Since when does Art. 53 apply – and to whom
The obligations for providers of general-purpose AI models (GPAI) have already applied since 02.08.2025 – alongside the governance rules and the penalty provisions of the AI Act. Anyone placing a GPAI model on the market should therefore no longer treat the obligations under Art. 53 as a future project, but as an ongoing compliance requirement. This applies regardless of whether the model is integrated into the provider’s own products or made available to third parties for integration.
The four core obligations under Art. 53(1)
Art. 53(1) AI Act sets out four obligations that must be met cumulatively:
a) Technical documentation (Annex XI). You must document the training and testing processes as well as the evaluation results – at least to the extent required by Annex XI. This includes, among other things, the model’s architecture and number of parameters, the release date, information on training, testing and validation data (type, provenance, curation methods, data points), as well as the computational resources used and the known or estimated energy consumption. This documentation must be available to be provided to the AI Office and the competent national authorities on request – it does not need to be published proactively, but must be kept accessible at all times.
b) Information for downstream providers (Annex XII). Anyone supplying their model to providers who integrate it into their own AI systems must provide them with information enabling them to understand the model’s capabilities and limitations and to fulfil their own obligations under the AI Act. Intellectual property and trade secrets must be protected in the process – the obligation to share information does not release providers from safeguarding these.
c) Copyright compliance policy. Providers must maintain a policy to comply with Union copyright law, in particular to identify and observe rights reservations under Art. 4(3) of Directive (EU) 2019/790 – for instance through technical processes that detect machine-readable opt-outs for text and data mining.
d) Summary of training content. A sufficiently detailed summary of the content used for training must be drawn up and published, following a template provided by the AI Office. Unlike the technical documentation under point (a), this is an active publication obligation.
Exemption for open source – but not a complete one
Art. 53(2) exempts providers of models under a free and open-source licence from obligations a) and b) – provided that access, use, modification and distribution are enabled and that parameters, architecture and information on use are publicly available. Obligations c) and d) – the copyright policy and the training data summary – remain in place regardless. Moreover, as soon as a model is classified as a GPAI model with systemic risk, the open-source exemption no longer applies at all. In that case, the stricter documentation requirements under Annex XI, Section 2, also apply – covering matters such as red-teaming measures and system architecture.
Codes of practice instead of harmonised standards
Until harmonised European standards are published, providers may, under Art. 53(4), rely on codes of practice pursuant to Art. 56 to demonstrate compliance with the obligations under paragraph 1. Anyone neither following an approved code of practice nor complying with a harmonised standard must demonstrate to the Commission alternative, equivalent compliance procedures. In practice, this is the more burdensome route – most providers therefore align themselves with the existing codes.
A common gap: contract instead of documentation
In practice, a gap often emerges between contractual and actual compliance: providers refer in licensing agreements to ‘model cards’ or API documentation that does not fully cover the minimum content required by Annex XI or Annex XII – for instance, missing information on the provenance of training data or on energy consumption. For downstream providers integrating the GPAI model, this is risky: they need precisely this information to fulfil their own obligations under the AI Act, and cannot rely solely on assurances from the model provider.
Whether your company qualifies as a provider, downstream provider or deployer of a GPAI-based system, and which obligations this entails in practice, can be clarified in a few minutes using the free risk assessment at /einstufung.