GovCompass

GPAI integration as a deployer: ChatGPT, Copilot, and EU AI Act

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Deployers using GPAI models like ChatGPT or Copilot are generally not subject to the provider obligations of Art. 52-55, but two frameworks do apply: the Art. 50 transparency obligations and a high-risk use-case analysis. If the way you deploy the GPAI creates a high-risk AI system under Annex III, the full Art. 26 deployer obligations apply.

Updated: June 2026

Introduction: GPAI is everywhere

General purpose AI (GPAI) models, ChatGPT, Microsoft Copilot, Google Gemini, Claude, and others, have become embedded in the daily workflows of most Dutch organizations. Staff use them for drafting, analysis, code generation, customer service, and dozens of other applications. Many organizations have Microsoft 365 Copilot integrated enterprise-wide, or use OpenAI's API for custom applications.

Understanding what the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → requires of deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → using GPAI is essential, and reassuringly, the obligations are generally lighter than for high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry →. But they are not zero.

The regulatory position of GPAI models

GPAI models are regulated primarily through Art. 52–55 of the EU AI Act, which creates obligations for model providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → (OpenAI, Microsoft, Google, Anthropic). As a deployer of GPAI tools, you benefit from your provider's compliance with these obligations but are not directly subject to Art. 52–55 obligations yourself.

However, two frameworks do apply to GPAI deployers:

1. Art. 50 transparency obligations

Art. 50 applies to deployers who use GPAI systems in consumer-facing applications. Key requirements (in force from 2 August 2026):

  • Chatbot disclosure: AI-powered chatbots must identify themselves as AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → to users (unless obviously artificial)
  • AI-generated content labeling: Content substantially generated by AI must be labeled as AI-generated when it could be mistaken for human-created content
  • DeepfakedeepfakeAI-generated or manipulated audio, image or video that convincingly depicts real people or events that did not occur; subject to labeling duties under the EU AI Act's transparency tier.Open full entry → labeling: AI-generated images, audio, and video that depicts real or realistic-looking content must carry a clear disclosure

2. high-risk use case analysis

This is the critical deployer obligation for GPAI: even if the underlying GPAI model is not itself classified as high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →, the way you deploy it may create a high-risk AI system. Specific deployment contexts that likely trigger high-risk classification:

  • Using ChatGPT as the sole or primary basis for hiring decisions
  • Using Copilot to generate credit risk assessments without human review
  • Using GPAI for medical diagnosis assistance without qualified oversight
  • Using GPAI to screen benefit applicants in the public sector

For each GPAI integration in your organization: assess the specific use case against the Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → categories. If the use case falls within a high-risk category, the full Art. 26 deployer obligations apply, even though the model itself is a GPAI.

Practical checklist for GPAI deployers

  1. Map every GPAI tool in use across your organization (including departmental use of consumer tools)
  2. For each deployment context, assess whether the specific use case creates a high-risk AI system
  3. For consumer-facing GPAI applications: prepare Art. 50 disclosure mechanisms ahead of August 2026
  4. Verify your GPAI provider's Art. 52–55 compliance (request their EU AI Act compliance documentation)
  5. Implement acceptable use policies for employee use of GPAI tools that prevent unauthorised high-risk deployments

FAQ

Q: We use Microsoft 365 Copilot enterprise-wide. Are we compliant by default because Microsoft is responsible?
A: Microsoft bears provider-level obligations under Art. 52–55 for the Copilot model. However, you as deployer are responsible for how Copilot is used in your organization. If staff use Copilot for high-risk decisions without oversight, that is your compliance responsibility, not Microsoft's.

Q: Our marketing team uses ChatGPT to draft blog posts. Do we need to label these?
A: Under Art. 50 (applicable from August 2026), if the content is substantially AI-generated and could be mistaken for human-authored content, labeling is required. Content substantially edited and augmented by a human author is less clearly required to be labeled. Develop a clear policy for your team before August 2026.

Provider obligations behind the model

The provider side of these obligations is set out article by article: Art. 53: baseline obligations for GPAI providers and Art. 55: obligations for systemic-risk GPAI providers.

Legal referencesArt. 50Art. 52Art. 26
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.

More on Transparency & explainability