A general-purpose AI model under the EU AI Act is a model capable of performing a wide range of distinct tasks. The obligations attach to the provider of the model, not to whoever eventually uses it.
Article 53 sets the baseline for every GPAI provider placing a model on the EU market:
- Technical documentation under Annex XI
- Information packs for downstream providers under Annex XII
- A copyright policy addressing the text and data mining opt-out
- A publicly available, sufficiently detailed summary of training data content
That last item is more demanding than it sounds. The Commission has published a template, and the summary must be updated at least every six months when a model is further trained on additional data.
Open-weight models get partial relief under Article 53(2). Technical documentation and downstream information requirements fall away for models with publicly available weights, architecture and usage terms. Copyright compliance and the training data summary still apply — and the exemption disappears entirely if the model crosses the systemic risk threshold.
These obligations have applied since 2 August 2025. They are not new, and nothing in the 2026 amendments touched them.
Key Takeaways
- “EU delays AI Act” headlines are producing a dangerous misreading. Only the high-risk tier moved. EU AI Act GPAI obligations never shifted, and Commission enforcement powers switched on 2 August 2026.
- The Digital Omnibus on AI — Regulation (EU) 2026/1744 — entered into force on 27 July 2026, deferring standalone high-risk obligations to 2 December 2027 and leaving Articles 51 to 55 untouched.
- The two regimes attach at different layers. The EU regulates the model by training compute. US states regulate the use by decision context. A company can be fully compliant in one and entirely out of scope in the other.
- The EU has one regulator with a €15 million or 3% of global turnover penalty. The US has fifty attorneys general, no federal statute, and an active preemption fight.
- The convergence points are real. Training-data disclosure and frontier safety frameworks appear in both regimes, so one artefact can satisfy two obligations.
Quick Navigation
- The EU AI Act GPAI Systemic Risk Threshold
- Which EU AI Act GPAI Deadlines Moved
- EU AI Act GPAI Versus the US State Patchwork
- Gap 1: EU AI Act GPAI Regulates Models, US Law Regulates Use
- Gap 2: One Regulator Versus Fifty
- Gap 3: Compute Thresholds Versus Decision Context
- Gap 4: EU AI Act GPAI Enforcement Versus US Litigation
- Where EU AI Act GPAI Rules Meet US Law
- Building One Program for Both Regimes
- Primary sources
- Frequently Asked Questions
The EU AI Act GPAI Systemic Risk Threshold
Article 51(2) creates a second tier with a bright-line trigger: cumulative training compute exceeding 10^25 floating-point operations.
Three details about that threshold matter operationally.
It measures the training run only, not inference. This is a one-time characteristic of how the model was built.
The presumption is rebuttable. A provider above the threshold can argue its model does not present systemic risk, and the Commission can designate a model below the threshold as systemic-risk based on equivalent impact or capabilities.
Notification is fast. A provider whose model meets or is expected to meet the threshold must inform the AI Office immediately, and within two weeks at the latest.
Crossing the threshold triggers Article 55: model evaluations including adversarial testing, systemic risk assessment and mitigation, serious incident reporting directly to the AI Office rather than national authorities, adequate cybersecurity protection, and energy consumption reporting.
The GPAI Code of Practice, coordinated by the AI Office and recognized by the Commission and AI Board as an adequate compliance route, specifies the methodology. Its adversarial testing scope covers at minimum cyber attack assistance, biological and chemical weapon development assistance, large-scale disinformation generation, and critical infrastructure vulnerability exploitation.
That testing requirement deserves scrutiny on its own terms, because a single passing evaluation demonstrates very little — an argument set out in why one passing red team test proves nothing. OpenAI, Anthropic, Google and Mistral are among the Code’s signatories.
Which EU AI Act GPAI Deadlines Moved
This section exists to correct a widespread misreading, and it is the single most useful thing in this article.
The European Parliament approved the Digital Omnibus on AI on 16 June 2026 by 423 votes to 57 with 174 abstentions. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026.
Headlines read “EU delays AI Act.” Teams concluded they have until December 2027.
Here is what actually happened.
| Obligation | Original date | Current date | Status |
|---|---|---|---|
| Article 5 prohibitions | 2 Feb 2025 | 2 Feb 2025 | In force |
| Article 4 AI literacy | 2 Feb 2025 | 2 Feb 2025 | In force |
| GPAI obligations (Arts 51–55) | 2 Aug 2025 | 2 Aug 2025 | Unchanged, in force |
| Article 50 transparency | 2 Aug 2026 | 2 Aug 2026 | Unchanged, in force |
| AI Office GPAI enforcement powers | 2 Aug 2026 | 2 Aug 2026 | Active |
| Art 50(2) marking, pre-existing models | 2 Aug 2026 | 2 Dec 2026 | Short grace period |
| National regulatory sandboxes | 2 Aug 2026 | 2 Aug 2027 | Deferred 12 months |
| High-risk Annex III standalone | 2 Aug 2026 | 2 Dec 2027 | Deferred ~16 months |
| High-risk Annex I embedded | 2 Aug 2027 | 2 Aug 2028 | Deferred 12 months |
The delay applies only to the high-risk tier. Chatbot disclosure, deepfake labeling and machine-readable marking of AI-generated content all landed on schedule eleven days ago. So did the Commission’s enforcement powers over GPAI providers.
