EU AI Act GPAI Rules: The Numbers You Have to Defend

Last Updated : October 4, 2026
Share Article

Table of Contents

Chapter V of the AI Act is a self-assessment regime wearing the clothes of a rulebook. Nobody inspects a general-purpose AI model before it ships. No authority issues a classification. The provider calculates a handful of figures about its own model, those figures decide which obligations attach, and the Commission arrives later with the power to disagree and a five-year memory.

GPAI compliance therefore turns on arithmetic long before it turns on paperwork. Five measurements do the work: training compute, modification compute, market reach, training-data share and domain rank. Annex XI then asks for a sixth figure, known or estimated energy consumption, as part of the file rather than as a trigger.

Get one of the five wrong and you land in the wrong regime, either exposed or over-documented. The Commission has published the formulas, the inclusions, the exclusions and the tolerance it will accept, and almost none of that material appears in the coverage of this subject.

What follows works through each number, what it switches on, and what a provider has to keep in order to stand behind it.

Training compute carries two definitions, and the one that applies depends on the question

General-purpose AI models are measured twice, by two different definitions of the same word. Guidelines paragraph 115 carries the distinction that most summaries skip. Training compute means one thing when the question is whether a model is general-purpose at all, and another when the question is systemic risk.

For a model that is not a general-purpose AI model with systemic risk, training compute is “the total amount of compute directly contributing to parameter updates in the model.” For the systemic-risk question it is “the cumulative amount of compute used to train the model.” Cumulative is the wider measure. A provider running one calculation and applying it to both thresholds will get at least one of them wrong.

General-purpose AI model figures then switch on different bodies of law. Guidelines paragraph 17 gives the indicative criterion for a general-purpose AI model. Training compute must be “greater than 10^23 FLOP and it can generate language (whether in the form of text or audio), text-to-image, or text-to-video”. Paragraph 18 describes that as roughly the compute “typically used to train a model with one billion parameters on a large amount of data.” Crossing it points at Article 53 and Article 54.

Article 51(2) draws the second line for a general-purpose AI model. A general-purpose AI model “shall be presumed to have high impact capabilities” where cumulative training computation “is greater than 10^25.” Presumed, not defined. Greater than, not equal to or greater than. Crossing it points at Article 52 notification and the whole of Article 55.

GPAI classification is not settled by either number on its own. Paragraph 20 puts a model above 10^23 that “exceptionally, does not display significant generality” outside the definition, and a model below it that exceptionally does display such generality inside.

Worked examples place transcription, text-to-speech, image upscaling, inpainting, chess and video-game models, weather models, music generation and sound-effect generation outside the definition even at 10^24 FLOP. Each performs only a narrow set of tasks. Article 51(2) is likewise rebuttable, and Article 52(2) lets a provider argue that its model, “due to its specific characteristics,” presents no systemic risk.

Recital 111 pulls compute in, and paragraph 119 pushes some of it back out

Cumulative compute reaches further than a training job report shows. Recital 111 includes “the computation used across the activities and methods that are intended to enhance the capabilities of the model prior to deployment, such as pre-training, synthetic data generation and fine-tuning”. Guidelines paragraph 116 turns that into a working rule: providers “should, as a general rule, account for all compute that contributed or will contribute to the model’s capabilities.”

General-purpose AI model sums have three inclusions to settle first. Paragraph 117 counts the forward passes used to generate synthetic data that is not publicly accessible, including discarded data. Its worked example: “if 100 samples were generated and only the top 10 samples were selected for training, the compute used to generate all 100 samples should be counted”.

Paragraph 118 counts the compute used to train weights that were later merged, averaged or used for initialisation. Paragraph 122 counts all operations equally, “independently of floating-point precision,” so a low-precision run buys no relief.

General-purpose AI model providers routinely assume a list of items is chargeable, and paragraph 119 removes them. Compute used to generate synthetic data that is publicly accessible falls out, “since it may be indistinguishable from other publicly accessible data.”

