What it is
“General-purpose AI provider” is a legal category created by the European Union’s AI Act, not an industry term of art. Article 3(63) of the Act defines a general-purpose AI (GPAI) model as one that “displays significant generality,” was typically trained on large amounts of data using self-supervision at scale, and “is capable of competently performing a wide range of distinct tasks” regardless of how it is packaged or sold. In practice, this describes the large foundation models that underpin most of today’s generative AI products — OpenAI’s GPT family, Anthropic’s Claude, Google’s Gemini, Meta’s Llama, and comparable systems from Mistral, Amazon, and others. A “provider” is the company or entity that develops such a model and places it on the EU market, whether directly or by licensing it into other companies’ products.
The category matters because the AI Act does not primarily regulate AI by what it does in a given application (a chatbot, a hiring tool, a medical device) — it separately regulates the underlying general-purpose models themselves, since one model can be repurposed into many different downstream systems with very different risk profiles. Article 53 sets baseline obligations for every GPAI provider: maintain technical documentation of how the model was built and evaluated, share relevant technical information with companies building products on top of the model, adopt a policy for complying with EU copyright law (including honoring rights holders’ opt-outs from AI training), and publish a public summary of the content used to train the model, following a template issued by the EU’s AI Office. A smaller subset of providers — those whose models are judged to pose “systemic risk,” a threshold defined partly by the computing power used in training — face additional obligations under Article 55, including adversarial testing, incident reporting, and cybersecurity safeguards.
To help providers meet these requirements before formal technical standards exist, the European Commission published a voluntary General-Purpose AI Code of Practice, finalized in July 2025. Signatories — including Amazon, Anthropic, Google, Microsoft, OpenAI, Mistral AI, IBM, and Cohere — get a presumption of legal compliance in exchange for following the Code’s transparency, copyright, and safety commitments. Meta has publicly declined to sign, arguing the Code creates legal uncertainty; Chinese model developers are largely absent from the signatory list.
Why it matters for AI governance and narratives
The “general-purpose AI provider” label is one of the few places where a governance framework, rather than a company’s own marketing, decides who counts as an infrastructural actor in the AI ecosystem. That distinction is doing real work in the current framing contest: providers who sign the Code of Practice can present themselves as good-faith regulatory partners, while non-signatories like Meta can frame their abstention as resistance to regulatory overreach — both are strategic communications, not neutral positions, and the observatory’s symmetric-skepticism principle applies equally to each. The category also creates a two-tier regulatory story: the transparency and copyright obligations apply to essentially every general-purpose model, while the more demanding systemic-risk provisions apply only to the handful of frontier labs with the largest training runs, which shapes which companies get to describe EU compliance as burdensome versus routine.
The deadline structure compounds this. GPAI obligations became legally binding on 2 August 2025, but the Commission’s power to investigate, demand documentation, and fine non-compliant providers (up to 3% of global annual turnover or €15 million) only activated on 2 August 2026. That gap between legal obligation and enforceable penalty has itself become rhetorical material — a year in which providers could claim compliance without facing consequences for falling short, and in which compliance vendors marketed the approaching enforcement date as urgency for their own services.
Key facts and dates
- The AI Act’s GPAI definition and provider obligations are set out in Articles 3(63) and 53; systemic-risk obligations for the largest models are in Article 55.
- GPAI provider obligations began applying on 2 August 2025; the Commission’s enforcement and fining powers over those obligations activated on 2 August 2026.
- Models already on the EU market before August 2025 have until 2 August 2027 to reach full compliance.
- The voluntary GPAI Code of Practice was finalized in July 2025; signatories include Amazon, Anthropic, Google, Microsoft, OpenAI, Mistral AI, IBM, and Cohere, while Meta declined to sign.
- Enforcement authority sits with the EU AI Office, a unit within the European Commission, centralizing GPAI oversight rather than leaving it to individual member states.
Where to learn more
- Article 3: Definitions — EU Artificial Intelligence Act — primary legal text defining “general-purpose AI model.”
- Article 53: Obligations for Providers of General-Purpose AI Models — primary legal text of the core provider obligations.
- European Commission: The General-Purpose AI Code of Practice — official Commission page on the voluntary compliance framework and its signatories.
- European Commission: General-Purpose AI Models in the AI Act — Questions & Answers — official Commission FAQ clarifying scope and thresholds.