Module 2 of the AI Act GPAI certification: Annex XI technical documentation, Annex XII information to downstream providers, the copyright policy and TDM reservation, and the public training-content summary.

Article 53 is short, and every one of its four obligations produces an artefact somebody outside your organisation will read.

53(1)(a) — technical documentation, to Annex XI

Providers of general-purpose AI models shall draw up and keep up to date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at minimum the information set out in Annex XI, for the purpose of providing it, on request, to the AI Office and the national competent authorities.

Annex XI covers, broadly: a general description of the model including tasks it is intended to perform and the type and nature of AI systems into which it can be integrated; acceptable use policies; date of release and methods of distribution; architecture and number of parameters; modality and format of inputs and outputs; the licence. Then, on the training process: the technical means required for integration; design specifications and training methodology including key design choices and rationale; information on the data used for training, testing and validation where applicable, including type and provenance and curation methodologies; computational resources used and training time; and known or estimated energy consumption.

Two observations.

It is held, not published. Unlike the training-content summary, Annex XI documentation is produced on request to the AI Office and national authorities. It is a file you must have, not a disclosure.

Energy consumption is in it. Known or estimated energy consumption of the model is an Annex XI element, which surprises teams reading the article for the first time.

53(1)(b) — information to downstream providers, to Annex XII

Providers shall draw up, keep up to date and make available information and documentation to providers of AI systems who intend to integrate the model into their AI systems.

The information must, without prejudice to the need to observe and protect intellectual property rights and confidential business information including trade secrets:

The minimum content is in Annex XII: a general description of the model, its intended tasks, the type and nature of systems it can be integrated into, acceptable use policies, release date and distribution methods, how it interacts with hardware and software external to the model, relevant software versions, architecture and parameter count, modality and format of inputs and outputs, and the licence — plus the technical means required for integration, and the model's design specifications and training process at the level needed for a downstream provider to do its job.

This is the article a downstream builder should quote when a model vendor declines to explain what the model can and cannot do. The confidentiality carve-out is real, but it qualifies how much detail is owed, not whether the obligation exists.

53(1)(c) — the copyright policy

Providers shall put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Art. 4(3) of Directive (EU) 2019/790.

Article 4 of the DSM Directive permits text and data mining for any purpose, unless the rightsholder has expressly reserved the use in an appropriate manner — for content made publicly available online, in machine-readable form.

So the obligation has two halves, and the second is the operational one: you must be able to identify reservations, and to comply with them. "Identify ... including through state-of-the-art technologies" is a moving standard: robots.txt-style signals, emerging machine-readable reservation formats, and whatever the state of the art becomes.

What a defensible position looks like: a written policy; a description of the crawling and acquisition pipeline and where reservation checks sit in it; the signals honoured and the version of the standard; a record of what was excluded and when; and a review cadence tied to the state of the art moving.

Note also that this obligation applies regardless of where the training took place. A model trained outside the Union and placed on the Union market carries it.

53(1)(d) — the public training-content summary

Providers shall draw up and make publicly available a sufficiently detailed summary about the content used for training the model, according to a template provided by the AI Office.

Three points that decide implementation.

Public. This is the only Art. 53 output that must be published. It is read by rightsholders, journalists, competitors and downstream buyers.

Sufficiently detailed. The tension in the article is deliberate: detailed enough to be meaningful to rightsholders assessing whether their content was used, without requiring disclosure of the dataset itself. The AI Office template is what resolves the tension in practice, and using it is the safe course.

Not a substitute for the copyright policy. The summary describes what you trained on; the policy describes how you respected reservations. A provider that publishes a good summary and cannot describe its reservation handling has satisfied (d) and not (c).

The open-source relief, and its limits

Art. 53(2) provides that the obligations in (a) and (b) — Annex XI documentation and Annex XII downstream information — do not apply to providers of models released under a free and open-source licence that allows access, usage, modification and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available.

Three limits.

It is conditional on genuine openness. Weights, architecture and usage information public, and a licence permitting access, use, modification and distribution. A weights-available licence with field-of-use restrictions is unlikely to qualify.

(c) and (d) survive. The copyright policy and the public training-content summary apply to open-source models too. This is the most frequently missed point in the whole article.

It does not apply to models with systemic risk. The relief falls away entirely once Art. 51 bites — Module 3.

Art. 54 — third-country providers

Providers of GPAI models established in third countries shall, prior to placing a model on the Union market, appoint by written mandate an authorised representative established in the Union.

The representative performs the tasks specified in the mandate, keeps a copy of the technical documentation at the disposal of the AI Office and national competent authorities, and cooperates with them. There is a corresponding relief for open-source models that do not present systemic risk.

Check yourself

  1. We release our model under an open licence, so Art. 53 does not apply.The relief covers (a) and (b) only. The copyright policy and the public training-content summary still apply, and the relief disappears for systemic-risk models.
  2. Our model vendor says the architecture is a trade secret and will tell us nothing.Art. 53(1)(b) and Annex XII require information enabling downstream providers to understand capabilities and limitations and to meet their own obligations, with confidentiality qualifying the detail rather than the duty.
  3. We trained outside the EU, so the TDM reservation rules do not reach us.Art. 53(1)(c) attaches to placing the model on the Union market, not to where training happened.
  4. We published a training-data summary; are we done on copyright?No. (d) describes what you trained on; (c) requires a policy showing how reservations were identified and complied with.

Previous: Module 1 — Model or system? The Chapter V boundary Next: Module 3 — Systemic risk (Art. 51, 52, 55) →

Frequently Asked Questions

Art. 53(1)(d) requires a sufficiently detailed summary of the content used for training the model, made publicly available, according to a template provided by the AI Office. The model weights and the dataset itself stay private; the summary does not. It is the only Art. 53 obligation whose output is public.

No. Models released under a free and open-source licence that allows access, use, modification and distribution, and whose parameters including weights, architecture and usage information are made publicly available, are relieved of the Annex XI documentation and the Annex XII downstream-information duties. The copyright policy and the public training-content summary still apply — and the relief falls away entirely for models with systemic risk.

A policy to comply with Union law on copyright and related rights, and in particular to identify and comply with — including through state-of-the-art technologies — reservations of rights expressed under Art. 4(3) of Directive (EU) 2019/790. In practice that means honouring machine-readable text-and-data-mining opt-outs, and being able to show how you did.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.