So does compute spent on “purely diagnostic processes that do not contribute to enhancing model capabilities, such as model evaluations or red-teaming.” So does compute on exploratory research and on failed synthetic-data experiments whose results are discarded. Distillation parent models fall out. So do auxiliary models such as value functions or reward models, and recomputation of activations to save memory.

Read together, those paragraphs answer the question engineering teams building a general-purpose AI model actually ask. Your evaluation runs do not count against you. Your discarded private synthetic data does.

Thirty per cent is the tolerance, and the assumptions travel with the number

Estimates come with a published tolerance. Paragraph 120 is the most practically useful sentence in the Guidelines, and one almost entirely absent from commentary on general-purpose AI models.

Providers “may choose any method to estimate the relevant amount of training compute, so long as the estimated amount is, in the providers’ best judgement, accurate within an overall error margin of 30% of the reported estimate.” The same paragraph requires documentation of “the assumptions made in making their estimations, including the method of estimation, and the associated uncertainties”.

General-purpose AI model compute has two named estimation methods. The hardware-based approach multiplies hardware units, duration in seconds, peak theoretical performance in FLOP per second and average utilisation. Paragraph 124 gives the formula: C = N · L · H · U.

Where unit counts changed during the run, paragraph 125 applies the formula per period and sums the results. The architecture-based approach counts operations directly, and paragraph 129 offers the familiar approximation for dense transformer language models: C ≈ 6 · P · D, where P is parameters and D is training tokens.

GPAI notifications carry a specified precision as well as a deadline. Article 52(1) requires notification to the Commission “without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met.”

Guidelines paragraph 31 then requires the compute figure “reported in FLOP and with two significant figures (e.g. 2.3×10^25 FLOP)” together with the estimation approach. Recital 112 explains why the duty can fall due before training ends: runs are planned and compute allocated up front, so providers “are able to know if their model would meet the threshold before the training is completed.”

Nobody official has ever counted the general-purpose AI models above the systemic-risk line. Epoch AI‘s large-scale models dataset, downloaded on 18 September 2026, holds 531 entries, of which 323 carry a published training-compute estimate. Twenty-one of those sit at or above 10^25 FLOP and three at or above 10^26.

The remaining 208 entries carry no compute figure at all, so twenty-one is a floor rather than a census, and every figure is a third-party estimate built from hardware and architecture reasoning rather than a provider disclosure.

Your second measurement runs against someone else’s denominator

GPAI provider status does not transfer on fine-tuning alone. Guidelines paragraph 59 sets the principle: a downstream modifier becomes the provider “only if the modification leads to a significant change in the model’s generality, capabilities, or systemic risk.” Paragraph 60 supplies the arithmetic. The indicative criterion is that “the training compute used for the modification is greater than a third of the training compute of the original model.”

The fraction has a denominator a downstream modifier often cannot see. Paragraph 61 handles it. Where the modifier cannot know the original figure and cannot estimate it, the threshold becomes one third of the relevant statutory number. For a systemic-risk original that is a third of 10^25, roughly 3.3 x 10^24 FLOP.

For any other general-purpose AI model it is a third of 10^23, roughly 3.3 x 10^22 FLOP. Footnote 13 adds a factual test for who performed the modification at all, pointing to “who has the control over the model’s weights, for example, in case of fine-tuning via API.”

A general-purpose AI model crossing that line transfers less than teams fear. Paragraph 65, following recital 109, limits the inherited obligations to the modification: Annex XI and Annex XII documentation covers information on the modification, while the copyright policy and the training-content summary cover only “the data used as part of the modification.” Paragraph 66 adds Article 54, so a third-country modifier that becomes a provider needs its own authorised representative.

One inherited duty is heavier, and it catches mid-sized companies by surprise. Paragraph 67 provides that where the original is a general-purpose AI model with systemic risk and the modification makes you its provider, “the resulting model is presumed to have high-impact capabilities.” Article 55 attaches in full, along with the two-week notification.

