On this date, several key provisions of the EU AI Act will come into force, which are primarily aimed at so-called GPAI models – that is, general-purpose AI models that can be used for a wide range of purposes (text, code, language, images, etc.). These include, for example, models such as GPT, LLaMA and Claude. These are therefore AI models that have not been developed solely for a specific task, but are capable of performing a wide range of tasks across different fields.
Obligations for providers of GPAI
Providers of GPAI models will in future have to comply with new requirements under the EU AI Act, which demand greater transparency and accountability in the use of AI. This includes technical documentation that clearly explains how the model is structured, what data it was trained on, and how much computing power was required for this.
In addition, transparency reports must be published, disclosing the model’s known weaknesses, risks and limitations. Furthermore, testing is mandatory to ensure that the AI does not produce discriminatory or dangerous results. The energy efficiency of the training process must also be documented to make resource consumption more transparent.
Another key point is the disclosure of the training data used. Providers should explain, in an easily understandable way, what data the model was trained on and where it came from. This is to ensure that it remains clear how the AI learns – and whether its basis is reliable and fair.
Additional requirements apply to particularly powerful models that are classified as posing systemic risk:
- Obligation to carry out risk assessments
- Adversarial testing to prevent misuse
- Introduction of risk mitigation measures
- Obligation to report incidents to supervisory authorities
The EU Member States themselves must also be in a position to act by then: they must designate national supervisory and notification authorities and put in place the necessary enforcement infrastructure.
Obligations for users of GPAI
In addition to providers, users of General-Purpose AI (GPAI) models are also subject to new requirements – particularly where GPAI is integrated into high-risk applications, such as in the fields of human resources, healthcare or finance. In such cases, users must ensure that the systems they use comply with the provisions of the EU AI Act, including documentation obligations, risk assessments and transparency requirements.
Why this issue is highly relevant right now
The provisions of the AI Act are no longer just theory – they have been adopted, have a set timetable and are accompanied by clear sanction mechanisms. From August 2025, companies and public authorities that develop, purchase or use AI technology may be subject to scrutiny by the authorities and face sanctions in the event of non-compliance.
The penalties are severe:
- Up to 35 million euros or 7 % of global annual turnover for breaches of prohibitions
- Up to 15 million euros or 3 % of annual turnover for failure to comply with GPAI obligations
- Even providing false information to supervisory authorities can result in a fine of up to 7.5 million euros or 1.5 %
A particularly pressing issue is that many technical requirements (e.g. regarding training data or system boundaries) have not yet been fully standardised. The EU’s announced ‘Code of Practice’ is not expected to be published until the end of 2025 – companies should therefore keep a close eye on developments and respond appropriately once it is published.
To-do list: What do you need to prepare now?
1. Stock-take & risk classification
Compile a comprehensive AI inventory: Which systems do you use? Are they in-house developments or third-party models? Is GPAI being used?
Classify them according to the risk categories set out in the AI Act (prohibited, high-risk, GPAI, systemic). This forms the basis for all further measures.
2. Technical documentation and transparency
For all GPAI systems, you will need:
- Model descriptions and the architecture in which the system is deployed
- A list and categorisation of the training data (e.g. text, images, audio, licence status)
- Details of training time, energy consumption and the infrastructure used
- Evidence of bias tests, robustness and failure behaviour
This data must be verifiable internally and presentable to the authorities.
3. Establish governance structures
Define internal responsibilities for:
- AI compliance and regulatory monitoring
- Data protection and AI ethics
- Incident reporting and audits
Integrate these structures into your existing risk and IT management. This is particularly important as the risk analysis, once documented within the context of the enterprise architecture (as described in point 2), may lead to new insights.
4. Review contracts and supply chains
If you use third-party AI (e.g. via APIs or in SaaS solutions), check the following:
- Are there contractual assurances regarding AI compliance?
- Are you informed about training data, system risks and limitations?
- Do you have access to audit reports and security certifications?
You may need to amend your procurement policies or introduce new standard clauses. Don’t forget your public liability insurance and cyber insurance!
5. Training & internal awareness
The AI Act requires companies to ensure staff have adequate knowledge of how to handle AI. Develop:
- Basic training courses for managers and specialist departments
- Specialist training for IT, data science, procurement and legal departments
- Processes for continuous professional development and documentation
What comes next?
Further milestones will follow in 2026, particularly for high-risk AI systems (e.g. in HR, the healthcare sector and finance). There will also be mandatory certifications, compliance procedures and extensive audit requirements at that stage.
Furthermore, new EU regulations such as the Cyber Resilience Act and the Data Act are closely linked to the AI Act. Anyone taking a strategic approach to AI compliance should factor these developments into their planning today.