Module 1 of the AI Act GPAI certification: Art. 3(63), significant generality, the research carve-out, and why an organisation building on foundation models is usually a provider twice over.
The single most common Chapter V error is answering the wrong question. An organisation asks "are we caught by the GPAI rules?" when the useful question is "which of the two things we are doing is regulated where?"
Art. 3(63), and the three tests inside it
'general-purpose AI model' means an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market.
Four things follow.
"Including where ... trained with a large amount of data using self-supervision at scale" is illustrative, not definitional. A model need not be a transformer trained on web-scale text. The tests are generality, breadth of competent task performance, and integrability.
"Regardless of the way the model is placed on the market." API, weights download, embedded in a product, offered free — the route does not change the classification.
"Can be integrated into a variety of downstream systems." A model that can only serve one application is a component of that application, not a general-purpose model.
The research carve-out ends at market placement. Models used for research, development or prototyping before being placed on the market are excluded. That protects experimentation; it does not protect a model you have started serving in production.
Model versus system, stated once
| GPAI model | AI system | |
|---|---|---|
| What it is | The trained artefact | The model plus what is built around it to serve a purpose |
| Governed by | Chapter V (Art. 51-56) | Chapters II and III |
| Bound party | Provider of the model | Provider of the system, plus its deployer |
| Enforcer | Commission, via the AI Office | National market surveillance authorities |
| Fine regime | Art. 101 — up to 3% or EUR 15 million | Art. 99 — bands by obligation |
| Applied since | 2 August 2025 | Art. 5 from Feb 2025; Art. 50 from Aug 2026; high-risk from Dec 2027 / Aug 2028 |
Note the enforcer row in particular. A GPAI provider deals with the Commission; a system provider deals with the Member State authority. Organisations that are both will meet both.
Why most organisations here are providers twice over
Take a company that trains a foundation model and also ships a customer-facing assistant built on it.
As a model provider, it owes Art. 53: technical documentation to Annex XI, information for downstream providers to Annex XII, a copyright policy, and a public summary of training content. If the model crosses the systemic-risk threshold, Art. 55 adds evaluation, risk mitigation, incident reporting and model cybersecurity.
As a system provider, it owes Art. 50(1) — telling people they are interacting with an AI system — and Art. 50(2) machine-readable marking of synthetic output. If the assistant is put to an Annex III use, the whole of Chapter III attaches on top.
Neither set substitutes for the other, and they do not even share a deadline.
The downstream case
Now take the far commoner position: a company that trains nothing and builds a product on somebody else's model.
It is not a GPAI provider. Chapter V duties for the underlying model stay with whoever provided it. What it is is the provider of the AI system it built, which brings Art. 50 and, depending on purpose, Chapter III.
Two things can change that.
Modification. Sufficiently substantial modification of a model can make you the provider of the modified model — Module 5 works through where the line sits.
Purpose. Under Art. 25(1)(c), putting a general-purpose AI system that was not classified as high-risk to a high-risk use makes you the provider of a high-risk system. That is a Chapter III event, not a Chapter V one, and it is the single most common way an ordinary product team acquires the heaviest obligations in the Regulation.
Where GPAI meets high-risk
Art. 25 also anticipates the case where a general-purpose AI system is used directly as a high-risk system, or integrated into one. Where that happens, the provider of the GPAI system that is being integrated has cooperation duties toward the downstream provider — the same logic that runs through Art. 25(2): the party holding the information must make it available to the party carrying the obligation.
In practice this is a contract question long before it is a litigation question, which Module 6 returns to.
What to settle first
Three determinations, written down:
- Do we place a model on the market, or put one into service? If yes, Chapter V applies to us for that model.
- Do we place a system on the market, or put one into service? If yes, Chapters II and III apply to us for that system, separately.
- If we build on a third-party model, what have we done to it? Fine-tuning, distillation, merging, continued pre-training — record what and how much, because that record is what answers the provider-status question later.
The third is the one that decays. Record it at the time.
Check yourself
- We use a third-party model through an API. Are we a GPAI provider? — No. You are the provider of the system you built on it; Chapter V duties stay with the model provider.
- Our model is used only internally for research. — The carve-out covers research, development and prototyping before market placement. Production use is not research.
- We train a model and ship an assistant on it. — You are a provider twice, under Chapter V for the model and under Chapter II/III for the system, with different deadlines and different enforcers.
- Who fines a GPAI provider, and under which article? — The Commission, through the AI Office, under Art. 101 — up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher.
Next: Module 2 — What every GPAI provider owes (Art. 53) →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Routinely, and the two obligation sets are independent. Training a model and placing it on the market makes you a GPAI provider under Chapter V. Building a product on that model and putting it into service under your own name makes you the provider of an AI system under Chapter II or III. Nothing about satisfying one discharges the other.
No. Art. 3(63) expressly excludes AI models used for research, development or prototyping activities before they are placed on the market. The carve-out ends at market placement, and putting a model into service for your own production use is not research.
The Commission, through the AI Office, centrally — not national market surveillance authorities. Those powers applied from 2 August 2026. The fine regime for GPAI providers sits in Art. 101 rather than Art. 99, at up to 3% of worldwide annual turnover or 15 million euro, whichever is higher.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.