← Back to all insights

Regulation Published · 14 August 2026

GPAI obligations: why you are probably not a provider (and what if you are)

Fines of up to €15 million or 3% of global turnover frighten a lot of people the rule doesn't reach. Telling provider from deployer apart saves you an expensive audit.

6 min read

Every time the EU AI Act’s penalties make the news we get the same call: “are we going to be fined €15 million?”. The answer is almost always no, and it is worth understanding why.

Provider does not mean “the one using it”

The Regulation assigns obligations by the role you play, not by whether you touch AI:

RoleWho it isRegulatory load
GPAI model providerDevelops and places a general-purpose model on the marketHigh: technical documentation, copyright policy, training-data summary
AI system providerDevelops a system and markets it under their own nameMedium, depending on the system’s risk
DeployerUses an AI system under their own authorityLow in most cases
Importer / distributorBrings in or markets third-party systemsConformity verification

If your company calls a frontier model’s API to classify tickets, you are a deployer. You are not a GPAI provider. The model’s technical documentation, training-data summary and copyright policy are the problem of whoever trained it.

Where it does change: if you take an open-weight model, fine-tune it substantially and place it on the market under your own brand, you may become a provider. That is the scenario to review with a lawyer beforehand, not afterwards.

The dates that apply

  • 2 August 2025 — GPAI model obligations, governance and the penalty regime took effect.
  • 2 August 2026 — penalties specific to GPAI providers apply, up to €15 million or 3% of global turnover, whichever is higher.
  • 2 August 2027 — deadline for GPAI models already on the market before August 2025 to come into line.

That last deadline explains why some older models still lack complete documentation: they have two years of runway.

What does apply to you as a deployer

The load is low, but it is not zero:

  • Use the system according to the provider’s instructions. Use it for something the provider expressly excludes and you take on the liability.
  • AI literacy for the staff operating it. An obligation since February 2025.
  • Article 50 transparency where there is interaction with people or synthetic content.
  • Human oversight where the system falls into a high-risk category.
  • Retain logs the system generates automatically, where they are under your control.

The expensive mistake we see

Companies commissioning a high-risk conformity audit for a system that is not high risk. Classifying inbound email, drafting sales copy or summarising internal documentation do not fall under Annex III.

Before spending on compliance, spend half a day on classification. The right question is not “do we use AI?”, it is “what decision does this system make, and about whom?” If the answer affects a person’s access to employment, credit, education or essential services, then there is a conversation. If not, the load is what you have just read.

Sources

Next step

How ready is your business for AI?

Evaluate your AI maturity in 5 minutes and get free personalised recommendations.

Ready to move beyond the hype?