Skip to main content
GPAI Myths That Will Cost You ComplianceEU AI Act & GPAI
5 min readFor AI Governance Leaders

GPAI Myths That Will Cost You Compliance

The European AI Act's General-Purpose AI Model provisions often create more confusion than clarity. Many governance teams misinterpret systemic risk thresholds, misunderstand grace periods, and miscalculate their exposure because they rely on assumptions that don't align with the regulation.

These myths persist because the AI Act's GPAI framework is complex. The roles of the AI Office, the Scientific Panel, and Member State authorities aren't intuitive. Distinguishing between a General-Purpose AI Model and one with systemic risk involves technical criteria that legal teams can't evaluate without engineering input. The implementation timeline includes overlapping grace periods and exemptions that don't apply uniformly.

Here's what your team needs to unlearn.

Myth 1: The 10^25 FLOP Threshold Is a Safe Harbor

The Reality: The Commission can classify your model as systemically risky even if you're below the floating-point operations threshold.

Article 51 gives the Commission authority to designate GPAI models as systemically risky based on criteria beyond compute. High-impact capabilities matter. If your model could cause serious harm at scale, the FLOP count becomes secondary.

This matters because providers are building more powerful models that require fewer FLOPs. The trend is toward efficiency, not brute-force compute. Your 10^24 FLOP model might still trigger Article 55 obligations, comprehensive risk assessment, adversarial simulation, incident reporting, and cybersecurity protections, if it's deemed systemically risky.

The Commission can also adjust the threshold through delegated acts. That 10^25 number isn't static. If you've planned your compliance roadmap assuming you'll stay under the bar, you're planning for a regulation that may not exist in 18 months.

Myth 2: You Have 24 Months to Achieve Full Compliance

The Reality: The grace period applies to existing GPAI systems, but high-risk systems already on the market get an exemption until you make significant modifications.

Article 83(3) grants the 24-month grace period for General-Purpose AI Models. But Article 83(2) exempts high-risk systems that entered the market before the Act's entry into force, they're exempt until you make significant changes to their design.

This creates a perverse incentive. If you're operating a high-risk system, you might delay improvements to avoid triggering compliance obligations. Organizations will weigh the cost of Technical Documentation (Annex IV), conformity assessment, and Post-Market Monitoring against the benefit of incremental model improvements.

The Commission still needs to define what constitutes a "significant modification" under Article 43(4). Until those rules exist, you're operating in ambiguity. Standard fine-tuning probably doesn't count. Removing safety layers definitely does. Everything in between is judgment.

Myth 3: The AI Office Will Operate Independently

The Reality: The AI Office sits within DG-CNECT, which means its strategic priorities flow from the Directorate-General's management plan.

The Commission's decision establishing the AI Office doesn't specify its organizational structure, staffing model, or operational autonomy. It will share infrastructure with DG-CNECT. This shapes what the Office prioritizes, how quickly it responds to systemic risk alerts, and which stakeholder concerns get attention.

The Office's primary mission is harmonized implementation and enforcement. But it also promotes EU competitiveness, tracks market developments, and supports initiatives that maximize AI's economic benefits. When these objectives conflict, the Office answers to DG-CNECT leadership.

This affects your compliance timeline. If the Office is stretched thin, competing with private-sector salaries for expert talent, managing Scientific Panel coordination, and supporting regulatory sandboxes across Member States, expect delays in guidance, slower responses to classification disputes, and inconsistent enforcement.

Myth 4: You Can Contest Systemic Risk Classification and Delay Obligations

The Reality: Article 52 allows you to contest the Commission's decision, but the obligations don't pause while you litigate.

If your model is trained with fewer than 10^25 FLOPs but is classified as systemically risky, you can challenge that determination. The dispute might reach the Court of Justice of the European Union. That process takes years.

But here's the problem: your Article 55 obligations start when the Commission makes the classification, not when the court rules. You'll need to implement Red Teaming, track serious incidents, and maintain cybersecurity protections while your lawyers argue the case. If you win, you've over-invested in compliance. If you lose after delaying implementation, you've been operating a systemically risky model without the required controls.

Organizations with resources will contest borderline classifications. That's rational, the compliance cost differential between standard GPAI obligations and systemic risk requirements is significant. But don't mistake "right to contest" for "safe to ignore."

Myth 5: Open-Source Models Get Blanket Exemptions

The Reality: The Open-Source Model Exemption is narrow and conditional, and it doesn't apply to models with systemic risk.

General-Purpose AI Models released under open-source licenses may receive lighter transparency obligations, but only if they don't exhibit systemic risk. Once your model crosses that threshold, whether by FLOP count or Commission designation, the exemption disappears.

You're still subject to the General-Purpose AI Code of Practice. You still need to demonstrate transparency about training data, model capabilities, and known limitations. And if you're providing the model as part of a high-risk AI system, the full Article 9 risk management requirements apply regardless of the license.

The exemption also doesn't shield downstream deployers. If someone fine-tunes your open-source foundation model and deploys it in a high-risk context, they own the compliance burden. But you may still face reputational and practical consequences if your model becomes the basis for non-compliant systems at scale.

What to Do Instead

Stop treating the AI Act as a checklist and start treating it as a dynamic regulatory framework. The Commission will adjust thresholds, issue guidance, and refine definitions based on how the technology evolves. Your compliance posture needs to flex with it.

Build change management plans now. Document anticipated modifications, performance adjustments, safety layer updates, shifts in intended use, and define how you'll assess whether those changes trigger new obligations. This approach comes from pharmaceutical regulation, where predetermined change protocols reduce friction between innovation and compliance.

Map your GPAI models to both current and plausible future classifications. If your model is near the FLOP threshold, or if it demonstrates high-impact capabilities, assume you'll need to meet systemic risk obligations eventually. Implement the controls early. Retrofitting Red Teaming and adversarial simulation after a Commission designation is expensive and slow.

Engage with the AI Office and Scientific Panel processes as they develop. The Code of Practice, the evaluation methodologies, and the incident reporting frameworks are all being defined now. Your input during the drafting phase is worth more than your objections after publication.

Finally, don't rely on grace periods to delay hard decisions. The 24-month window is for preparation, not procrastination. Use it to build Technical Documentation, establish Post-Market Monitoring, and validate that your risk assessments actually work. When the exemptions expire, you want to be ready, not scrambling.

You Might Also Like