GPAI Obligations Under the EU AI Act: Scope and Contractual Responses Japanese Companies Should Check
A summary of the GPAI model obligations under the EU AI Act, covering scope, the entities bearing obligations, transitional measures, the Code of Practice, and contractual responses for Japanese companies.
Primary sources
The announcements and documents this analysis covers.
Of the EU AI Act (Regulation (EU) 2024/1689), Articles 51 to 56, which set out the obligations concerning general-purpose AI (GPAI) models, have applied since August 2, 2025. As of the time of writing (July 12, 2026), nearly a year has passed, but full-scale enforcement, including the provision on fines for GPAI providers (Article 101), begins on August 2, 2026, and existing models benefit from a transitional period until August 2, 2027. This article focuses on the GPAI model obligations under Article 51 onward and examines their scope, the distinction among the entities that bear obligations, the legal nature of the Code of Practice, and the impact on Japanese companies' vendor review and contract practice. The obligation to label AI-generated content (Article 50) is outside the scope of this article.
What Has Applied, and Since When
Article 3(63) defines a GPAI model as "an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications," and excludes models used only for research, development or prototyping activities before they are placed on the market. A GPAI model itself is not a "system"; what incorporates a model so that it can be used for a variety of purposes is a "GPAI system" under Article 3(66).
Under Article 53(1), providers of GPAI models are required to draw up and keep up to date technical documentation, including the training and testing process (a); to draw up documentation explaining the model's capabilities and limitations and the like for downstream businesses that integrate the model (b); to put in place a policy to comply with copyright law (c); and to draw up and make publicly available a summary of the content used for training (d). Models released under an open-source license with their parameters made publicly available are exempt from (a) and (b), but this exemption does not apply if the model is classified as presenting systemic risk.
The criteria for classification as presenting systemic risk are in Article 51. In addition to cases where a model is assessed as having high-impact capabilities, a model is presumed to have high-impact capabilities where the cumulative amount of computation used for its training exceeds 10 to the 25th power floating-point operations (Article 51(2)). Under Article 55, providers of models so classified bear additional obligations: conducting model evaluations, including adversarial testing based on state-of-the-art methods; assessing and mitigating systemic risks; reporting serious incidents to the AI Office; and ensuring cybersecurity protection.
As for timing, Article 113 provides that Section 4 of Chapter III, Chapter V (Articles 51 to 56), Chapter VII, Chapter XII and Article 78 apply from August 2, 2025, and excludes Article 101 (fines for GPAI providers) from that application. Because the general date of application of the Regulation as a whole, including Article 101, is August 2, 2026, the structure is such that the substantive obligations of GPAI providers have arisen since August 2, 2025, while enforcement through fines begins one year later. In addition, Article 111(3) provides a transitional measure under which providers of GPAI models placed on the market before August 2, 2025 need only comply with the obligations by August 2, 2027.
The simplification package (Digital Omnibus), which received final Council approval on June 29, 2026, centers on postponing the application dates for high-risk AI systems, and does not change the GPAI model obligations in Articles 51 to 56 themselves. While it includes content clarifying that the AI Office has priority competence where the same provider develops both a model and a system incorporating it, the powers of national authorities are maintained in the areas of law enforcement, border management, judicial authorities and financial institutions.
Who Bears the Obligations
The addressees of Articles 53 and 55 are strictly "providers of GPAI models." A "provider" under Article 3(3) is defined as a person that develops an AI system or GPAI model, or has one developed, and places it on the market under its own name or trademark, or puts the AI system into service. Accordingly, where a Japanese company develops its own foundation model and provides it to customers in the EU, it is a provider in this sense and bears the obligations under Article 53 (and, where applicable, Article 55) directly.
In contrast, where a Japanese company builds its own service by integrating a GPAI model developed by another company (which may be a U.S., Japanese or any other business) and places it on the EU market, it is a "downstream provider" under Article 3(68). A downstream provider is defined as standing in the position of a provider of an AI system integrating a GPAI model, regardless of whether it developed the model itself or received it from another business under a contract; while it does not bear the obligations under Articles 53 and 55 as a provider of the model itself, it is in the position of bearing separate obligations as a provider of the AI system it has built (including the obligations applicable to high-risk AI systems where the system qualifies as one). In this case, whether the downstream provider can fulfill its own obligations depends on whether it can obtain from the model provider the documentation explaining capabilities and limitations under Article 53(1)(b).
On the other hand, where a company merely uses a tool incorporating a GPAI model in its own operations, it is positioned as a "deployer" under Article 3(4) (a person using an AI system under its authority), and the obligations under Articles 51 to 56 do not apply directly. Even in the position of a deployer, however, whether the provider of the service being procured is fulfilling its documentation obligations under Article 53 can be a factor in vendor selection.
As for extraterritorial application, Article 2 makes clear that providers placing AI systems or GPAI models on the market or putting them into service in the EU are covered regardless of whether they are established or located in the EU or in a third country, and further covers providers and deployers located in a third country where the output of their AI system is used in the EU. Before a provider established in a third country places a GPAI model on the EU market, it must, under Article 54, appoint by written mandate an authorised representative established in the EU. This representative is responsible for verifying that the obligations under Article 53 (and Article 55, where applicable) have been fulfilled, keeping the relevant documentation for 10 years, and providing it to the authorities upon request. Models released under an open-source license with their parameters made publicly available are exempt from this appointment obligation, but not if they are classified as presenting systemic risk.
