The Clock Has Struck
On August 2, 2025, the EU AI Act's transparency obligations for General-Purpose AI GPAI models became enforceable -- six months after the initial prohibited practices provisions took effect. This second wave of requirements affects a much broader set of organizations: anyone developing, deploying, or distributing GPAI models including fine-tuned versions that interact with EU residents.
What GPAI Providers Must Now Do
The transparency requirements are substantial:
Technical documentation: Providers must maintain comprehensive documentation of model architecture, training methodology, data sources, and known limitations. This is not a one-time exercise -- documentation must be updated with each significant model change.
Copyright compliance: Providers must implement policies and technical measures regarding copyrighted training data, including maintaining records of data sources and honoring opt-out requests from rights holders.
Energy consumption disclosure: GPAI providers must report the energy consumption of their model training and, where feasible, inference operations.
Downstream notification: Organizations that deploy GPAI models in applications must inform end-users that they are interacting with AI-generated content.
The "Systemic Risk" Category
GPAI models classified as posing "systemic risk" -- generally those with training compute above 10^25 FLOPs, which includes GPT-4, GPT-5, Claude 3.5+, and Gemini 1.5+ -- face additional obligations:
- Model evaluation and adversarial testing - Systemic risk assessment and mitigation - Incident monitoring and reporting to the EU AI Office - Cybersecurity protections for model weights
Enterprise Compliance Implications
For enterprises using GPAI-based tools and services, the compliance burden varies by role:
If you build on foundation models fine-tuning, RAG implementations, custom applications, you share provider obligations for transparency and documentation of your specific modifications.
If you deploy AI-powered SaaS tools, your vendor's compliance posture directly affects your own. Audit your AI vendors' EU AI Act readiness now.
If you serve EU customers, even from outside Europe, extraterritorial provisions apply. US and Australian companies with European customer bases must ensure their AI applications comply.
The Compliance Opportunity
Organizations that proactively meet these transparency requirements differentiate themselves in a market increasingly sensitive to AI governance. Documented compliance:
- Builds trust with enterprise customers conducting vendor due diligence - Reduces regulatory risk as enforcement mechanisms mature - Positions organizations favorably as other jurisdictions adopt similar frameworks - Creates internal discipline that improves AI system quality
The August 2025 GPAI deadline is not the end of EU AI Act compliance -- it is the middle. High-risk AI system obligations arrive in August 2026. Organizations that establish gove