GPAI obligations are not your obligations
Articles 53 and 55 of the EU AI Act bind the providers of general-purpose AI models — the organisations that build and place those models on the market. If you build a product on top of one of them, those are not your duties. Article 50’s are.
Who each set of rules binds
The GPAI model provider
- Develops a general-purpose AI model and places it on the EU market — the frontier-model labs and anyone shipping a comparable model of their own.
- Article 53: keep and update technical documentation of the model, give downstream providers what they need to understand it, put in place a policy to comply with Union copyright law, and publish a sufficiently detailed summary of the training content.
- Article 55: for models with systemic risk, additionally evaluate the model against standardised protocols, assess and mitigate systemic risks, report serious incidents to the AI Office, and ensure adequate cybersecurity.
- Applying since 2 August 2025.
You, the provider or deployer of a system
- Builds or runs an AI system — very often on top of somebody else’s model, through an API.
- Tell people when they are interacting with an AI (50(1)).
- Mark synthetic audio, image, video and text machine-readably (50(2)).
- Inform people exposed to emotion-recognition or biometric-categorisation systems (50(3)), and disclose deepfakes and AI-generated public-interest text (50(4)).
- Applying from 2 August 2026.
The line is model versus system. A general-purpose AI model is the trained artefact. An AI system is the thing with a purpose, an interface and users. Using a model does not make you its provider — but note the corollary in Article 25: if you put your own name or trade mark on a high-risk system, or substantially modify one, you can become its provider, with the provider’s duties attached.
Why this matters commercially
Teams read a summary of the Act, see “training-data summaries” and “systemic risk evaluations”, and conclude EU AI Act compliance is an enormous programme they cannot start. Then they do nothing — including the part that is theirs, is small, and is already dated.
For most companies building with AI, the whole of their transparency obligation is four paragraphs long and demands a disclosure they can ship in an afternoon. The hard part is not doing it. The hard part is proving you did it, on the version that was live, months later.
Common questions
Do the EU AI Act's GPAI obligations apply to me if I use the OpenAI or Anthropic API?
No. Articles 53 and 55 bind the provider of the general-purpose AI model — the organisation that develops and places the model on the market. Building a product on someone else's model through an API makes you a downstream provider or deployer of an AI system, not a GPAI model provider. Your transparency obligations come from Article 50.
What is the difference between Article 50 and Article 53?
Article 50 is a transparency duty about how an AI system behaves towards the people using or exposed to it: tell them they are talking to an AI, mark AI-generated output, disclose deepfakes. Article 53 is a documentation and copyright duty owed by a model provider to downstream providers and to the AI Office, about the model itself.
When do GPAI obligations apply?
Obligations for general-purpose AI models have applied since 2 August 2025. Article 50's transparency duties apply from 2 August 2026. The two dates are often reported together, which is part of why the two sets of rules get confused.
Find out which duties are actually yours
The applicability check asks three questions about your system and tells you which paragraphs of the Act land on you — including whether you are, in fact, a model provider. It is free and needs no account.
Official sources
- Articles 51–56 are the general-purpose AI model chapter; Article 50 sits in Chapter IV, separately.
- The Commission’s code for model providers. If you are reading it wondering which parts apply to you, the answer is very likely none of them.
Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.