Skip to main content
EU AI Act GPAI Compliance: Five MythsEU AI Act & GPAI
5 min readFor AI Governance Leaders

EU AI Act GPAI Compliance: Five Myths

If you're preparing for the Commission's August 2026 enforcement deadline, you've probably heard some confident assertions about what the EU AI Act requires from General-Purpose AI Model providers. Some of these claims sound authoritative. Most are wrong.

These myths persist because Chapter V is complex. The Act distinguishes between substantive and procedural obligations, creates different tiers for systemic risk models, and splits enforcement between the Commission and national authorities. That complexity creates room for misinterpretation, and the stakes are high: fines reach 3% of annual worldwide turnover or EUR 15,000,000, whichever is higher.

Here's what you actually need to know.

Myth 1: You're Safe Until August 2026

Reality: Your obligations started on 2 August 2025. The Commission's enforcement powers activate on 2 August 2026, but you're already required to maintain Technical Documentation (Annex IV), provide information to downstream AI system providers, implement a copyright compliance policy, and publish training content summaries.

The distinction matters for your compliance roadmap. If you're treating August 2026 as your start date, you're building a documentation backlog that will be visible to regulators the moment they request it. The Act requires you to keep documentation "up-to-date," which means contemporaneous record-keeping, not retroactive assembly.

For models released before 2 August 2025, you have until 2 August 2027 to achieve full compliance. That's not an extension of your preparation window; it's recognition that retrofitting documentation for existing models takes time. Start now.

Myth 2: Open-Source Models Are Exempt

Reality: The Open-Source Model Exemption is narrow and conditional. If you release a General-Purpose AI Model under a free and open-source license, you're still required to implement a copyright compliance policy and publish a training content summary. You're only exempt from the full Technical Documentation (Annex IV) and downstream provider information requirements.

That exemption disappears entirely if your model presents systemic risk. A General-Purpose AI Model with Systemic Risk faces the complete obligation set: model evaluations, risk assessment and mitigation, serious incident reporting, and cybersecurity protections. The open-source license doesn't shield you from these requirements.

The practical implication: don't assume your licensing strategy resolves your compliance burden. Map your actual obligations based on your model's capabilities and risk profile, not its distribution model.

Myth 3: Enforcement Is the Commission's Problem, Not Yours

Reality: Multiple actors can trigger enforcement action against you. National market surveillance authorities can request that the Commission exercise its powers against your organization. Downstream AI system providers can lodge formal complaints. The scientific panel can alert the AI Office to systemic or identifiable risks your model poses.

Article 53(3) imposes a broad cooperation obligation on you. You must respond to Commission requests for documentation and information under Article 91. You must provide model access for evaluations under Article 92. Supplying "incorrect, incomplete or misleading information" is itself a fineable infringement.

This creates enforcement pathways you can't control. A downstream provider struggling with your model's performance can initiate scrutiny. A national authority conducting market surveillance on a high-risk AI system can escalate concerns about your model to the Commission. Your compliance posture needs to account for these indirect routes to enforcement, not just direct Commission oversight.

Myth 4: The Notification Requirement Only Applies at Release

Reality: If your model reaches high impact capabilities (presumed at 10^25 FLOP cumulative training compute), you must notify the Commission "without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met."

The "or it becomes known that it will be met" language creates a forward-looking obligation. If your training roadmap indicates you'll cross the threshold in your next training run, you're required to notify before you hit that milestone. This isn't a post-hoc reporting requirement; it's a predictive disclosure obligation.

For organizations running continuous training or iterative improvement cycles, this means your notification trigger isn't a single event. You need monitoring systems that track cumulative compute and flag upcoming thresholds with enough lead time to file the notification within the two-week window.

Myth 5: You're Only in Scope If You Target the EU Market

Reality: You're in scope if you place your model on the Union market, regardless of your location or intent. Recital 97 extends this further: Chapter V "should apply also when these models are integrated or form part of an AI system."

This creates supply chain exposure. If you release a General-Purpose AI Model in a third country, and a downstream provider integrates it into an AI system they place on the EU market, you may fall within scope. The Act's jurisdictional reach follows the model through the AI supply chain, not just at initial release.

The practical test isn't "Did I target EU customers?" It's "Is my model accessible to or integrated into systems operating in the Union?" That's a much broader threshold, and it means your compliance analysis needs to account for downstream integration patterns you don't directly control.

What to Do Instead

Build your compliance program around the actual obligation structure, not the myths:

Map your obligations by model type. Standard General-Purpose AI Models face one obligation set. Models with Systemic Risk face expanded requirements. Models released under open-source licenses have partial exemptions unless they present systemic risk. Your compliance roadmap depends on accurate classification.

Treat procedural obligations as seriously as substantive ones. The Commission can fine you for non-compliance with information requests, evaluation access, or requested measures under Article 93. Your response protocols for Commission interactions need the same rigor as your Technical Documentation (Annex IV).

If you're established in a third country, appoint your authorized representative now. Article 54 requires this before you place your model on the EU market, unless you're releasing under a free and open-source license. The written mandate must meet specific requirements listed in Article 54(3). This isn't administrative paperwork; it's your designated point of contact for enforcement actions.

Document contemporaneously, not retrospectively. When the Commission requests documentation under Article 91, they're not asking you to create it. They're asking you to produce what you've already maintained. The gap between "we can reconstruct this" and "here it is" becomes visible immediately.

The August 2026 enforcement date isn't your deadline. It's the date the Commission gains the power to verify what you've already been required to do since August 2025. Organizations that treat this as a verification milestone rather than a compliance start date will have a very different experience when that verification begins.

You Might Also Like