The General Purpose AI provisions of the EU AI Act were not in the original Commission proposal. They were added in the parliamentary process in 2023, partly in direct response to ChatGPT’s public release in November 2022 and the sudden political urgency of governing large language models. They were added late, they were negotiated quickly, and they show it — the GPAI chapter is the regulation’s least technically precise section, and it has generated more legal uncertainty per word than any other part of the Act.
This is significant because the GPAI provisions are the part of the regulation that governs the most powerful AI systems in the world. GPT-4o, Claude 3.5 Sonnet, Gemini 1.5 Ultra, Llama 3. Systems trained on computational budgets that exceed the 10^25 FLOP threshold for “systemic risk” designation. Systems that generate regulatory obligations more demanding than those faced by most high-risk application AI.
Understanding what these obligations actually require — and more importantly, how OpenAI, Anthropic, and Google are responding to them — is the most important story in EU AI Act enforcement and also the one getting the most analysis-free coverage.
The Two Tiers of GPAI
The Act creates a two-tier structure for general-purpose AI models. All GPAI models distributed in the EU face a baseline tier: they must provide technical documentation adequate for deployers to understand what the model can and cannot do; they must maintain copyright compliance policies for training data; they must implement policies allowing rights holders to opt out of training data use under applicable EU law.
GPAI models trained on computational budgets exceeding approximately 10^25 floating-point operations face a second tier: systematic risk evaluation; adversarial testing; incident reporting to the EU AI Office; and cybersecurity measures “adequate to the risks.” The threshold is a proxy for capability — the assumption being that sufficiently large models are sufficiently capable to warrant additional scrutiny.
The baseline tier is annoying but manageable. The technical documentation requirements are detailed but analogous to what sophisticated enterprise customers already demand. Copyright compliance has created its own legal complexity — Axel Springer’s lawsuit against OpenAI in German courts over training data rights is proceeding independently of the AI Act, but the Act’s requirement to maintain a copyright policy means GPAI providers need a written policy regardless of the underlying legal questions about whether training on copyrighted material is permissible.
The systemic risk tier is where things get genuinely complex and contested.
What “Adversarial Testing” Means in Practice
The EU AI Office published technical guidelines for GPAI systemic risk evaluation in March 2026. The guidelines specify that adversarial testing — what the AI industry calls “red-teaming” — must be conducted by “independent third parties” with “sufficient expertise to evaluate the specific risks associated with the model.”
This requirement is more demanding than it sounds. Red-teaming a frontier model at the scale the guidelines contemplate — covering behavioral risks, safety risks, societal risks, and misuse potential — requires teams with deep technical AI expertise, information security background, and domain knowledge across the risk categories the model might affect. There are perhaps 300 to 400 people globally with sufficient qualifications to conduct this kind of evaluation credibly. They are employed by AI labs, government agencies, and a small number of specialist research organizations.
The demand for qualified independent red-teamers exceeds supply by a significant margin. Anthropic’s EU-market adversarial testing, commissioned in Q1 2026, was conducted by a team from a UK-based AI safety research organization under a contract that reportedly cost $800,000 and took four months. OpenAI used a similar arrangement. Google’s Gemini models were evaluated by a consortium including three European universities and a specialist cybersecurity firm.
These arrangements are functional but expensive and slow. The EU AI Office’s guidelines require evaluation to be repeated when “significant changes” are made to a model. Given that frontier model providers update their models on timescales ranging from weeks to months, the operational requirement for frequent re-evaluation creates a practical tension between the regulation’s requirement for current evaluation and the reality of rapid model development.
OpenAI released GPT-4o-mini in May 2026. Whether a new model version constitutes a “significant change” requiring new systematic risk evaluation is not definitively specified. OpenAI’s position, documented in their compliance filing with the EU AI Office, is that point releases of existing models that don’t materially change capability profiles don’t trigger new systemic risk evaluation requirements. The EU AI Office has not formally endorsed or rejected this position.
This interpretive gap will eventually be resolved by either a formal guidance update or an enforcement case. Until it is, frontier AI providers are operating on their own legal interpretation of what the regulation requires — which is to say, they’re operating on interpretations developed by lawyers who have a professional obligation to protect their clients’ interests.
The Transparency Problem
The GPAI technical documentation requirements ask for something that creates genuine tension with AI companies’ business models and competitive interests: meaningful transparency about model capabilities, limitations, and training data.