Provider status rarely changes hands this way today. Paragraph 64 is candid about it. Currently, the Commission says, “few modifications may meet the criterion set out in paragraph 60”, though the number of downstream modifiers that become providers “may increase over time”. The criterion is described as “primarily forward-looking.”

Read plainly, an adapter tuned for style sits nowhere near the line and a serious continued-pretraining run on a small open model may not. Do the calculation either way and keep it, because the answer to an accusation is a compute estimate with its assumptions attached, not a recollection that you felt safe.

Market reach is a threshold that ignores compute entirely

General-purpose AI models can be designated on reach alone, under a second quantitative presumption that receives almost no coverage. Point (f) treats a model as having high impact on the internal market where “it has been made available to at least 10 000 registered business users established in the Union.” Nothing in that test looks at FLOP.

GPAI designation can also arrive without any threshold being crossed. Article 51(1)(b) lets the Commission classify a model on the Annex XIII criteria of its own motion, or following a qualified alert from the scientific panel. The panel was appointed on 1 June 2026 and consists of sixty independent experts. Annex XIII also lists parameter count, dataset size in tokens, modalities, benchmark performance, autonomy and tool access, and registered end-user numbers, so the route is wider than compute and wider than business users.

A general-purpose AI model designation is not permanent. Article 52(5) lets a designated provider request reassessment on “objective, detailed and new reasons that have arisen since the designation decision,” at the earliest six months after the decision, and six months again after any decision maintaining it.

Naming your training data is a ranking exercise, not a full disclosure

Article 53(1)(d) requires a public summary of training content “according to a template provided by the AI Office.” The Explanatory Notice and Template, published 24 July 2025 and adopted as a Communication on 5 December 2025, states at paragraph 4 that the Template “holds important legal value” precisely because providers must draw the summary up according to it.

Two numbers fix how deep a general-purpose AI model provider must go. A dataset must be itemised where it is large. Large means total data size for any one modality that “exceeds 3% of the size of all publicly available datasets for that modality used for training.” Size is measured after pre-processing.

The Template blocks the obvious workaround by requiring it “without splitting the dataset to prevent reporting circumvention.” Crawled content is disclosed by rank. The Template asks for “the top 10 % of all domain names determined by the size of the content scraped.” SMEs disclose the “top 5% of all domain names or 1 000 internet domain names, whichever is lower.”

Volume is reported only in bands, so a text-generating general-purpose AI model states whether it used under one billion tokens, between one billion and ten trillion, or more than ten trillion. Banding is why the exercise is a ranking rather than an inventory, and why the summaries published so far carry little quantitative content.

Publication timing is specified for a general-purpose AI model training summary, and often missed. Paragraph 32 of the Template requires publication “at the latest when the model is placed on the Union market.” Publication goes on the provider’s official website “in a clearly visible and accessible manner”, and again “together with the model across all its public distribution channels”.

Paragraph 29 sets the refresh rule conditionally: where the provider further trains its model on additional data that requires an update, the summary is updated at six-month intervals or sooner if the additional data requires a materially significant update.

Article 53(1)(c) sits alongside it and is the quieter half. The copyright policy must “identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790.” Machine-readable opt-outs are the operative mechanism, and the Commission ran a consultation on reservation protocols from 1 December 2025 to 23 January 2026.

Annex XI answers the regulator and Annex XII answers your customer

GPAI documentation splits across two annexes written for two different readers. Merging them is a common and expensive error.

Annex XI, produced under Article 53(1)(a), is held for the AI Office and national competent authorities on request. Its first section covers intended tasks, acceptable use policies, release date and distribution methods, architecture and parameter count, modalities and licence, then design specifications and training methodology, data provenance and curation, bias-detection measures, computational resources in floating point operations, and known or estimated energy consumption. Section 2 adds three items for systemic-risk models: evaluation strategies with results, adversarial testing measures including red teaming, and system architecture.

Annex XII, produced under Article 53(1)(b), goes to downstream providers so they can meet their own obligations. Its opening general description runs to eight sub-points against the six in Annex XI, adding how the model interacts with external hardware or software and the versions of relevant software. Its second section adds maximum input and output size, including context window length.

