Since 2 August 2025, general-purpose AI models (GPAI) such as ChatGPT, Claude, Gemini or Llama have been subject to a specific regime. If your company uses one of these models to build a product or service, you have obligations.
General-purpose AI models (GPAI) are models trained on large amounts of data and capable of performing a wide range of tasks: writing, code, analysis, conversation, image generation. Examples: GPT-4o (OpenAI), Claude 3.5 (Anthropic), Gemini (Google), Llama (Meta), Mistral.
According to Article 51 of the EU AI Act, a GPAI model is an AI model trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks. The technical criterion: a threshold of 10^23 FLOP of compute used for training distinguishes standard GPAI models from systemic risk models.
If you use ChatGPT, Claude or Gemini via an API to build a product or service for European users, you are a deployer. Your main obligations:
Using a model from a major provider (OpenAI, Anthropic, Google) does not exempt you from your obligations. The model's compliance does not equal the compliance of your use of the model.
This is the most immediate obligation for GPAI model deployers: since 2 August 2026, your users must know they are interacting with AI. In practice:
Models exceeding 10^23 FLOP of compute (including GPT-4, Claude 3 Opus, Gemini Ultra) are subject to additional obligations imposed on their providers: adversarial evaluation, serious incident reporting, cybersecurity measures. For you as a deployer, these additional obligations do not directly change your responsibilities - they are the responsibility of the model provider.
Check your obligations in 17 questions. Free educational simulator.
Start the simulator