Back to Blog
EU AI Act

General-purpose AI: the Chapter V obligations

Published 16 October 20265 min readBy EmberHound

Chapter V sets duties for providers of general-purpose AI models, and a second, heavier set for models classed as carrying systemic risk. Here is what each covers, and which parts reach you if you only use these models.

Chapter V is the part of the AI Act that deals with general-purpose AI models rather than AI systems put to a particular use. It runs on a different track from the high-risk regime: the duties attach to the model provider, and they attach whatever the model is later used for.

Most organisations reading this are downstream of a general-purpose model rather than providers of one. The useful thing to know is which duties are the provider's, and which of them produce documentation you should be receiving.

What every GPAI provider has to do

Article 53(1) sets four obligations on providers of general-purpose AI models:

  1. 1Draw up and keep up to date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at a minimum the information in Annex XI, for provision on request to the AI Office and national competent authorities.
  2. 2Draw up, keep up to date and make available information and documentation to providers of AI systems who intend to integrate the model into their systems, containing at a minimum the elements in Annex XII.
  3. 3Put in place a policy to comply with Union copyright law, and in particular to identify and comply with a reservation of rights expressed under Article 4(3) of Directive (EU) 2019/790, including through state-of-the-art technologies.
  4. 4Draw up and make publicly available a sufficiently detailed summary about the content used for training the model, according to a template provided by the AI Office.

The second of those is the one that matters most to a downstream builder. It is the provision that entitles you to documentation good enough, in the article's own words, to have a good understanding of the capabilities and limitations of the model and to comply with your own obligations under the regulation. It carves out intellectual property and trade secrets, so it is not a right to see the model, but it is a right to be equipped.

The open-source carve-out, and its limit

Article 53(2) disapplies the first two obligations for providers of models released under a free and open-source licence permitting access, usage, modification and distribution, where the parameters including the weights, the model architecture information, and the model usage information are made publicly available.

Two things are worth reading carefully. The carve-out covers points (a) and (b) only, so the copyright policy and the training-content summary still apply. And the last sentence of the paragraph removes it entirely for models with systemic risk.

What makes a model systemic-risk

Article 51 gives two routes. A model is classified as carrying systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies including indicators and benchmarks, or if the Commission decides, on its own initiative or following a qualified alert from the scientific panel, that it has equivalent capabilities or impact having regard to the criteria in Annex XIII.

Article 51(2) adds a presumption with a number attached: a model is presumed to have high impact capabilities when the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10 to the power of 25. Article 51(3) provides for the Commission to amend that threshold by delegated act as the state of the art moves, so it is a current figure rather than a fixed one.

The threshold is a presumption, not a definition. A model below it can still be classified through the Commission route in Article 51(1)(b), and the figure itself is designed to be revised.

The additional duties for systemic-risk models

Article 55(1) adds four obligations on top of Articles 53 and 54:

  • Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing to identify and mitigate systemic risks.
  • Assess and mitigate possible systemic risks at Union level, including their sources, stemming from development, placing on the market, or use of the model.
  • Keep track of, document, and report without undue delay to the AI Office and, as appropriate, national competent authorities, relevant information about serious incidents and possible corrective measures.
  • Ensure an adequate level of cybersecurity protection for the model and for the physical infrastructure of the model.

Article 52 requires a provider whose model meets the Article 51(1)(a) condition to notify the Commission without delay. Classification is not something a provider is entitled to sit on.

Codes of practice, and what they buy

Both Article 53(4) and Article 55(2) allow providers to rely on codes of practice within the meaning of Article 56 to demonstrate compliance, until a harmonised standard is published. Compliance with European harmonised standards grants a presumption of conformity to the extent those standards cover the obligations.

A provider that neither adheres to an approved code of practice nor complies with a harmonised standard has to demonstrate alternative adequate means of compliance, for assessment by the Commission. The route is optional; being able to show compliance is not.

What this means if you are downstream

None of Chapter V lands on you for using a model. What it does is create documentation you should be able to obtain, and that documentation feeds the obligations that do land on you: the Article 26 deployer duties if the system you build or buy is high-risk, and the Article 50 transparency duties depending on how the system interacts with people.

So the practical question is not whether Chapter V applies to you. It is whether you know which general-purpose models sit underneath the tools your organisation uses, and whether you have the Annex XII documentation for each.

How EmberHound fits

That question is an inventory question, and it is harder than it sounds because the model is usually two layers down: a department buys a tool, the tool is built on a model, and nobody wrote down which. The AI Act Workspace records the AI systems an organisation uses and what each is used for, so the models underneath them can be traced rather than guessed at. It is in early access.

This article is general information, not legal advice. It describes Chapter V as consolidated at 27 July 2026.

Sources & references

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) - EUR-Lex
  2. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) - EUR-Lex
  3. Regulation (EU) 2024/1689 - consolidated text as at 27 July 2026 - EUR-Lex
  4. AI Act - regulatory framework for artificial intelligence - European Commission

Want more of this in Google?

See what personal data your endpoints are hiding

EmberHound scans your devices for GDPR and PCI data automatically - no manual discovery required.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy