-incident reports, safety-and-security frameworks, model reports and alternative-compliance reports from non-signatories. The Commission’s current provider guidance describes the process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Sign the Code or use alternative compliance?
Following the Code gives a provider a documented and regulator-recognized path. It can also provide a common structure for internal teams and make it easier to explain the provider’s controls to customers and the AI Office.
The trade-off is that Code commitments may go beyond the minimum wording of the AI Act. Providers may need to disclose sensitive operational information and maintain costly documentation, evaluation and incident-reporting processes.
Alternative measures may suit an open-weight provider, a smaller developer or an organization with a mature internal safety framework. But the evidentiary burden remains. An alternative framework must be documented and credible enough to demonstrate compliance under regulatory scrutiny. The Commission’s Q&A explains the relationship between the Code and alternative measures.
What this means for enterprise AI buyers
Companies that do not build foundation models can still be affected. A downstream AI provider may need accurate information from its model supplier to document and manage its own system.
Before adopting a foundation model, an enterprise should ask the supplier for:
- Technical documentation and model-version information.
- Capabilities, limitations and evaluation evidence.
- The public training-content summary.
- The provider’s copyright-compliance policy.
- Confirmation of whether it treats the model as GPAI.
- Whether it has signed the Code or uses alternative compliance measures.
- Systemic-risk evaluation and incident-reporting procedures where relevant.
- Processes for notifying customers about material model changes.
- Contractual commitments to provide updated documentation.
Using a major cloud or model platform does not automatically make the customer compliant. Responsibility depends on the company’s role, the system’s intended purpose, its risk classification and how the model is deployed.
Important uncertainties
Several difficult issues remain unsettled in practice:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Compute is an imperfect proxy for capability and risk.
- The systemic-risk threshold may change.
- The precise meaning of a serious incident and the timing of reporting require careful operational interpretation.
- Responsibility can be difficult to assign when an open-weight model is modified and redistributed.
- It may be unclear whether a failure originates in the model or in a downstream system.
- Future standards and enforcement practice may refine how evidence is assessed.
The November 2024 draft raised many of these questions; it did not resolve them. The final Code provides compliance pathways, not a universally accepted scientific test for safe AI.
Primary sources
- Original November 2024 reporting on the draft
- European Commission: contents of the GPAI Code
- Commission guidelines on scope and obligations
- Commission guidance for GPAI providers
- Commission summary of GPAI obligations
The Bottom Line
The EU has moved from a provisional November 2024 draft to an operational framework. The GPAI Code is voluntary, but the AI Act obligations it helps providers demonstrate are binding. Model providers now need reliable documentation, copyright processes, training-content summaries and downstream information; systemic-risk providers face additional evaluation, mitigation, incident-reporting and cybersecurity duties.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




