GovCompass

Art. 53 EU AI Act: baseline obligations for GPAI providers

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 53 sets the baseline obligations that every provider of a general-purpose AI model carries, regardless of whether the model has systemic risk. The provider must keep technical documentation of the model, provide information to downstream providers who integrate it, put in place a policy to comply with EU copyright law, and publish a sufficiently detailed public summary of the content used to train the model. These obligations have applied since 2 August 2025.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

The four baseline obligations

Art. 53 applies to every providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of a general-purpose AI modelgeneral-purpose AI modelEU AI Act term for a model displaying significant generality and capable of many distinct tasks, typically integrated into downstream systems; carries its own obligation set, with extra duties for models posing systemic risk.Open full entry →. It sets four obligations that exist independently of the systemic-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → classification, and that form the foundation on which the additional Art. 55 obligations build for the small group of systemic-risk models.

Technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →. The provider must draw up and keep up to date the technical documentation of the model, covering its training and testing process and the results of its evaluation, in line with Annex XI. This documentation must be made available to the AI OfficeAI OfficeThe European Commission body that coordinates implementation of the EU AI Act and supervises general-purpose AI models. National market surveillance authorities enforce the Act for most AI systems; the AI Office is the central point for the general-purpose AI layer. See general-purpose AI, EU AI Act.Open full entry → and national competent authorities on request.

Downstream information. The provider must make information and documentation available to downstream providersdownstream providerA provider that builds an AI system on top of another party's model, often a general-purpose model, and takes on obligations for the system it ships.Open full entry → who intend to integrate the general-purpose AIgeneral-purpose AIA model trained on broad data that can be adapted to many downstream tasks; the AI Act sets specific obligations for it, with extra duties when it poses systemic risk.Open full entry → model into their own AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry →, in line with Annex XII. This lets a downstream provider understand the model's capabilities and limitations well enough to meet its own obligations under the Act. It is the mechanism that carries model-level information down the value chainvalue chainThe sequence of actors from model development through provision to deployment and use, along which responsibilities and AI-Act obligations move.Open full entry →.

Copyright policy. The provider must put in place a policy to comply with Union law on copyright and related rights, in particular to identify and respect reservations of rights expressed by rightsholders.

Public training-content summary. The provider must draw up and make publicly available a sufficiently detailed summary of the content used to train the model, using the template provided by the AI Office.

The open-source position

The Act provides a limited exemption for certain free and open-source GPAI models from some of these obligations, specifically the technical-documentation and downstream-information duties, where the model's parameters and usage information are made publicly available under a free and open license. This exemption does not extend to the copyright policy or the training-content summary, and crucially it does not apply at all where the model has systemic risksystemic riskEU AI Act category for the most capable general-purpose models (presumed above a training-compute threshold), triggering extra duties: evaluations, adversarial testing, incident reporting, cybersecurity.Open full entry →. A systemic-risk model carries the full obligations regardless of how openly it is released.

Timing and the Code of Practice

The Art. 53 obligations became applicable on 2 August 2025. To help providers operationalize them during the period before harmonized standardsharmonized standardA European standard developed on request of the European Commission. Under Article 40 of the EU AI Act, compliance with harmonized standards published in the Official Journal gives a presumption of conformity with the requirements those standards cover. Harmonized standards for the AI Act are still in development. See conformity assessment, EU AI Act.Open full entry → exist, the AI Office coordinated a General-Purpose AI Code of Practice, published on 10 July 2025. The Code is a voluntary tool: a provider can use it to demonstrate compliance with Art. 53 and 55, but adherence is not itself the legal obligation, and not signing the Code does not exempt a provider from the Act. A provider that does not rely on the Code must demonstrate compliance by other adequate means.

Why it matters

For the organizations that build on foundation modelsfoundation modelA model trained on broad data at scale that can be adapted to many downstream tasks; called a general-purpose AI model in EU AI Act terminology.Open full entry → rather than train them, Art. 53 is the reason the model information they need exists at all. The downstream-information duty and the public training-content summary are what let a deploying organization understand the model underneath its system, which it needs in order to meet its own obligations, particularly where its system is high-risk.

In the seven pillars of responsible AI

Art. 53 sits primarily in the transparency and explainabilitytransparency and explainabilityThe principle that people can know an AI system is involved and can be told why it produced a given outcome. The failure is concrete rather than abstract: it arrives on the day a customer, a supervisor, or a court asks for the reasoning, and "the model decided" turns out to be the absence of an explanation rather than one. The EU AI Act separates the two directions: Article 13 requires high-risk systems to be transparent enough for the deployer to interpret and use their output, and Article 50 requires people to be informed when they interact with AI or receive AI-generated content. See model card, responsible AI.Open full entry → and accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry →: it is about documenting the model and making the right information available to the right parties down the value chain.

Continue reading

Legal referencesArt. 53
Share Share on LinkedIn