Legal Nature of the GPAI Code of Practice
Article 56 provides that the AI Office is to encourage and facilitate the drawing up of a Code of Practice, with the participation of GPAI model providers, national authorities, civil society, academia and others, to support the proper application of the obligations under Articles 53 and 55. According to the account published by the European Commission, the final version of this Code of Practice was submitted to the Commission on July 10, 2025, after a multi-stakeholder process chaired by independent experts, and on August 1, 2025, ahead of August 2, 2026, the European Commission and the AI Board each made an adequacy decision (confirmation of adequacy).
As to its legal nature, participation in the Code of Practice is not mandatory. Articles 53(4) and 55(2) provide that, until harmonized standards are in place, providers may rely on the Code of Practice to demonstrate compliance with their obligations, while also leaving open to providers that do not follow the Code a path to demonstrate alternative adequate means of compliance, subject to assessment by the Commission. A provider that does not sign bears the burden of explaining to the Commission itself the adequacy of its alternative means. Article 56 also provides that if a Code of Practice is not finalized or is deemed inadequate, the Commission may lay down common rules by implementing act, but the adequacy decision of August 1, 2025 means that this situation has not arisen.
In parallel with the Code of Practice, on July 24, 2025 the European Commission published a template for the obligation to publish a summary of training content under Article 53(1)(d). Use of this template is mandatory as the means of implementing Article 53(1)(d); it applies to new models placed on the market on or after August 2, 2025, with a transitional period until August 2, 2027 for existing models. Its content consists of general information about the provider and the model, a classification of the data used for training by type (public datasets, licensed datasets, online content collected or scraped, user data, synthetic data and the like), and descriptions of processing aspects such as copyright compliance and removal of illegal content, and it also applies to open-source models. From the standpoint of the handling of training data, this also relates to the issues organized in Generative AI, Copyright and Training Data Checkpoints. Separately from the Code of Practice, the European Commission has also published interpretive guidelines for GPAI providers, and an update can be confirmed as of April 28, 2026. These guidelines are not legally binding, but as the Commission's own interpretation, they set out its approach to whether a model qualifies as a GPAI model, the conditions for applying the open-source exemption, and notification of systemic risk.
Impact on Japanese Companies' Contracts and Vendor Review
As a premise, it is necessary to check which of the company's services will be "placed" on the EU market. Because the nature of the obligations differs between providing a self-developed model directly to customers in the EU and providing in the EU the company's own service that integrates another company's model, the starting point is to classify the company's services according to whether they are provided as a model provider, provided as a downstream provider, or merely used as a deployer.
Where a company is in the position of building services by integrating another company's GPAI model, it may confirm with the vendor, as specific question items, whether the model used is a GPAI model under Article 3(63); whether it is classified as presenting systemic risk; whether the vendor can provide the documentation explaining capabilities and limitations under Article 53(1)(b) (for downstream integrators); the content of its copyright compliance policy; the URL where its training data summary template is published; whether it has signed the Code of Practice; and, if it is a third-country provider, the status of its appointment of an authorised representative in the EU. The practical response is to add these GPAI-specific items to the check items organized in AI Vendor Due Diligence and Contract Review.
As contract clauses, it may be possible to incorporate into the contract, as document-provision obligations and representation and warranty clauses, the vendor's obligation to continuously provide the technical documentation under Article 53(1)(a) and (b) and the documentation for integrators, representations and warranties concerning the handling of training data in compliance with copyright law, an obligation to give notice where the training data summary is updated every six months, and an obligation to give prompt notice upon classification as presenting systemic risk. The possibility that training data may include users' personal data partly overlaps with the review of contract clauses covered in What Are Personal Data Handling Clauses? Points to Check in Outsourcing and SaaS Agreements, and I think it is advisable to examine the content of the training data summary published by the vendor together with the review of contract clauses on the handling of personal data.
Developments to Watch
On August 2, 2026, fines under Article 101 begin to apply, and the AI Office's exercise of enforcement powers, such as requests for information, access to models and recalls, is also expected to get fully under way. From that date, it will be necessary to examine how existing vendor review and contractual measures function in actual enforcement. On August 2, 2027, the transitional period for models placed on the market before August 2, 2025 ends, so companies will need to check the status of compliance by that date even for models they have used for a long time.
The Digital Omnibus clarification of the AI Office's competence concerns the division of roles among authorities where the same provider develops both a model and a system, and the content of future implementing acts and official guidance will need to be checked. The European Commission's interpretive guidelines for GPAI providers have also continued to be updated as of April 28, 2026, and it is necessary to keep checking whether there are further revisions concerning the conditions for applying the open-source exemption and the criteria for notification of systemic risk. For the Code of Practice as well, reporting by signatories on implementation and the concrete development of its operation in the Signatory Taskforce are expected to progress, and it may be worth adding the status of the vendors the company deals with to the items to be checked periodically.