Skip to main content
Category: EU AI Act & GPAI

General-Purpose AI Model

Also known as: GPAI Model, General-purpose AI, GPAI, General-purpose AI model
Simply put

A general-purpose AI model is an AI model trained on a large amount of broad data so that it can perform a wide range of different tasks, such as writing, coding, summarizing, or generating text, images, or video, rather than being built for a single narrow purpose. Because it can be adapted to many uses, it can be integrated into or serve as the basis for a variety of downstream applications and systems. The term is most precisely defined in the context of the EU AI Act and may carry a narrower or broader meaning in other settings.

Formal definition

Under the EU AI Act, a general-purpose AI model is defined as an AI model, including where trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of how the model is placed on the market, and that can be integrated into a variety of downstream systems or applications. This model-level concept should be distinguished from a general-purpose AI system, which the AI Act frames as an AI system based on a general-purpose AI model that has the capability to serve a variety of purposes. Within the AI Act, a subset of such models may be classified as general-purpose AI models with systemic risk where they are assessed to have high-impact capabilities, as determined by technical tools and other criteria described in the Act; the specific classification thresholds and evidentiary criteria are set out in the legislation and are not reproduced here. Note that the AI Act is EU legislation and its definition should not be assumed to be authoritative or interchangeable across other jurisdictions, voluntary standards, or general enterprise usage, where 'general-purpose AI' is often used more loosely to describe broadly capable models.

Why it matters

The concept of a general-purpose AI model matters because it marks a shift in how regulators and governance professionals think about AI: rather than assessing a model solely by the single task it was built for, the general-purpose framing recognizes that one model can be adapted to many downstream uses that its original developers may not have anticipated. Under the EU AI Act, this model-level concept carries specific regulatory weight, and it is distinguished from a general-purpose AI system, which the Act frames as an AI system based on a general-purpose AI model that has the capability to serve a variety of purposes. That distinction matters for allocating obligations along the value chain: the entity that places a model on the market and the entity that integrates it into a downstream system may face different responsibilities.

The general-purpose framing also introduces a tiered approach to risk within the AI Act. A subset of these models may be classified as general-purpose AI models with systemic risk where they are assessed to have high-impact capabilities, as determined by technical tools and other criteria set out in the legislation. This classification is significant for compliance planning because it can trigger heightened expectations for the models it applies to. However, the specific thresholds and evidentiary criteria are established in the AI Act itself and are not reproduced here; governance teams should consult the legislation and any implementing guidance rather than assume a fixed numeric trigger.

Professionals should be cautious not to treat the EU AI Act definition as universal. The AI Act is EU legislation, and its definition of a general-purpose AI model should not be assumed to be authoritative or interchangeable across other jurisdictions, voluntary standards, or general enterprise usage. In many everyday and vendor contexts, 'general-purpose AI' is used more loosely to describe any broadly capable model, which can create ambiguity when regulatory obligations hinge on the precise legal definition.

Who it's relevant to

AI governance and policy specialists
Those responsible for organizational AI oversight need the precise EU AI Act distinction between a general-purpose AI model and a general-purpose AI system, because obligations and accountability can differ depending on whether an organization develops the model, places it on the market, or integrates it into downstream applications. They should also track how the systemic-risk subset is defined, while recognizing that the specific classification criteria live in the legislation itself.
Legal and regulatory professionals
Legal advisers assessing exposure under the EU AI Act must apply the Act's specific definitions rather than the looser everyday usage of 'general-purpose AI.' They should be attentive to the fact that this is EU legislation whose definitions are not automatically authoritative in other jurisdictions or in voluntary standards, and that the thresholds for systemic-risk classification are set out in the Act and any implementing guidance.
Model risk managers and validators
Teams managing model risk should note that a general-purpose model's ability to be adapted to many downstream tasks expands the range of uses that may need to be considered when scoping validation and monitoring. Because a single model can serve applications its developers did not anticipate, risk assessment cannot rely solely on the original intended use. Note that model risk management is a distinct discipline from the AI governance framing in which the GPAI concept originates, and the two should be coordinated rather than conflated.
Compliance officers and auditors
Compliance and audit functions need clarity on which regulatory definition applies before mapping obligations, since the EU AI Act's model-level concept differs from how vendors and internal teams may casually describe 'general-purpose' capabilities. Where a model may fall into the systemic-risk subset, compliance teams should confirm the applicable criteria against the legislation rather than assuming a fixed trigger.
Data scientists and model developers
Developers building or fine-tuning broadly capable models trained on large datasets using self-supervision should understand that such models may meet the EU AI Act's definition of a general-purpose AI model, which can carry regulatory consequences depending on how the model is placed on the market and integrated downstream. Understanding the model-versus-system distinction helps developers anticipate where responsibilities may attach.

Inside GPAI Model

Broad Capability Across Tasks
A general-purpose AI model is characterized by its ability to perform a wide range of distinct tasks rather than being purpose-built for a single narrow function. This general applicability is typically what distinguishes it from a task-specific model.
Adaptability and Downstream Integration
Such models are often intended to be integrated into a variety of downstream systems and applications, sometimes by parties other than the original developer. This layered deployment chain is a defining feature that complicates governance and risk allocation.
Training on Large and Diverse Data
General-purpose models are commonly trained on large volumes of varied data, which contributes to their broad capabilities. The scale and diversity of training data are often cited as factors in how these models are categorized in regulatory discussions.
Regulatory Categorization Under the EU AI Act
The term 'general-purpose AI model' is used within the EU AI Act, an instrument issued by the European Union, as a distinct category with associated obligations. As commonly discussed, some general-purpose models may be treated as carrying heightened obligations where they are assessed to present systemic considerations, though the specific thresholds and criteria should be verified against the current text.