The capabilities documentation is straightforward — providers are required to characterize what the model can and cannot do across relevant task categories. This is public-facing product documentation, and providers had economic incentives to produce it even before the Act required it. OpenAI’s GPT-4 technical report, published in 2023, is a model of this kind of documentation (with significant limitations).
Training data documentation is more contentious. The Act requires GPAI providers to document their training data, including sources, filtering methodology, and copyright compliance measures. OpenAI, Anthropic, and Google have all produced some version of this documentation for EU compliance purposes. The documentation is, in each case, less specific than academic researchers and regulatory technologists would prefer.
Anthropic’s EU GPAI documentation for Claude 3.5 describes training data as “a large and diverse corpus of internet text, books, and other digital content, filtered for quality and safety.” This is accurate in its broad outlines and nearly uninformative about what specifically is in the training set, how filtering was conducted, or what specific copyright compliance measures were applied to identified copyrighted materials. It satisfies the Act’s documentation requirement in the sense that a document exists. It doesn’t satisfy the spirit of transparency that the requirement was designed to achieve.
The EU AI Office has publicly indicated that training data documentation is an area where current practice is “insufficient” — specifically, the July 2026 state-of-the-art assessment noted that GPAI providers’ training data documentation “does not yet meet the standard of specificity that would enable meaningful independent auditing.” The Office has not issued formal violation notices based on this assessment. The subtext: the standard is being negotiated, not simply enforced.
Incident Reporting and What It Actually Means
The systemic risk GPAI tier requires providers to report “serious incidents” to the EU AI Office. A serious incident is defined as “an incident or malfunctioning of a GPAI model with systemic risk that gives rise to a risk to public safety, public security, or fundamental rights.”
In eight months of enforcement, three incidents meeting this threshold have been formally reported to the EU AI Office by GPAI providers — all three by US-based providers (the identities have not been disclosed publicly, but the Office confirmed the count in its July 2026 report). All three involved outputs from deployed models used by third parties in harmful ways, rather than fundamental model failures.
The reporting mechanism’s functionality is hard to assess from three data points. What’s more telling is what hasn’t been reported. There have been documented cases in 2025 and 2026 of frontier AI models being used to generate disinformation at scale, to assist in financial fraud, and in one high-profile German case, to produce materials used in a domestic violence context. Whether any of these constituted reportable “serious incidents” under the GPAI definition is contested.
The incident reporting framework, like much of the GPAI chapter, is operational in form but early in establishing the substantive norms that will make it meaningful. The first major dispute between the EU AI Office and a GPAI provider over whether an incident should have been reported — whenever it comes — will reveal more about the regulation’s real teeth than anything the Act’s text says. Brussels and Silicon Valley are in an early phase of relationship definition. The pleasant phase.
What the Fines Actually Look Like
The AI Act’s penalties for GPAI providers are, on paper, formidable. Non-compliance with GPAI systemic risk obligations can attract fines of up to 3 percent of global annual turnover, or €15 million — whichever is higher. For OpenAI, with estimated revenues of $10+ billion annually by 2026, 3 percent means $300 million plus.
These numbers generate headlines. They’re less meaningful in context. GDPR allows fines of up to 4 percent of global turnover. Google has been fined under GDPR 14 times, including the €4.34 billion Android fine in 2018 (later reduced to €4.125 billion on appeal). These fines are real; they also haven’t meaningfully altered Google’s market position or business model. The fine-as-deterrent model works better in theory than practice when the regulated company’s profit margins absorb the fine comfortably.
The more practically significant penalty in the AI Act is market access restriction — the theoretical authority of the EU AI Office to require a non-compliant GPAI model to be withdrawn from the EU market. For a company like OpenAI, losing European market access would be genuinely serious. Europe represents a significant share of their API revenue. The threat of exclusion is more powerful than any specific fine amount.
But market exclusion orders are legally demanding. They require evidence of systemic risk, procedural fairness, proportionality review, and are subject to challenge in EU courts. No market exclusion order for a GPAI model has been issued. The legal and political difficulty of excluding a major US AI system from the European market — with all the diplomatic freight that entails — makes this a theoretical deterrent that Brussels has been careful not to test. The real enforcement dynamic is somewhere between the theoretical maximum and the current pleasant phase. Finding out where requires someone to push first.
One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.
