DoAIRight
ISO/IEC 42001

EU AI Act GPAI Obligations: Compliance Guide

PUBLISHED 06 AUG 2026

The EU AI Act GPAI framework establishes strict requirements for providers of general-purpose AI models (often referred to as foundation models), ranging from mandatory technical documentation and copyright policy compliance to systemic risk evaluations for high-capability models. Under the regulation, all general-purpose AI providers must maintain up-to-date technical documentation, publish summaries of training content, and adhere to EU copyright law. Models posing systemic risk face additional mandates, including adversarial testing, cybersecurity standards, and incident reporting. Organizations can align with these foundation model obligations by implementing an AI Management System (AIMS) structured around ISO/IEC 42001.

What is a GPAI Model Under the EU AI Act?

The EU AI Act defines a general-purpose AI (GPAI) model as an AI model trained on broad data at scale, capable of competently performing a wide range of distinct tasks, and easily integrated into downstream AI systems. Unlike narrow AI built for specific application domains, GPAI models serve as fundamental building blocks across industries.

The EU AI Act categorizes GPAI models into two tier structures:

  1. Standard GPAI Models: General-purpose models that meet baseline transparency and governance thresholds.
  2. GPAI Models with Systemic Risk: High-capability models, typically evaluated by computational training thresholds exceeding $10^{25}$ FLOPs (floating-point operations) or designated by the EU AI Office due to equivalent impact.

Baseline GPAI Obligations for All Providers

If your organization develops or fine-tunes a general-purpose AI model for market release in the European Union, you must satisfy several baseline compliance requirements:

  • Technical Documentation: Maintain comprehensive records detailing model architecture, training methodologies, energy consumption, and capabilities (Annex XI compliance).
  • Downstream Information Provision: Provide documentation to downstream integrators, ensuring they understand the model's capabilities, limitations, and operational requirements.
  • Copyright Compliance: Establish a policy to observe EU copyright laws, including respecting rights reservations under the Digital Single Market Directive.
  • Training Content Summary: Create and publicly release a sufficiently detailed summary of the datasets used to train or fine-tune the model.

Additional Obligations for GPAI Models with Systemic Risk

Providers of frontier models categorized as having systemic risk must implement enhanced governance frameworks:

  • Model Evaluation & Adversarial Testing: Conduct standardized model evaluations, including red-teaming and adversarial testing, to identify systemic vulnerabilities.
  • Systemic Risk Management: Continuously assess and mitigate potential systemic risks, such as algorithmic bias, disruption to critical infrastructure, or weaponization capability.
  • Serious Incident Reporting: Report serious security incidents and operational failures to the European AI Office and relevant national authorities without delay.
  • Cybersecurity Protection: Ensure robust physical, digital, and operational cybersecurity controls across the model life cycle.

Aligning EU AI Act Requirements with ISO/IEC 42001

Meeting complex foundation model obligations requires systematic organizational governance. An ISO/IEC 42001 AI Management System (AIMS) provides an actionable, standard-based blueprint to satisfy EU AI Act mandates seamlessly:

1. Risk and Impact Management (Clause 6, Annex A.5)

ISO/IEC 42001 requires organizations to systematically assess AI risks and societal impacts on individuals, groups, and communities (Annex A.5). This directly maps to the systemic risk assessment requirements outlined in the EU AI Act.

2. AI System Life Cycle Control (Annex A.6)

ISO/IEC 42001 control domain A.6 ensures rigorous oversight from dataset selection through development, evaluation, and retirement, directly covering technical documentation and red-teaming obligations.

3. Data Quality and Provenance (Annex A.7)

Domain A.7 focuses on data management for AI systems, helping organizations document data origin, verify licensing, and maintain compliance with transparency and copyright rules.

4. Transparency and Downstream Information (Annex A.8)

Control domain A.8 requires clear disclosure to downstream users and interested parties, matching EU requirements for technical documentation sharing and dataset summaries.

5. Vendor & Third-Party Oversight (Annex A.10)

Organizations integrating or fine-tuning third-party GPAI models must ensure compliance across their supply chain. Annex A.10 enforces strong vendor risk management controls.

Building a Continuous Compliance Management System

Compliance with general-purpose AI rules is not a one-time audit; it requires continuous monitoring under Clause 8 (Operation), Clause 9 (Performance evaluation), and Clause 10 (Improvement). Establishing governance through ISO/IEC 42001 helps organizations continuously maintain technical documentation, adapt to regulatory updates, and perform regular internal audits.

To prepare for formal ISO/IEC 42001 certification—which is granted independently by an accredited certification body following an auditor review under ISO/IEC 42006—organizations can utilize platforms like DoAIRight to assess their readiness, bridge governance gaps, and automate AIMS deployment.

Frequently asked

What qualifies as a general-purpose AI (GPAI) model under the EU AI Act?

A GPAI model is an AI model trained on broad data at scale that displays significant generality and can competently perform a wide range of distinct tasks, regardless of how it is placed on the market.

When does a GPAI model carry systemic risk?

A GPAI model is presumed to have systemic risk if its cumulative computational training budget exceeds 10^25 FLOPs, or if the EU AI Office designates it as having equivalent high-impact capabilities.

How does ISO/IEC 42001 help with EU AI Act GPAI compliance?

ISO/IEC 42001 provides a management system framework addressing risk management, impact assessments (Annex A.5), life cycle management (Annex A.6), data governance (Annex A.7), and stakeholder transparency (Annex A.8), directly supporting EU AI Act requirements.

Does DoAIRight issue ISO/IEC 42001 certificates?

No. DoAIRight provides tools to evaluate compliance readiness, implement governance frameworks, and prepare organizations for audit. Official certification must be issued by an independent accredited certification body.

See where you stand on ISO 42001.

A free readiness assessment scores you against every clause and control.

Get your score