Common questions

Answers to the questions practitioners most commonly ask about GPAI Model.

Is a 'general-purpose AI model' the same thing as a high-risk AI system?
No. These are distinct categorizations that professionals frequently conflate. A general-purpose AI model refers to a model characterized by broad capability and adaptability across many downstream tasks, whereas 'high-risk' is a risk-classification concept applied to certain uses or applications. A general-purpose model is not automatically high-risk, and a high-risk system need not be built on a general-purpose model. Whether specific obligations attach depends on the applicable framework and how the model is deployed, so the two labels should be assessed separately rather than treated as interchangeable.
Does labeling a model 'general-purpose' mean it is unregulated or falls outside model risk management?
No. The general-purpose designation describes the breadth of a model's capabilities, not its regulatory status. Depending on jurisdiction and use, such models may fall within specific regulatory frameworks, and where a general-purpose model is used within an organization's decision-making, it can still be subject to the same model risk management disciplines—identification, measurement, monitoring, and control—that apply to other models. The broad and adaptable nature of these models can, if anything, complicate scoping rather than exempt them from oversight.
How should an organization scope a general-purpose model for model risk management when it supports many downstream uses?
Because a general-purpose model may support multiple, evolving applications, scoping typically involves inventorying the specific use cases in which the model informs decisions, rather than treating the model as a single monolithic item. In many model risk management approaches, risk is assessed at the level of the model-plus-use, so the same underlying model may warrant different controls across different applications. Organizations should document which uses are in scope, note that new downstream uses may require reassessment, and recognize that this scoping question can be contested where framework guidance is still evolving.
What validation challenges arise when the model was developed by a third party?
When a general-purpose model is supplied by an external provider, the organization often has limited visibility into training data, design choices, and internal testing. This can constrain independent validation, which typically seeks to assess whether a model is conceptually sound and performs as intended for its use. Common responses include relying more heavily on outcome- and use-focused testing within the deployment context, obtaining available documentation from the provider, and clearly recording residual uncertainty. This does not eliminate model risk; it manages it, and the adequacy of such measures may depend on the applicable framework and the criticality of the use.
Who holds accountability for a general-purpose model across the lines of defense?
Accountability is commonly distributed rather than singular. In many organizations, the first line (those who deploy or use the model) owns the use-case risk, the second line provides independent oversight and challenge such as validation and risk management, and the third line offers independent assurance through audit. For a third-party general-purpose model, allocating these responsibilities can be less straightforward because some development activities sit outside the organization. Clear ownership documentation for each use is generally advisable, though the precise arrangement depends on organizational structure and governance choices rather than a single mandated model.
How should ongoing monitoring be handled given that a general-purpose model may change over time?
General-purpose models may be updated by their providers, and their behavior in a given application can shift, which raises the distinction between model risk and model performance degradation. Ongoing monitoring typically tracks whether the model continues to perform acceptably for each in-scope use and whether provider changes materially alter behavior. Practices may include establishing performance and stability indicators, defining triggers for revalidation, and recording version or change information where available. Monitoring reduces the likelihood that emerging issues go undetected but does not remove the underlying risk, and appropriate intensity generally scales with the criticality of the use.

Common misconceptions

A general-purpose AI model is simply any large language model or any large model.
General purpose refers to breadth of applicability across tasks, not to model size or architecture per se. While many general-purpose models are large, size alone does not define the category, and not every large model is treated as general-purpose in regulatory terms. The classification depends on the framework applying it, most prominently the EU AI Act, which is not universal across jurisdictions.
The obligations attached to general-purpose AI models are settled and apply the same way everywhere.
The term has a specific meaning within the EU AI Act and does not carry identical legal force in other jurisdictions. Regulatory treatment is still developing in many places, so requirements should be described with qualified language and verified against the applicable instrument rather than presented as globally settled law.
Governing a general-purpose model once, at the developer level, is sufficient to manage its risks.
Because these models are frequently integrated into many downstream applications, risk can arise at points of deployment and use that the original developer did not anticipate. Governance and model risk management are distinct but complementary here: organizational oversight structures do not substitute for identifying, measuring, and monitoring risks in each specific downstream context, and controls reduce rather than eliminate risk.

Best practices

Confirm which regulatory framework's definition of 'general-purpose AI model' applies to your context before assuming any specific obligation, noting that the term is most prominently used in the EU AI Act and may not carry the same meaning in other jurisdictions.
Map the deployment chain for each general-purpose model, documenting where it is integrated downstream and by whom, so that governance accountability and model risk responsibilities are clearly allocated across parties.
Distinguish governance activities (oversight structures, policies, accountability) from model risk management activities (identification, measurement, monitoring, and control of model risk) when designing controls, and address both rather than treating them as interchangeable.
Assess risk at the level of specific downstream uses, not only at the developer level, since broad applicability means the same model can present different risk profiles across applications.
Use qualified language in internal documentation when describing regulatory requirements for general-purpose models, given that regulatory treatment is still evolving and thresholds may change.
Verify specific thresholds, criteria, and effective dates against the current text of the governing instrument rather than relying on general summaries, and record the version consulted.