IA 360
Regulatory Framework

AI Act: what changes on 2 August 2026 for GPAI models

GPAI duties have applied since 2025; 2 August 2026 activates the Commission's enforcement and fining powers. The timeline depends on the model, date and each company's role.

Admin IA360 5 min read AI-generated Leer en español
AI Act: what changes on 2 August 2026 for GPAI models

2 August 2026 does not create a new package of duties for providers of general-purpose AI models, or GPAI models. Those duties began to apply on 2 August 2025. The concrete change concerns enforcement: the temporary exception for Article 101 ends and the Commission can enforce GPAI provider obligations through the fines it establishes.

The distinction prevents two opposite errors. A company cannot postpone until 2026 duties that already affect a new model; nor should it read the date as meaning that every API user automatically faces a fine. The timetable depends on which entity is the provider, when the model was placed on the market and whether it presents systemic risk.

The transferable skill is to answer four questions in order: are we dealing with a model or a system integrating it, who places it on the Union market, did that happen before or after 2 August 2025, and is it an ordinary GPAI model or one with systemic risk? Only then can a duty, deadline and piece of evidence be matched correctly.

Three dates that mean different things

Article 113 of Regulation (EU) 2024/1689 makes 2 August 2026 the general application date. It brought Chapter V on GPAI models forward to 2 August 2025, however, while excluding Article 101 from that early start. The substantive duties will therefore have applied for a year when the specific fining phase begins.

From 2 August 2025, a provider placing a new GPAI model on the EU market must meet the applicable duties and, if the model presents systemic risk, notify the AI Office without delay. From 2 August 2026, the Commission's enforcement powers, including fines, apply. The official GPAI guidelines page sets out that sequence.

A separate transition exists for older models. Article 111 gives providers of GPAI models placed on the market before 2 August 2025 until 2 August 2027 to take the necessary compliance steps. The deadline follows an already marketed model; it is not a general exemption for another model the same company launches after the cut-off.

The maximum fine is not an automatic tariff

Article 101 allows the Commission to fine a provider up to EUR15 million or 3% of its total worldwide annual turnover in the preceding financial year, whichever is higher. That is a statutory ceiling. It does not mean every infringement attracts the maximum or that the figure is triggered merely by the date arriving.

Covered conduct includes infringing relevant provisions of the Regulation, failing to comply with requests for documents or information, supplying incorrect, incomplete or misleading information, failing to comply with requested measures, and refusing access to a model for a Commission evaluation. A decision requires a procedure and must consider the nature, gravity and duration of the infringement, among other factors set out in the article.

The Code of Practice does not determine fines or liability. The official GPAI model explanation separates that voluntary instrument from questions of scope, classification and enforcement. Signing can provide a way to demonstrate compliance; it does not confer immunity. Not signing does not itself prove an infringement either, but the provider must sustain alternative adequate means.

What a GPAI provider must be able to demonstrate

Article 53 has four cores. First, current technical documentation covering the model, including development, training, testing and evaluation, available to the AI Office and competent authorities when applicable. Second, information for downstream providers integrating the model, sufficient to understand its capabilities and limitations and meet their own duties.

Third, a policy for complying with Union copyright and related-rights law, including identifying and respecting reservations of rights made under that law. Fourth, a sufficiently detailed public summary of the content used to train the model, following the AI Office template. Disclosure duties coexist with protections for intellectual property, confidential business information and trade secrets; they do not require every detail of a model to be published.

A provider established outside the Union can still be covered when placing a model on the EU market. Subject to the stated exceptions, Article 54 requires it to appoint an authorised representative in the Union in writing before placing the model on the market. Hosting servers outside Europe does not by itself answer the territorial-scope question.

Open source: a partial exemption, not an eraser

Article 53 provides an exemption for certain models released under a free and open-source licence when weights, architecture and model-usage information are public. The exemption concerns parts of technical documentation and information for downstream integrators. It does not remove the copyright policy or public training-content summary, and it does not apply to GPAI models with systemic risk.

“Open” requires checking conditions rather than accepting a marketing label. A licence that permits weight downloads may impose limits inconsistent with the legal definition or leave required elements unpublished. Assessment should map the licence, available parameters, architecture, usage information and risk classification.

The Commission guidelines explain how it interprets these concepts, but state that they are not legally binding. They help predict the enforcement approach; the Regulation remains the higher legal authority.

When enhanced duties appear

A GPAI model with systemic risk adds Article 55. Its provider must evaluate the model using appropriate protocols and documented adversarial testing, assess and mitigate Union-level systemic risks, track and report serious incidents and corrective measures, and maintain adequate cybersecurity for the model and its physical infrastructure.

Article 51 presumes high-impact capabilities when cumulative training compute exceeds 1025 floating-point operations. The Commission can amend that threshold through delegated acts and can also designate a model by its capabilities or impact under the statutory criteria. The number is a regulatory presumption, not a scientific boundary between safe and dangerous models.

When a provider knows its model will meet the compute condition, Article 52 requires notification to the Commission without delay and within two weeks at most. The provider can submit arguments that the model does not present systemic risk despite the threshold; the Commission decides. The duty is not simply a FLOP calculation and a tick box.

Provider, integrator and modifier

A company using an API inside its service will commonly be the provider of the downstream system rather than the provider of somebody else's GPAI model. It must request the information needed from the model provider and meet the rules applying to its own system and use. Responsibility has not disappeared; it sits at a different layer.

The position may change if the company modifies or fine-tunes a model and places it on the market under its own name. The AI Office's questions and answers explain that not every modification creates a new provider and give the amount of compute used relative to the original model as an indicative criterion. This is guidance for analysing a case, not a universal licence to remain outside scope.

Models and systems must also remain separate. Chapter V duties follow the GPAI model regardless of its final use; rules for AI systems additionally depend on deployment context. One model may power anything from a text editor to a high-risk system. Documentation from the model provider enables the integrator's own assessment but does not replace it.

A useful check before 2 August

A minimum inventory connects model name and version, the entity placing it on the market, date of first EU placement, licence type, available documentation and possible systemic risk. Each duty should have an owner, document version, update date and delivery route to the AI Office or downstream integrators.

Then check the evidence: technical documentation; a capabilities and limitations record; copyright policy; training-content summary; authorised representative where needed; and, for systemic risk, notification, evaluations, mitigations, incidents and cybersecurity. The official GPAI Code page collects its three chapters as a voluntary route for part of this work.

The 2026 date does not turn compliance into a last-day task. It turns missing evidence into a risk the Commission can enforce. The durable method is to connect every model, version and date to a specific duty and verifiable document. A particular legal decision requires checking the law then in force and the facts with competent advice; a general checklist cannot replace that analysis.

This article was produced with artificial intelligence under human editorial oversight.

Share this article

This website uses cookies to improve the browsing experience. Cookie policy.

↑↓ navigate ↵ open esc close