The EU AI Act introduces specific compliance thresholds: 10²³ FLOPs for General-Purpose AI (GPAI) model classification and 10²⁵ FLOPs for systemic risk designation. If you're building or operating large models in the EU market, these numbers define your regulatory obligations.
This guide explains what you need to track, when to notify authorities, and where potential edge cases exist.
Scope of This Guide
This guide covers:
- General-Purpose AI Model classification criteria under the EU AI Act
- Compute-based thresholds and their measurement
- Notification requirements for systemic risk models
- Provider determination in multi-party development scenarios
- Open-source exemptions and their limits
- Downstream modification thresholds
It does NOT cover high-risk AI system requirements, prohibited AI practices, or transparency obligations for non-GPAI systems.
Key Concepts and Definitions
General-Purpose AI Model: A model trained using more than 10²³ FLOPs, capable of generating language, text-to-image, or text-to-video outputs across various tasks.
Training Compute: Total compute used for parameter updates during training. For systemic risk assessment, all cumulative training compute counts, including forward passes for synthetic data generation.
General-Purpose AI Model with Systemic Risk: A model trained using ≥10²⁵ FLOPs, presumed to have high-impact capabilities. Additional obligations apply.
Provider: The entity that develops a General-Purpose AI Model and places it on the EU market, or has it developed under their name/trademark and places it on the market.
Compute Estimation Baseline: A model with roughly 1 billion parameters trained on substantial datasets typically meets the 10²³ FLOPs threshold. This serves as a reference point.
Requirements Breakdown
For All GPAI Models (≥10²³ FLOPs)
Obligations begin at the start of the pre-training run:
Documentation: Maintain and update lifecycle documentation. Provide to downstream providers and, upon request, to the AI Office or national authorities.
Training Data Summary: Publish using the AI Office template (pending release).
Copyright Policy: Document your copyright compliance approach. This may apply across all your models.
For Systemic Risk Models (≥10²⁵ FLOPs)
Additional requirements:
Risk Assessment and Mitigation: Conduct comprehensive evaluations throughout the lifecycle, including model assessments.
Cybersecurity Measures: Implement robust controls appropriate to the systemic risk level.
Serious Incident Tracking and Reporting: Establish a formal incident management and notification process.
Notification to Commission: Notify within two weeks of foreseeing or reaching the 10²⁵ FLOPs threshold. Include:
- Compute estimates
- Estimation methodologies
Open-Source Model Exemptions
If your model is open source (released under a free and open-source license permitting use, access, modification, and redistribution without discriminatory restrictions), you're exempt from providing documentation to downstream providers or authorities upon request. You still must comply with training data summary and copyright policy.
Critical: If designated as systemic risk, all systemic risk obligations apply in full, regardless of open-source status.
Implementation Guidance
Compute Tracking
Start tracking training compute now if you haven't already. You need:
- Parameter count
- Training dataset size
- Total FLOPs calculation methodology
Exclusions you can document:
- Publicly available synthetic data generation
- Diagnostic/evaluation tasks
- Failed experiments or research-only runs
- Auxiliary model training (e.g., reward models)
Inclusions you must count:
- All compute contributing to model capabilities
- Forward passes for synthetic data generation
- Compute for weight merging or initialization using pre-trained models
Provider Determination in Complex Scenarios
Consortium development: The provider is typically the coordinator or the consortium itself, depending on contractual arrangements.
Repository hosting: Uploading to a repository doesn't transfer provider status. The entity that developed the model remains the provider.
Non-EU origin models: If you make a model available outside the EU but it's later incorporated into a system placed on the EU market, you're the provider unless you've explicitly excluded EU use. In that case, the downstream integrator becomes the provider.
Downstream Modification Threshold
You become a new GPAI provider if your modification compute exceeds one-third of the original training compute:
- ≥1/3 of 10²³ FLOPs for standard GPAI models
- ≥1/3 of 10²⁵ FLOPs for systemic risk models
If you cross this threshold, your obligations cover only the modification: documentation, training data summary, and copyright policy relate to the additional compute.
Exception: If you're modifying a systemic-risk model and cross the threshold, full systemic risk obligations apply to you.
Rebuttal Process for Systemic Risk Designation
If your model is automatically designated based on compute but you believe it doesn't present systemic risk, you can contest with evidence:
- Benchmark results
- Scaling law analysis
- Capability assessments
Obligations remain in effect during review. You can request an initial reassessment six months post-designation, and a second reassessment six months after that if the first is unsuccessful.
Common Pitfalls
Functional generality misinterpretation: Exceeding 10²³ FLOPs doesn't automatically make your model a General-Purpose AI Model. Specialized models (transcription, image upscaling, weather forecasting, gaming) are excluded if they lack general capabilities across a broad range of tasks. Document your specialization clearly.
Monetization killing open-source status: Your open-source exemptions disappear if you introduce dual licensing, pay-to-access support for essential functionality, or process user data commercially. Optional premium services are fine; functional dependency on paid features is not.
Notification timing: "Reasonably foreseeing" the 10²⁵ FLOPs threshold means you can't wait until training completes. Set internal alerts at 80-90% of the threshold to ensure you notify within the two-week window.
Upstream responsibility gaps: If you're an upstream provider and don't explicitly exclude EU use, you're responsible even if a downstream party integrates your model into an EU-market system. Document use restrictions clearly in licensing terms.
Modification compute underestimation: Fine-tuning and continued pre-training both count toward the one-third threshold. Track cumulative modification compute across all downstream training runs.
Quick Reference Table
| Threshold | Classification | Notification | Key Obligations |
|---|---|---|---|
| <10²³ FLOPs | Not a General-Purpose AI Model | None | None under GPAI regime |
| ≥10²³ FLOPs | General-Purpose AI Model | None | Documentation, training data summary, copyright policy |
| ≥10²⁵ FLOPs | Systemic risk GPAI | Within 2 weeks | All GPAI obligations + risk assessment, cybersecurity, incident reporting |
| ≥1/3 original compute (modification) | New GPAI provider | If systemic risk | Modification-specific obligations; full systemic risk obligations if modifying General-Purpose AI Model with Systemic Risk |
Timeline checkpoints:
- 2 August 2025: Obligations begin for new models
- 2 August 2026: AI Office gains full enforcement powers
- 2 August 2027: Compliance deadline for models placed before 2 August 2025
The AI Office has signaled a collaborative enforcement approach during the initial phase, but don't mistake that for optional compliance. Start your compute tracking and documentation now.