One drafting difference decides how much work each represents. Annex XI opens with the qualifier “as appropriate to the size and risk profile of the model.” Annex XII carries no such qualifier. What a provider owes the regulator scales with what it is. What it owes its customers does not.

Systemic risk attaches evaluation, mitigation, incident reporting and cybersecurity

Systemic risk adds four obligations at Article 55(1). Its opening words make them cumulative for a general-purpose AI model: “In addition to the obligations listed in Articles 53 and 54.” Providers must perform model evaluation “in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing.”

Providers must assess and mitigate systemic risks at Union level, including their sources. Serious incidents and possible corrective measures go to the AI Office “without undue delay,” and only “as appropriate” to national authorities. Cybersecurity protection must cover the model “and the physical infrastructure of the model.”

Serious incidents mean something narrower and stranger for a model than for a high-risk system. Guidelines paragraph 100 records that the concept covers “serious cybersecurity breaches related to the model or its physical infrastructure, including the (self-)exfiltration of model parameters and cyberattacks.”

The Commission published a dedicated reporting template for systemic-risk model incidents on 4 November 2025. A separate consultation on draft guidance and a template for Article 73 incidents involving high-risk systems ran from 26 September to 7 November 2025, and no final Article 73 guidance has been published since, so the two instruments should not be merged.

The open-source exception tests your licence, not your weights

GPAI providers do not buy the open-source exception by publishing weights. Article 53(2) removes only points (a) and (b) of Article 53(1), leaving the copyright policy and the training-content summary fully owed, and footnote 4 of the Template says so directly. The exception fails entirely for a model with systemic risk, and Article 54(6) mirrors the same carve-out for the authorised representative duty.

Qualification turns on the licence terms attached to the general-purpose AI model. Guidelines paragraph 80 lists what disqualifies: non-commercial or research-only limits, prohibitions on distributing the model or its components, requirements to obtain separate commercial licences for specific use cases, and “usage restrictions triggered by user scale thresholds (e.g. requiring additional licensing if monthly active users exceed a certain number).” Paragraph 81 preserves “specific, safety-oriented terms that reasonably restrict usage” where proportionate and based on objective, non-discriminatory criteria.

Monetisation destroys the exception for a general-purpose AI model, and paragraphs 82 to 86 define it broadly. Exclusive hosting on a paid platform counts, as does free access served with paid advertisements, and paid support indistinguishably linked to the model. Paragraph 84 goes further still, treating access that requires the collection or processing of personal data “in same manner as monetisation strategies” unless that processing is strictly limited to the security of the model. Paragraph 86 relieves transactions between microenterprises.

A separate confusion has propagated through technical forums and is worth killing. Article 2(12) exempts AI systems released under free and open-source licences from the Regulation, subject to exceptions. General-purpose AI models are governed instead by Articles 53(2) and 54(6), which are narrower and differently drafted. The two provisions are not interchangeable, and a page that cites the first to a model provider is citing the wrong law.

Placing on the market is the event that makes every number due

GPAI obligations under Articles 53 and 54 fall due only when the model is placed on the market, defined in Article 3(9) as “the first making available of an AI system or a general-purpose AI model on the Union market.” Guidelines paragraph 51 lists the routes, and the list is wider than a launch announcement.

A software library counts. An API counts. Upload to a public catalogue, hub or repository counts. A physical copy counts. A cloud service counts. Copying onto a customer’s own infrastructure counts. Integration into a web chatbot counts, as does integration into a mobile application shipped through an app store.

The final entry catches companies that believe themselves outside. A general-purpose AI model is placed on the market where it “is used for internal processes that are essential for providing a product or service to third parties or that affect the rights of natural persons in the Union.” An internal coding assistant used by your own engineers stays outside. A general-purpose AI model that routes support tickets for paying customers, or that scores applicants, does not.

General-purpose AI models are caught by the Union market, not by the provider’s address. Article 2(1)(a) reaches providers “placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country.”

Note the drafting asymmetry: AI systems are caught on placing on the market or putting into service, while for models only the first limb appears. Article 54(1) then requires a third-country provider to appoint an authorised representative in the Union by written mandate before the model reaches the market, and Article 54(3)(b) requires that representative to keep the Annex XI documentation available for ten years.

Legacy general-purpose AI models get one concession. Article 111(3) gives providers of general-purpose AI models placed on the market before 2 August 2025 until 2 August 2027 to comply. Guidelines paragraph 108 adds that retraining or unlearning is not required where the information is unavailable or retrieval would be disproportionate, provided the gaps are “clearly disclosed and justified” in the copyright policy and the training summary.

What the omnibus moved, and the two places it left behind

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and makes forty-three numbered amendments to the AI Act. Most coverage reduces it to the word delay, which is accurate for high-risk systems and misleading for everything here.

High-risk dates moved by up to sixteen months while GPAI dates did not move at all. Annex III systems ran from the general application date of 2 August 2026 and now run from 2 December 2027. Annex I systems ran from 2 August 2027 and now run from 2 August 2028.

Articles 51, 52, 53, 54, 55, 101, 111(3) and 113(b) are absent from the amendment list, and so are Annexes XI, XII and XIII. The GPAI obligations and the date the fining power vested did not move at all.

Chapter V, which governs general-purpose AI models, was touched once, at Article 56(6). The adequacy assessment of codes of practice moved from the AI Office to the Commission, “taking utmost account of the opinion of the Board,” with a new duty to publish that assessment. Two places were left behind.

Article 56(9) still refers to “the AI Office deems it is not adequate following its assessment under paragraph 6,” which paragraph 6 no longer says. And the Commission’s own Guidelines still describe a code as “assessed as adequate by the AI Office and the Board (Article 56(6) AI Act)” at paragraph 91, wording the omnibus overtook two months ago.

Supervision shifted in one respect that matters to anyone shipping a product on their own model. Article 75(1), as replaced, makes the AI Office “exclusively competent” for AI systems “based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking as that provider.”

Systems inside a very large online platform or search engine are covered too. Four carve-outs remain with national authorities: Annex I products, Annex III point 2, law enforcement, border and financial bodies under Article 74(6), and Annex III point 8 on the administration of justice. The competence covers providers of those systems, and deployers only where they are also the provider or part of the same undertaking.

Who checks your number, with what powers, and for how long

Article 88(1) gives the Commission “exclusive powers to supervise and enforce Chapter V,” with implementation entrusted to the AI Office. Member State authorities enforce the rest of the Act and have no jurisdiction over a GPAI model as such.

Fines come from Article 101(1), not Article 99. Exposure runs to “3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher.” Four triggers apply, each requiring the Commission to find the provider acted “intentionally or negligently”: infringing relevant provisions, failing to answer an Article 91 request, failing to comply with an Article 93 measure, or refusing access for an Article 92 evaluation.

Article 99(4) lists the obligations the Member State regime reaches, and Articles 53 and 55 are not on that list. The EUR 35 000 000 and seven per cent tier is Article 99(3) and belongs to prohibited practices under Article 5. Published pages quoting it for GPAI breaches have borrowed the wrong provision; pages quoting the right amount under Article 99 have the right number with the wrong regulator, procedure and forum.

Chapter V applied from 2 August 2025 under Article 113(b), with a carve-out in the same sentence: “with the exception of Article 101.” The fining power fell back to the general rule and vested on 2 August 2026.

Guidelines paragraph 112 states the effect plainly: “In the first year from 2 August 2025 onwards, the Commission cannot take any enforcement actions because its enforcement powers only enter into application on 2 August 2026,” and from that date “the Commission will enforce with fines compliance with all obligations by providers of general-purpose AI models who are not fully compliant on that date.”

Commission Implementing Regulation (EU) 2026/1755 of 20 July 2026 supplies the procedure the Act omitted, and repays reading before anyone needs it. In force since 10 August 2026, its Article 2(2) defines what a request for access to a general-purpose AI model can reach.

