Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Provider vs user of GPAI
Most ordinary businesses are users of third-party GPAI tools, not providers of GPAI models. But if your company develops or releases a model that can support many downstream tasks, the analysis changes. Providers of GPAI models face specific obligations, and providers of models with systemic risk face additional expectations.
Questions for vendors
- Does the product rely on a GPAI model, and which one?
- What documentation, transparency materials and model information are available?
- How are copyright, training data summary, safety and security handled?
- Are updates announced in advance when they may affect outputs or risk?
- Can enterprise customers control data retention, training use, logging and access?
What deployers should do
If you use GPAI through third-party tools, focus on approved-tool lists, data restrictions, procurement review, vendor documentation, user notices, human review and monitoring. Do not let employees select unsanctioned tools for sensitive business workflows.
Evidence to collect
Keep vendor contracts, data-processing terms, model cards or documentation, security information, training-data summaries where relevant, release notes, and internal approval notes.
FAQ
What does GPAI mean?
General-purpose AI models are models capable of performing a wide range of tasks and serving as a basis for many downstream systems.
Do I have GPAI obligations if I only use a chatbot?
You may not be a GPAI model provider, but you still need governance controls for how the tool is used.
Are GPAI rules already relevant?
Official EU materials indicate GPAI obligations became applicable in the phased timeline before the majority of rules.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.