Penalties for GPAI and Article 50 breaches run up to €15 million or 3% of global annual turnover, whichever is higher.
If you provide a model, nothing was postponed for you.
EU AI Act GPAI Versus the US State Patchwork
The comparison most people expect is “strict Europe versus permissive America.” That framing is wrong and it leads teams to the wrong compliance work.
| Dimension | EU AI Act GPAI | US state laws |
|---|---|---|
| What triggers coverage | Model characteristics (training compute) | Use context (consequential decisions) |
| Regulated party | Model provider | Developer and deployer separately |
| Territorial hook | Placing a model on the EU market | Affecting that state’s residents |
| Tiering basis | 10^25 FLOP threshold | Decision domain and sector |
| Enforcement body | AI Office, centralised | State attorneys general, fragmented |
| Maximum penalty | €15M or 3% global turnover | Varies widely by state |
| Current status | In force, enforcement active | Patchwork, several deferred to 2027 |
The US position as of August 2026: no comprehensive federal statute exists. Texas TRAIGA and several California laws are in force. Colorado’s original AI Act was repealed and reenacted as SB 26-189, effective 1 January 2027 and subject to litigation. More than 2,000 AI-related bills have been introduced across the states.
The detail of who owes what on the US side is covered in state AI laws and what builders and deployers each owe.
Gap 1: EU AI Act GPAI Regulates Models, US Law Regulates Use
This is the structural difference everything else follows from.
The EU asks: what is this model, and how much compute trained it? Obligations attach at the point the model is placed on the market, before anyone has used it for anything.
US states ask: what decision is this system influencing, and about whom? Obligations attach at the point of use, and the same model may be regulated in one deployment and unregulated in another.
Two practical consequences fall out, and both surprise people.
A frontier model provider can be heavily regulated in the EU and largely out of scope in most US states, because it never touches a consequential decision directly. Its customers do.
A small company using an off-the-shelf model for hiring is a US deployer with real obligations and, in the EU, is not a GPAI provider at all. It may be a high-risk deployer — but that tier now sits at December 2027.
The layers are complementary rather than competing. Anyone assuming EU compliance covers US exposure has misread which layer each regime occupies.
Gap 2: One Regulator Versus Fifty
The EU concentrates authority. The AI Office oversees GPAI providers directly, receives Article 55 incident reports, and has held enforcement powers since 2 August 2026. One body, one interpretation, one escalation path.
The US distributes it. Enforcement sits with state attorneys general applying different statutes with different definitions and different deadlines.
Three operational consequences.
Interpretation is centralized in the EU and contested in the US. The Commission publishes guidelines, templates and a Code of Practice. In the US, one state’s reading of “materially influences” may not match another’s.
Reporting channels differ. Article 55(1)(c) incidents go to the AI Office, not national authorities. There is no US equivalent — no central body receives AI incident reports.
Safe harbours are jurisdiction-specific. Adhering to the GPAI Code of Practice is a recognized compliance route in the EU. Substantially complying with the NIST AI RMF earns an enforcement safe harbour under Texas TRAIGA. Colorado’s successor statute dropped its framework-based defence entirely. Three regimes, three different answers to “does following a standard protect me?”
Gap 3: Compute Thresholds Versus Decision Context
The EU’s 10^25 FLOP line is objective, measurable and checkable by a third party. That is its strength and its weakness.
The strength: you know exactly which side you are on. Compute is a number.
The weakness: compute is a poor proxy for harm. A model trained below the threshold, deployed into a lending decision at scale, can cause more real-world damage than a frontier model used for code completion. The Commission’s designation power exists precisely to patch this, but designation is discretionary and slow.
US decision-context tiering has the mirror-image profile. It targets harm directly — employment, lending, housing, healthcare, insurance — which is where discrimination actually happens. But the boundaries are contested. Does an AI tool that ranks candidates “materially influence” a hiring decision if a human makes the final call? Different states answer differently, and no court has settled it.
Both regimes also share a blind spot worth naming: neither is built for autonomous agents. The EU asks about model characteristics; US states ask about decisions affecting consumers. An agent that chains tool calls, modifies records and takes irreversible actions fits neither frame cleanly, and both may leave it unaddressed — the practical fallback being human approval on high-consequence actions.