The list runs to APIs, internal access, source code, model weights, hosting infrastructure, and the ability “to inspect and modify the system state during interaction with the model.” Access is expressly “not limited to all levels of access granted to employees of the provider.” Article 2(3) lets the Commission require the provider to disable logging that would record the Commission’s own access.

Deadlines in that instrument run in both directions. Article 5(3) allows interim measures before proceedings are opened, on urgency grounds and “based on a prima facie finding,” including “preventing a general-purpose AI model from being made available on the market.” Article 7(2) gives an addressee of preliminary findings no less than twenty-one days to reply, and the Annex caps the reply at fifty pages.

Article 10 sets a five-year limitation period for imposing a fine, running from the conduct or, for continuing conduct, from the day it ceases. Four acts interrupt it and restart the clock: a request for documentation, a request for evaluation access, an invitation to a structured dialogue, and the opening of proceedings. An outer limit of twice the period caps the restarts, and Article 11 adds a separate five-year period for enforcing a fine once imposed.

GPAI providers that sign a code of practice change the texture of all this without changing the law. Articles 53(4) and 55(2) let providers rely on codes “to demonstrate compliance,” and grant the presumption of conformity only for “compliance with European harmonised standards.” Guidelines paragraph 91 says the Commission “will focus its enforcement activities on monitoring their adherence to the code of practice” for signatories.

Any opt-out from a chapter “results in losing the benefits” for that chapter. Paragraph 92 says non-signatories “will have to report the measures they have implemented to the AI Office” and are expected to run a gap analysis against the Code. Such providers “may also be subject to a larger number of requests for information and requests for access to conduct model evaluations.” Paragraph 93 makes code commitments a mitigating factor on fine quantum.

Four things the Commission has not published

Article 52(6) is an obligation on the regulator, not the regulated: “The Commission shall ensure that a list of general-purpose AI models with systemic risk is published and shall keep that list up to date.” Thirteen months after Chapter V began to apply, and seven weeks after the fining power vested, no such list appears on any Commission website. The number of notifications received under Article 52(1) has not been published either.

General-purpose AI models have no harmonised standard, and none is being written. The Commission’s standardisation FAQ, updated 10 March 2026, says the standards currently in development “focus specifically on high-risk AI systems,” and the ten areas in the standardisation request are all framed around AI systems.

The first AI standard to reach public enquiry, prEN 18286 on quality management systems, did so on 30 October 2025, and the Commission has said the Official Journal review begins only after publication. Guidelines paragraph 97 calls a code of practice “a temporary tool” pending harmonised standards. For general-purpose AI models, that successor is not on the work programme, so the presumption of conformity in Article 53(4) is a door with nothing behind it.

No formal enforcement step against a GPAI provider has been announced. Searching the Commission newsroom, the press corner, the enforcement framework page updated 24 August 2026 and the AI Act Service Desk produces no announced Article 91 request, Article 92 evaluation, Article 93 measure, Article 101 fine or opening of proceedings against any provider. Absence of an announcement is not absence of activity, since simple requests for information carry no publication duty and Article 78 confidentiality applies, but the public record is empty.

No refreshed GPAI guidance accompanies the start of enforcement. The Commission’s core questions-and-answers page on general-purpose AI models still shows a last update of 9 September 2025. Neither the Guidelines Communication that November nor the start of enforcement a year later produced a revision.

Against that, the AI Office describes itself as employing “more than 125 staff” across six units on a page updated 8 September 2026, and a European Parliamentary Research Service briefing recorded that as of March 2026 only eight of twenty-seven Member States had notified a single point of contact.

Adherence data on general-purpose AI models tells a similar story of drift. The Commission’s Code of Practice page, last updated 31 July 2026, lists twenty-one full signatories and records separately that “xAI signed up to the Safety and Security Chapter,” leaving that provider to demonstrate transparency and copyright compliance by other means. The AI Office’s own Signatory Taskforce Vademecum of January 2026 lists twenty-three participants.

