Six-module certification on Chapter V of the EU AI Act: the model/system boundary, Art. 53 obligations, systemic risk under Art. 51 and 55, codes of practice, when fine-tuning makes you a provider, and building downstream.
Chapter V is the newest and least settled part of the AI Act, and the one with the most confusion about who it binds. The confusion has a single root: the Regulation regulates models and systems under different chapters, on different timetables, with different enforcers — and almost every organisation working with foundation models touches both.
This track separates the two, then works through each.
The six modules
Module 1 — Model or system? The Chapter V boundary Art. 3(63), what "significant generality" means, the research carve-out, and why the same organisation is usually a provider twice over.
Module 2 — What every GPAI provider owes (Art. 53) Technical documentation to Annex XI, information to downstream providers to Annex XII, the copyright policy and the text-and-data-mining reservation, and the public training-content summary.
Module 3 — Systemic risk (Art. 51, 52, 55) The 10^25 FLOP presumption and how to rebut it, the two-week notification, and the four additional obligations that follow.
Module 4 — Codes of practice and the standards gap (Art. 56) What adherence demonstrates, what it does not, and how to work while harmonised standards do not yet exist.
Module 5 — Becoming a model provider Fine-tuning, modification, the open-source relief and its limits, and the Art. 54 authorised representative for third-country providers.
Module 6 — Building downstream You are the provider of the system you built: Art. 50 transparency, the Art. 25 trap, and what to demand from a model provider before you depend on them.
What the examination asks
Twenty questions drawn from a bank, stratified so every module is covered, graded on our server. The pass mark is 70%.
Before you start
This track assumes the free Fundamentals course. If your organisation also builds high-risk systems on these models, the Provider track covers the Chapter III obligations that then attach.
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗This is not the same examination
The Fundamentals examination checks that you have read the Regulation. This one checks that you could apply it to a real case — same subject, different question.
| Fundamentals (free) | GPAI (this track) | |
|---|---|---|
| Questions served | 15 | 20 |
| Question bank | 60 | 89 |
| Modules covered | 5 | 6 |
| What is tested | Whether you are in scope, and by what | Which chapter binds you, which party, and which enforcer |
| Access | Open, no card required | Track holders only |
Two sample questions on the same article. They are written for this page and appear in no bank.
Fundamentals — free
Which chapter of the AI Act governs providers of general-purpose AI models?
- Chapter II
- Chapter III
- Chapter V
- Chapter IX
Show the answer and the reasoning
Answer 3. Chapter II covers prohibited practices, Chapter III the high-risk system requirements, and Chapter IX post-market monitoring and market surveillance. A reference, recalled — useful, and it tells you nothing about what to do next.
GPAI — this track
You serve a customer assistant built on a third-party foundation model you did not train, under your own brand, to the EU public. Who owes the machine-readable marking of its synthetic output, and who would enforce a failure?
- The model provider, enforced by the Commission through the AI Office
- You, as provider of the system, enforced by your national market surveillance authority
- Nobody until December 2027, when the high-risk regime applies
- Jointly, with the Art. 101 fine regime applying to both
Show the answer and the reasoning
Answer 2. Art. 50(2) is a system-provider duty and you built the system, so it is yours — in force since 2 August 2026. Chapter V duties stay with whoever provided the model, and the enforcers differ: the Commission for models under Art. 101, national market surveillance authorities for systems under Art. 99. Three separate distinctions in one scenario, and most organisations get at least one wrong.
Every paper is drawn per candidate and stratified across all modules; the order of the options differs between candidates. Grading happens on the server — the answer key never reaches the browser.
Frequently Asked Questions
Art. 3(63) defines it as an AI model, including where trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way it is placed on the market, and that can be integrated into a variety of downstream systems or applications. Models used for research, development or prototyping activities before being placed on the market are excluded.
A model is the trained artefact; a system is the model plus everything built around it to serve a purpose — the interface, the retrieval, the guardrails, the deployment. Chapter V binds providers of models. Chapters II and III bind AI systems. The same organisation is frequently both, with two separate obligation sets running in parallel and different deadlines.
Art. 51 sets two routes. A model is presumed to have high impact capabilities where the cumulative amount of compute used for its training exceeds 10^25 floating point operations — a rebuttable presumption the Commission may update. Or the Commission may designate a model under Art. 51(2) on the basis of other criteria. Where the compute criterion is met, Art. 52 requires the provider to notify the Commission without delay and in any event within two weeks.
It depends on the extent of the modification. A modification that produces what is in substance a different model, or that materially changes its capabilities, can make you the provider of that model with Chapter V obligations attaching to your version. A light adaptation for a downstream task usually does not. What is certain is that building a system on the model makes you the provider of the system, which is a separate question with its own obligations.
2 August 2025 for the GPAI obligations themselves. The Commission's enforcement powers over GPAI providers, exercised through the AI Office, applied from 2 August 2026. Neither was deferred by the Digital Omnibus, which moved the high-risk system dates rather than the model regime.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.