DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

EU AI Act: What Happened to the Draft Guidance—and What Big AI Must Do Now

The EU’s first GPAI guidance was only a draft. Here is what changed, who is covered and what AI model providers must do under the EU AI Act now.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The European Union’s first draft guidance for general-purpose AI models, published in November 2024, was only a provisional starting point—not binding law or a final compliance checklist. It has since been followed by a final voluntary Code of Practice, binding obligations for GPAI providers and active European Commission enforcement powers.

The key dates are August 2, 2025, when GPAI obligations began applying, and August 2, 2026, when the Commission’s enforcement powers began applying. Models placed on the EU market before August 2, 2025 generally have until August 2, 2027 to comply.

As an Amazon Associate I earn from qualifying purchases.

What the November 2024 draft guidance was

The item reported on November 14, 2024 was the first draft of a Code of Practice being prepared under the EU AI Act. It was not a new regulation, technical standard or final list of mandatory controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 36-page draft was explicitly high-level and incomplete. It contained provisional measures, open questions and unfinished performance indicators, and invited stakeholder feedback until November 28, 2024. A more detailed final version was expected in 2025.

The draft nevertheless showed the direction of travel for major model developers such as OpenAI, Google, Meta, Anthropic and Mistral AI. It focused on documentation, copyright controls, evaluations, safety and security, incident reporting and risk mitigation. TechCrunch’s original report is useful historical coverage, but it should not be read as a description of the rules that apply today.

What changed after the draft

The European Commission received the final GPAI Code of Practice on July 10, 2025. The Commission and EU AI Board approved it as an adequate voluntary tool for demonstrating compliance. Its three principal chapters cover:

  • Transparency, including model documentation and information for downstream providers.
  • Copyright, including policies for complying with EU copyright law and a public summary of training content.
  • Safety and security, particularly for models presenting systemic risk.

The Code is voluntary, but that does not mean the underlying obligations are optional. A provider can follow the Code as a recognized compliance route or use alternative measures that demonstrate compliance with the AI Act. The Commission may consider adherence when monitoring compliance, but signing the Code does not guarantee immunity from enforcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See the Commission’s announcement of the final Code and its overview of the Code’s contents and status.

What counts as a general-purpose AI model?

A general-purpose AI model is broadly capable rather than designed for one narrow task. It can perform a range of tasks and be integrated into many downstream AI systems—for example, a language model used for writing, coding, analysis, customer service or document processing.

The Commission’s guidance uses an indicative technical criterion of more than 1023 floating-point operations combined with broad generative capability, such as generating language, text-to-image or text-to-video output. This is not the sole legal test, and exceptions may apply. Compute thresholds are screening tools, not complete scientific definitions of capability or danger.

The relevant regulated party is generally the provider placing the model on the EU market. A company merely using an external model through an API is not automatically the GPAI provider, although it may have separate responsibilities as the provider or deployer of a downstream AI system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Commission’s scope guidelines and GPAI obligations FAQ explain the classification in more detail.

Which companies may be affected?

Frontier-model developers are the most obvious examples, but the rules are not limited to famous technology companies. Potentially affected providers include:

  • Large companies developing broadly capable models.
  • Smaller companies placing GPAI models on the EU market.
  • Providers established outside the EU and selling models into the EU.
  • Organizations making significant modifications to an existing GPAI model.
  • Some developers distributing open-weight models, depending on the model, license, transparency conditions and systemic-risk status.

Open-source licensing is not an automatic blanket exemption. The provider’s role, the model’s distribution, the extent of modifications and any systemic-risk classification all matter. Minor changes do not automatically make a company a provider, while significant modifications may create provider obligations.

The baseline obligations for GPAI providers

For most covered providers, the current framework requires more than publishing a marketing page or a basic model card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Maintain technical documentation

Providers must draw up and maintain documentation about the model and its development process. The material should give regulators and downstream AI-system providers enough information to understand how the model was built, what it can do and where it can fail.

Relevant information can include:

  • Intended tasks, capabilities and limitations.
  • Training and development processes.
  • Evaluation results and relevant testing methods.
  • Acceptable-use policies.
  • Release date and distribution method.
  • Software versions and interfaces where relevant.
  • Integration information for downstream providers.

2. Give downstream providers useful information

Companies building products on top of a foundation model need information to assess their own obligations under the AI Act. Model providers therefore need processes for supplying documentation about capabilities, limitations, intended use, known risks, evaluation evidence and relevant changes between model versions.

3. Maintain a copyright-compliance policy

Providers must maintain a policy for complying with EU copyright law and related rights. That includes taking account of rights reservations and machine-readable exclusions, such as applicable robots.txt instructions.

This is distinct from publishing a public training-data summary. A provider may need detailed internal records about data sources, permissions, exclusions and complaints even though the public summary is not a complete list of every training item.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Publish a sufficiently detailed training-content summary

The public summary is intended to explain the content used to train the model at an appropriate level of detail. It is not necessarily a public dump of every dataset record, copyrighted work or individual web page.