Five of them are not on the current public list, and three names on the public list are not in the Vademecum. The Vademecum explains part of that gap by noting that members join between publications, and the Commission page carries its own caveat that signatures are added as they are confirmed. None of it is a register, and none of it is the list Article 52(6) requires.

Keeping the working, not only the answer

GPAI figures are produced by the provider and audited by the Commission afterwards, which inverts what a compliance file is for. The artefact that matters is the estimate behind the number, not the number itself. A defensible file records which method was used, which activities were counted, which were excluded under paragraph 119, what the utilisation assumption was, and who signed off. Paragraph 120 says so directly by requiring the assumptions, the method and the uncertainties to be documented alongside the estimate.

Retention periods turn a general-purpose AI model into a records problem rather than a project. Annex XI documentation is held “for the purpose of providing it, upon request.” Article 54(3)(b) keeps a copy alive for ten years after the model reaches the market.

Article 10 of the implementing regulation keeps the fining power alive for five years after the conduct, restarting on every request for documentation. A general-purpose AI model trained in 2026 can be the subject of a question in 2031, asked of people who were not there.

Governance software earns its place at exactly that point, and this is the problem Govern365 was built around. Mapping each obligation to the record that proves it, giving that record an owner and keeping a dated version history turns scattered estimates into a file that can be handed over.

Govern365.ai holds that obligation-to-evidence mapping across the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework, so an Annex XI entry, an ISO 42001 control and a NIST function point at one artefact rather than three copies that drift apart.

Every number in one table

FigureWhat it decidesSource
Compute directly contributing to parameter updatesDefinition of training compute for the general-purpose questionGuidelines para 115
Cumulative training computeDefinition for the systemic-risk questionGuidelines para 115
10^23 FLOP plus a generative modalityIndicative criterion for a model being general-purposeGuidelines para 17
10^25 FLOPPresumption of high impact capabilities, so systemic riskArticle 51(2)
30%Permitted error margin on a training-compute estimateGuidelines para 120
C = N · L · H · UHardware-based estimation formulaGuidelines para 124
C ≈ 6 · P · DArchitecture-based approximation for dense transformersGuidelines para 129
Two significant figuresRequired precision of the notified compute estimateGuidelines para 31
Two weeksDeadline to notify the Commission once the threshold is met or knownArticle 52(1)
One third of original training computePoint at which a downstream modifier becomes providerGuidelines para 60
3.3 x 10^24 and 3.3 x 10^22 FLOPFallback modification thresholds where original compute is unknownGuidelines para 61
10 000 registered business users in the UnionPresumption of high impact on the internal marketAnnex XIII(f)
Six monthsEarliest point to request reassessment of a designationArticle 52(5)
3% of publicly available datasets for a modalityTest for a dataset that must be itemised in the training summaryTemplate section 2.1
Top 10% of scraped domain names, or top 5% or 1 000 for SMEsDisclosure depth for crawled contentTemplate section 2.3
Ten yearsRetention of Annex XI documentation by an authorised representativeArticle 54(3)(b)
21 days minimum, 50 pages maximumReply window and length cap on preliminary findingsIR 2026/1755, Article 7(2) and Annex
Five yearsLimitation period for imposing a fine, and separately for enforcing oneIR 2026/1755, Articles 10 and 11
3% of worldwide turnover or EUR 15 000 000, whichever is higherMaximum fine, imposed by the CommissionArticle 101(1)
2 August 2025, 2 August 2026, 2 August 2027Chapter V applied, fining power vested, legacy models dueArticles 113(b) and 111(3)

Frequently asked questions

How do I calculate training compute for the EU AI Act?

Guidelines paragraph 120 permits any method accurate within an overall error margin of 30 per cent, provided the assumptions, method and uncertainties are documented. The hardware approach multiplies hardware units, duration in seconds, peak theoretical performance and average utilisation. The architecture approach counts operations, approximated for dense transformer language models as six times parameters times training tokens. All operations count equally regardless of floating-point precision.

