What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

General-purpose AI model

A general-purpose AI model, under the EU AI Act, is an AI model general enough to perform many different tasks well and to be built into many downstream systems or applications. Large generative AI models are a typical example. Models used only for research, development or prototyping before release are excluded.

Last reviewed

Key points

  • Article 3(63) of the EU AI Act defines the term by generality. The model must handle many different tasks and fit into many downstream systems.
  • A model is not an AI system. A general-purpose AI system (Article 3(66)) is a system built on such a model that can serve a variety of purposes.
  • Providers must document the model, inform those who build on it, keep a copyright policy and publish a training-content summary (Article 53). Qualifying open-source models skip the two documentation duties unless they carry systemic risk.
  • A model trained with more than 10^25 floating point operations (FLOP) is presumed to carry systemic risk. Its provider must also evaluate it, including adversarial testing that tries to make it fail, assess and mitigate systemic risks, report serious incidents and secure it (Article 55).
  • The Commission's non-binding guidelines add a working test. A model is indicatively in scope above 10^23 FLOP of training compute if it generates language, images from text or video from text.

How the Act draws the line

A general-purpose AI model is defined by what it can do. Article 3(63) of the EU AI Act asks whether a model “displays significant generality” and can competently perform “a wide range of distinct tasks”. Recital 99 names large generative AI models as a typical example.

A model is not an AI system. Recital 97 says models “do not constitute AI systems on their own” and need further components, such as a user interface. A system built on the model that can serve a variety of purposes is a general-purpose AI system, defined separately in Article 3(66).

What providers must do

Article 53(1) lists four core duties for providers:

  • keep technical documentation for regulators
  • give documentation to companies that build the model into their systems
  • keep a policy to comply with EU copyright law
  • publish a summary of the content used for training

A model under a free and open-source licence, with its weights, architecture and usage information public, skips the first two, unless it carries systemic risk.

Systemic risk is a risk specific to the most capable models that can spread at scale (Article 3(65)). Training above 10^25 floating point operations (FLOP) creates a presumption of it (Article 51), and the Commission can designate other models. Article 55 then adds model evaluation “including conducting and documenting adversarial testing”, systemic-risk mitigation, serious-incident reporting and “an adequate level of cybersecurity protection”.

Why it matters

Article 55 makes adversarial testing and model cybersecurity legal duties for models with systemic risk, not good practice. Where Article 53 documentation is required, it must give companies building on a model a good understanding of its capabilities and limitations.

In practice

The European Commission’s non-binding guidelines add a number to the definition. A model is indicatively in scope when its training used more than 10^23 FLOP and it generates language, images from text or video from text. Generality still decides: a model trained with 10^24 FLOP only to transcribe speech is out, if that is all it can competently do.

Providers outside the EU must appoint an authorised representative in the Union, unless the model is released under a free and open-source licence with its parameters public and carries no systemic risk (Article 54). A provider whose model crosses 10^25 FLOP must notify the Commission within two weeks (Article 52).

The provider duties apply from 2 August 2025, or 2 August 2027 for models already on the market before then. From 2 August 2026, the Commission can fine a provider that intentionally or negligently breaks the rules up to 3% of the previous year’s worldwide turnover or EUR 15 million, whichever is higher.

Where definitions disagree

Foundation model is the research term for much the same thing. The 2021 Stanford report that coined it describes models “trained on broad data at scale” and “adaptable to a wide range of downstream tasks”.

The two terms overlap but are different tests. Foundation model describes how a model is built and used. The legal term turns on displayed generality and market status: it excludes models used for research, development or prototyping before release. The Commission reads it through an indicative compute-and-output test that can be overridden either way. Calling a model a foundation model does not settle whether the Act applies to it.

Questions and answers

What is the difference between a general-purpose AI model and a general-purpose AI system?

Under the EU AI Act, the general-purpose AI model is the trained model itself. A general-purpose AI system, defined in Article 3(66), is an AI system based on such a model that can serve a variety of purposes, such as a chatbot that can handle many kinds of request. Recital 97 says a model needs further components, such as a user interface, to become a system.

Is every large language model a general-purpose AI model?

Not automatically. The EU AI Act tests generality, not model type. The Commission's non-binding guidelines treat a model trained with more than 10^23 FLOP that generates language as indicatively in scope. Their examples put a model trained on natural language with 10^22 FLOP that cannot competently perform a wide range of tasks out of scope. Models used only for research, development or prototyping before release are excluded.

When does a general-purpose AI model have systemic risk?

Under Article 51 of the EU AI Act, a model has systemic risk if it has high impact capabilities, meaning capabilities that match or exceed those of the most advanced general-purpose AI models, presumed when training used more than 10^25 floating point operations, or if the Commission designates it for equivalent capabilities or impact.

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Article 3: DefinitionsEuropean Union, 12 Jul 2024
  2. Commission Guidelines on the scope of the obligations for providers of general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act), C(2025) 7719 finalEuropean Commission, 19 Nov 2025
  3. On the Opportunities and Risks of Foundation ModelsStanford Center for Research on Foundation Models (arXiv), 16 Aug 2021