EU AI Act Enforcement for GPAI Models Now Live
The European Union's AI Act has started enforcing its rules for general-purpose AI (GPAI) models, affecting automotive companies that use, integrate, fine-tune, or develop these models.

The European Union's AI Act has started enforcing its rules for general-purpose AI (GPAI) models, affecting automotive companies that use, integrate, fine-tune, or develop these models.
The EU AI Act regulates artificial intelligence at two levels: AI systems at the application level, and general-purpose AI (GPAI) models at the model level. The distinction matters, as a model is not itself an AI system; it becomes one only once further components, such as a user interface, are added.
GPAI is subject to a separate regime in Chapter V, Articles 51 - 56 AI Act. Article 53 contains the core provider obligations; Article 55 addresses models with systemic risk; Article 54 concerns the EU authorized representative; and Article 56 provides for codes of practice.
The core GPAI obligations have applied since 2 August 2025. Providers of GPAI models placed on the market before that date must comply by 2 August 2027 (Art. 111 (3)). The Commission’s and AI Office’s GPAI enforcement powers have applied since 2 August 2026.
A company can become a provider by significantly modifying a third-party GPAI model. In particular, where the additional training compute amounts to at least one third of the original training compute, the modifying company is responsible for the elements under its control.
The regime applies to providers of GPAI models: any entity that develops a GPAI model, or has one developed, and places it on the EU market under its own name or trademark, whether for payment or free of charge. “Making available” is understood broadly and can include physical or virtual distribution, APIs and downloads in the course of commercial activity.
The reach is extraterritorial. Before placing a GPAI model on the Union market, a third-country provider must appoint an EU authorized representative in writing (Art. 54). The representative must verify technical documentation, retain a copy for ten years, respond to reasoned AI Office requests and cooperate with the authorities.
For suppliers in a value chain, the key question is whether they place a model on the EU market themselves or supply it to a downstream provider that integrates it into an AI system. In the latter case, the Art. 53 (1) (b) information duties become the commercially critical touchpoint and will typically be reflected in contractual documentation, warranties and indemnities.
Since 2 August 2026, Articles 88 - 94 provide a dedicated GPAI enforcement mechanism. It includes requests for documents and information, requests for API or source-code access for model evaluations (Art. 92), and the power to require compliance with Arts. 53 and 54.
Under Art. 101 (1), the Commission may impose fines of up to 3% of total worldwide annual turnover or EUR 15 million, whichever is higher, for intentional or negligent infringements, non-compliance with information requests or Art. 93 measures, or refusal of model access.
Regulation 2026/1755 permits interim measures on prima facie evidence, notably to prevent a model being made available. Any AI Office correspondence should therefore be treated as a formal regulatory matter: activate a regulatory response protocol, not an ad hoc business-team response; involve EU counsel where past deadlines may have been missed; and communicate cooperatively.
Covered models have significant generality: they can competently perform a wide range of distinct tasks and be integrated into a variety of downstream systems. LLMs are the paradigm case. The Commission’s GPAI guidelines use an indicative training-compute threshold of 10^23 FLOP. Models with systemic risk are presumed to have high-impact capabilities above 10^25 FLOP (Art. 51 (2)), or may be designated by the Commission using Annex XIII criteria.
The decisive line is often single-purpose versus multi-purpose. A model trained for a narrow function (predictive maintenance, defect detection on the line or a specific ADAS perception function) may not be a GPAI model. A broadly capable voice or language assistant that performs a wide range of distinct tasks and can be integrated into several downstream applications may fall squarely within Chapter V.
Fine-tuning can change this distinction. Significant modification of a third-party model, particularly where additional training compute reaches at least one third of the original, can turn an OEM or supplier into a provider with its own Art. 53 obligations for the elements it controls.
The supply-chain considerations for GPAI models are complex. The regulatory picture is layered: AI embedded in vehicles is caught by the high-risk regime logic under Art. 6 (1) together with the Annex I harmonization legislation when subject to type-approval. In this case, however, the specific requirements will no longer stem from the EU AI Act but rather from the requirements of the type approval framework that will apply in the future under Regulation (EU) 2018/858 and Regulation (EU) 2019/2144 or additional specific legislation.
For applications that are not subject to the type approval framework, the general requirements of the AI Act remain applicable. Given the AI Act’s modified application for sectoral products, GPAI analysis must be conducted alongside - not instead of - product and type-approval compliance.
The source of this information is the Taylor Wessing publication "GPAI obligations under the EU AI Act: Enforcement has started".