Gap 4: EU AI Act GPAI Enforcement Versus US Litigation
The final gap concerns what “the law” even means right now in each jurisdiction.
In the EU, it means a regulation in force with an active supervisory authority. The Digital Omnibus was itself adopted through the ordinary legislative process, so even the amendments are settled law rather than pending change.
In the US, it means a live contest.
Executive Order 14365, signed 11 December 2025, directed the Attorney General to establish an AI Litigation Task Force to challenge state AI laws on interstate commerce and preemption theories, and directed a Commerce review that could condition federal broadband funding on a state’s AI posture. Colorado’s law was named specifically.
Colorado’s own statute is enjoined pending litigation, and its attorney general has indicated no enforcement until rulemaking completes — rulemaking that had not formally begun as of mid-2026.
No federal preemption has been enacted. But the practical difference is stark. EU obligations are stable enough to build a two-year compliance programme around. US obligations require quarterly re-verification because the map keeps redrawing itself.
Where EU AI Act GPAI Rules Meet US Law
The gaps are real, and so is the overlap. Three convergence points let one artefact serve two regimes.

Training data disclosure. EU Article 53(1)(d) requires a public summary of training data content. California’s AB 2013 requires public documentation of training data for generative AI. The formats differ; the underlying work is largely the same, and doing it once to the EU template will substantially cover the California requirement.
Frontier safety frameworks. EU Article 55 requires systemic risk assessment, adversarial testing and incident reporting for models above the compute threshold. California’s SB 53 requires frontier developers to publish safety frameworks and report critical incidents. Both target the same population with similar demands.
Content provenance. EU Article 50(2) requires machine-readable marking of AI-generated content. California’s AI Transparency Act, operative since 2 August 2026, requires detection tooling and latent disclosures from large providers.
The sensible sequencing: build to the stricter requirement, map it to the looser one, and maintain a single evidence base. Three years of records satisfies most US state retention rules; the EU Code of Practice’s Model Documentation Form asks for ten.
Building One Program for Both Regimes
Six steps, ordered by dependency.
Determine your role in each regime separately. GPAI provider is an EU concept keyed to the model. Developer and deployer are US concepts keyed to use. You may hold different roles in each, and one company can be all three.
Measure your training compute. If you train models, know your cumulative FLOP figure. It determines whether Article 55 applies and triggers a two-week notification clock.
Build the training data summary first. It is required by the EU regardless of tier, required by California for generative AI, and has a published template. Highest-leverage single artefact.
Do not defer on the strength of the high-risk delay. Article 50 transparency and GPAI enforcement are live. Only Annex III moved.
Pick a governance framework and document adherence. NIST AI RMF for the US safe harbour where it exists, GPAI Code of Practice for the EU. They overlap substantially in substance.
Re-verify quarterly on the US side and annually on the EU side. The asymmetry is deliberate: EU rules are settled, US rules are not.
Primary sources
- EU AI Act, Regulation (EU) 2024/1689
- European Commission — AI Office and GPAI
- GPAI Code of Practice
- Texas HB 149 (TRAIGA)
- NIST AI Risk Management Framework
Statutory status changes frequently and several US provisions are subject to pending litigation. This article is general information, not legal advice.
Frequently Asked Questions
Were EU AI Act GPAI obligations delayed?
No. Articles 51 to 55 have applied since 2 August 2025 and the Digital Omnibus did not touch them. Commission enforcement powers over GPAI providers became active on 2 August 2026. Only the high-risk tier was deferred.
What is the 10^25 FLOP threshold?
Article 51(2) presumes a GPAI model presents systemic risk if cumulative training compute exceeds 10^25 floating-point operations. The presumption is rebuttable, and the Commission may also designate models below the threshold.
Do open-weight models escape EU AI Act GPAI obligations?
Only partially. Article 53(2) removes technical documentation and downstream information requirements, but copyright compliance and the training data summary still apply. The exemption disappears entirely above the systemic risk threshold.
Is the US going to preempt state AI laws?
No preemption has been enacted. Executive Order 14365 created a litigation task force and challenges are pending, but state obligations remain enforceable until a court or statute says otherwise.
If I comply with the EU AI Act, am I covered in the US?
No. The regimes attach at different layers — the EU at the model, US states at the use. EU compliance addresses provider duties and leaves deployer duties, notice requirements and adverse-decision explanations unaddressed.
Keep reading
Here are the latest posts from the blog.

AI Compliance Evidence: 4 Proven Records Regulators Want

GPAI Obligations: 4 Critical Gaps in the US Patchwork

Agent Skills Security: 4 Hidden Gaps in Every Registry
