General-purpose AI model (GPAI)
A general-purpose AI model (GPAI model) is an AI model, including one trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way it is placed on the market, and that can be integrated into a variety of downstream systems or applications, excluding models used for research, development or prototyping before market placement (Art. 3(63) EU AI Act). Foundation models and large language models such as those behind ChatGPT, Claude, Gemini, Llama or Mistral are the paradigm cases; the Commission's guidelines use a training-compute threshold of 10^23 FLOPs as an indicative criterion.
Since 2 August 2025, providers of GPAI models must (Art. 53) maintain technical documentation, provide information and documentation to downstream providers integrating the model, put in place a policy to comply with Union copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed summary of the training content using the Commission's template; open-source models benefit from partial exemptions. GPAI models with systemic risk, presumed where training compute exceeds 10^25 FLOPs or designated by the Commission, face additional obligations (Art. 55): model evaluation and adversarial testing, assessment and mitigation of systemic risks, serious incident reporting and cybersecurity. The voluntary GPAI Code of Practice published in July 2025 offers a route to demonstrate compliance, and the European AI Office supervises GPAI providers directly. Models placed on the market before August 2025 have until August 2027 to comply.
For life sciences organisations, the GPAI provisions mostly bite indirectly. A pharmaceutical company fine-tuning a foundation model for medical writing, pharmacovigilance case processing or literature screening becomes a downstream provider or deployer of an AI system, and must rely on the model provider's documentation to meet its own transparency and risk obligations; if the resulting system is used for a high-risk purpose, the full regime applies to the company as provider of that system. Where a company substantially modifies a GPAI model, it may itself become a GPAI provider. Processing of personal data in prompts, fine-tuning datasets and outputs remains governed by the GDPR, as the EDPB Opinion 28/2024 on AI models explains, and transfers to US-hosted model providers require a Chapter V mechanism.