The framework distinguishes between:

  • A public summary of training content.
  • More detailed technical documentation for regulators and downstream providers.
  • Internal provenance, rights and data-governance records.

5. Appoint an EU representative where required

A provider established outside the EU generally must appoint an authorized representative in the Union before placing the model on the EU market.

The Commission’s obligations FAQ and its GPAI obligations fact page provide the current summary.

Additional duties for models with systemic risk

The AI Act adds requirements for the most advanced or impactful GPAI models. It presumes systemic risk where a model was trained using more than 1025 FLOPs, although the Commission says this threshold is under review. The threshold is not an infallible measure of real-world danger, and a model below it can still create serious risks in a particular context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Commission identifies four additional areas of responsibility:

  • Notify the Commission.
  • Conduct model evaluations.
  • Assess and mitigate systemic risks.
  • Report serious incidents.
  • Maintain adequate cybersecurity protections.

The draft Code proposed practical mechanisms including safety-and-security frameworks, continuous risk identification, red-teaming, adversarial testing, benchmarks, question-and-answer evaluations, human-uplift studies, model-organism testing, simulations and proxy evaluations where classified or inaccessible material cannot be used directly.

It also contemplated serious-incident tracking, corrective-action procedures and forecasts for when future capabilities might cross risk thresholds. These tools can improve evidence and governance, but they do not eliminate the difficult scientific problem of measuring dangerous capabilities.

Timeline: from draft guidance to enforcement

Date What happened
November 14, 2024 The first draft of the GPAI Code was reported and opened for feedback.
November 28, 2024 The feedback deadline cited in the original coverage.
July 10, 2025 The Commission received the final GPAI Code of Practice.
July 18, 2025 The Commission published guidelines on the scope of GPAI provider obligations.
August 2, 2025 GPAI obligations began applying.
August 2, 2026 The Commission’s GPAI enforcement powers began applying.
August 2, 2027 Models placed on the market before August 2, 2025 generally must comply by this date.

As of August 18, 2026, providers of new GPAI models should already be complying. Providers that have not signed the Code need to explain how they will meet the AI Act through alternative measures.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Specified submissions to the AI Office use the EU SEND platform. Depending on the provider and model, submissions can include systemic-risk notifications, reassessment requests, serious-incident reports, safety-and-security frameworks, model reports and alternative-compliance reports from non-signatories. The Commission’s current provider guidance describes the process.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Sign the Code or use alternative compliance?

Following the Code gives a provider a documented and regulator-recognized path. It can also provide a common structure for internal teams and make it easier to explain the provider’s controls to customers and the AI Office.

The trade-off is that Code commitments may go beyond the minimum wording of the AI Act. Providers may need to disclose sensitive operational information and maintain costly documentation, evaluation and incident-reporting processes.

Alternative measures may suit an open-weight provider, a smaller developer or an organization with a mature internal safety framework. But the evidentiary burden remains. An alternative framework must be documented and credible enough to demonstrate compliance under regulatory scrutiny. The Commission’s Q&A explains the relationship between the Code and alternative measures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this means for enterprise AI buyers

Companies that do not build foundation models can still be affected. A downstream AI provider may need accurate information from its model supplier to document and manage its own system.

Before adopting a foundation model, an enterprise should ask the supplier for:

  • Technical documentation and model-version information.
  • Capabilities, limitations and evaluation evidence.
  • The public training-content summary.
  • The provider’s copyright-compliance policy.
  • Confirmation of whether it treats the model as GPAI.
  • Whether it has signed the Code or uses alternative compliance measures.
  • Systemic-risk evaluation and incident-reporting procedures where relevant.
  • Processes for notifying customers about material model changes.
  • Contractual commitments to provide updated documentation.

Using a major cloud or model platform does not automatically make the customer compliant. Responsibility depends on the company’s role, the system’s intended purpose, its risk classification and how the model is deployed.

Important uncertainties

Several difficult issues remain unsettled in practice:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Compute is an imperfect proxy for capability and risk.
  • The systemic-risk threshold may change.
  • The precise meaning of a serious incident and the timing of reporting require careful operational interpretation.
  • Responsibility can be difficult to assign when an open-weight model is modified and redistributed.
  • It may be unclear whether a failure originates in the model or in a downstream system.
  • Future standards and enforcement practice may refine how evidence is assessed.

The November 2024 draft raised many of these questions; it did not resolve them. The final Code provides compliance pathways, not a universally accepted scientific test for safe AI.

Primary sources

The Bottom Line

The EU has moved from a provisional November 2024 draft to an operational framework. The GPAI Code is voluntary, but the AI Act obligations it helps providers demonstrate are binding. Model providers now need reliable documentation, copyright processes, training-content summaries and downstream information; systemic-risk providers face additional evaluation, mitigation, incident-reporting and cybersecurity duties.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.