Does training compute mean the same thing for both thresholds?

No. Guidelines paragraph 115 defines it as compute directly contributing to parameter updates when the question is whether a model is a general-purpose AI model, and as cumulative training compute when the question is whether it carries systemic risk. Cumulative is wider.

What compute do I have to include, and what can I leave out?

Recital 111 includes pre-training, synthetic data generation and fine-tuning. Paragraph 117 includes forward passes used to generate non-public synthetic data, including discarded samples. Paragraph 118 includes compute behind merged or initialised weights. Paragraph 119 excludes publicly accessible synthetic data generation, model evaluations and red-teaming, failed experiments, distillation parent models, auxiliary models such as reward functions, and recomputation of activations.

When does fine-tuning make me a provider of a general-purpose AI model?

Where the modification leads to a significant change in generality, capabilities or systemic risk. The indicative criterion at Guidelines paragraph 60 is modification compute greater than one third of the original model’s training compute, with fallbacks at paragraph 61 of one third of 10^25 FLOP for a systemic-risk original and one third of 10^23 FLOP otherwise. The obligations that follow are limited to the modification.

Did the Digital Omnibus delay GPAI obligations?

No. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved high-risk dates by up to sixteen months. Annex III systems now run from 2 December 2027 and Annex I systems from the following August. Articles 51 to 55, Article 101, Article 111(3), Article 113(b) and Annexes XI to XIII were not amended. Chapter V was touched once, at Article 56(6).

Are open-source models exempt from the AI Act?

Only partly, and only where the licence qualifies. Article 53(2) removes the Annex XI and Annex XII duties for models under a free and open-source licence with parameters, architecture information and usage information publicly available. The copyright policy and training-content summary still apply, the exception never applies to a systemic-risk model, and monetisation as defined in Guidelines paragraphs 82 to 86 removes it. Article 2(12) is a separate and wider carve-out for AI systems, not models.

Is an internal-only model caught by the GPAI rules?

Not while it stays internal. A model counts as placed on the market, on Guidelines paragraph 51, where it is used for internal processes that are essential for providing a product or service to third parties or that affect the rights of natural persons in the Union.

Does signing the GPAI Code of Practice give me a presumption of conformity?

No. Articles 53(4) and 55(2) let providers rely on codes of practice to demonstrate compliance, and grant the presumption of conformity only for compliance with European harmonised standards. No harmonised standard covering Chapter V exists, and the standardisation request covers high-risk AI systems.

What are the penalties for GPAI non-compliance?

Article 101(1) allows the Commission to fine a provider up to 3 per cent of annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher, for intentional or negligent infringement, failure to answer an Article 91 request, failure to comply with an Article 93 measure, or refusal of Article 92 evaluation access. The EUR 35 000 000 and seven per cent tier is Article 99(3) and reaches prohibited practices under Article 5.

Who enforces the GPAI rules?

The Commission, exclusively, under Article 88(1), with implementation entrusted to the AI Office. Since 27 July 2026 the AI Office is also exclusively competent under the amended Article 75(1) for AI systems built on a general-purpose AI model where model and system come from the same provider or undertaking, subject to four carve-outs that stay with national authorities.

Has the Commission published the list of GPAI models with systemic risk?

Not as at 18 September 2026. Article 52(6) requires it, and no such list appears on a Commission website. The number of notifications received under Article 52(1) has also not been published, and no formal enforcement step against a provider has been publicly announced

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

model-risk-management

Model Risk Management After SR 26-2, One Word at a Time

Supervisory guidance is a text before it is a framework, and the text changed on

Read More →
ai-policies-incident-response

AI Incident Reporting Duties, Sorted by the Date They Bind You

Almost everything written about AI incident reporting assumes Article 73 of the EU AI Act

Read More →
ai-policies-acceptable-use

Grading Every Clause in an AI Acceptable Use Policy

Open any AI acceptable use policy and the clauses look alike, set in the same

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.