Who Counts as a 'General-Purpose AI Provider' Under the EU AI Act

General-purpose AI providers are companies whose models — GPT, Claude, Gemini, Llama, and similar broadly-capable systems — meet the EU AI Act's legal threshold for regulation as foundational technology, triggering transparency, copyright, and (for the largest models) systemic-risk obligations.

Created 2026-08-08 Last reviewed 2026-08-08

What it is

“General-purpose AI provider” is a legal category created by the European Union’s AI Act, not an industry term of art. Article 3(63) of the Act defines a general-purpose AI (GPAI) model as one that “displays significant generality,” was typically trained on large amounts of data using self-supervision at scale, and “is capable of competently performing a wide range of distinct tasks” regardless of how it is packaged or sold. In practice, this describes the large foundation models that underpin most of today’s generative AI products — OpenAI’s GPT family, Anthropic’s Claude, Google’s Gemini, Meta’s Llama, and comparable systems from Mistral, Amazon, and others. A “provider” is the company or entity that develops such a model and places it on the EU market, whether directly or by licensing it into other companies’ products.

The category matters because the AI Act does not primarily regulate AI by what it does in a given application (a chatbot, a hiring tool, a medical device) — it separately regulates the underlying general-purpose models themselves, since one model can be repurposed into many different downstream systems with very different risk profiles. Article 53 sets baseline obligations for every GPAI provider: maintain technical documentation of how the model was built and evaluated, share relevant technical information with companies building products on top of the model, adopt a policy for complying with EU copyright law (including honoring rights holders’ opt-outs from AI training), and publish a public summary of the content used to train the model, following a template issued by the EU’s AI Office. A smaller subset of providers — those whose models are judged to pose “systemic risk,” a threshold defined partly by the computing power used in training — face additional obligations under Article 55, including adversarial testing, incident reporting, and cybersecurity safeguards.

To help providers meet these requirements before formal technical standards exist, the European Commission published a voluntary General-Purpose AI Code of Practice, finalized in July 2025. Signatories — including Amazon, Anthropic, Google, Microsoft, OpenAI, Mistral AI, IBM, and Cohere — get a presumption of legal compliance in exchange for following the Code’s transparency, copyright, and safety commitments. Meta has publicly declined to sign, arguing the Code creates legal uncertainty; Chinese model developers are largely absent from the signatory list.

Why it matters for AI governance and narratives

The “general-purpose AI provider” label is one of the few places where a governance framework, rather than a company’s own marketing, decides who counts as an infrastructural actor in the AI ecosystem. That distinction is doing real work in the current framing contest: providers who sign the Code of Practice can present themselves as good-faith regulatory partners, while non-signatories like Meta can frame their abstention as resistance to regulatory overreach — both are strategic communications, not neutral positions, and the observatory’s symmetric-skepticism principle applies equally to each. The category also creates a two-tier regulatory story: the transparency and copyright obligations apply to essentially every general-purpose model, while the more demanding systemic-risk provisions apply only to the handful of frontier labs with the largest training runs, which shapes which companies get to describe EU compliance as burdensome versus routine.

The deadline structure compounds this. GPAI obligations became legally binding on 2 August 2025, but the Commission’s power to investigate, demand documentation, and fine non-compliant providers (up to 3% of global annual turnover or €15 million) only activated on 2 August 2026. That gap between legal obligation and enforceable penalty has itself become rhetorical material — a year in which providers could claim compliance without facing consequences for falling short, and in which compliance vendors marketed the approaching enforcement date as urgency for their own services.

Key facts and dates

Where to learn more

Sources

Primary legal source for the statutory definition of a general-purpose AI model.
Primary legal text establishing documentation, downstream-information, copyright, and training-data-summary obligations for GPAI providers.
Official Commission source on the voluntary Code, its three chapters, and its role as a presumption-of-compliance mechanism.
Official Commission FAQ clarifying which companies and models fall within scope, including the systemic-risk threshold.
Secondary but authoritative explainer corroborating the Code's structure, timeline, and list of signatories versus non-signatories.
Referenced in: Editorial No. 251