CSOAI - GPAI obligations
If you ship a model, this is your 2 Aug 2026 list
General-purpose AI provider obligations become enforceable on 2 August 2026. Here is exactly what every model provider owes - and the extra duties if your model carries systemic risk.
You are interacting with an AI system.
The embedded 'Ask the Sovereign' panel (SovereignSpot) sends questions to the live Sovereign chat endpoint (os.meok.ai/api/chat), where a model writes the answer. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.
Disclosed under EU AI Act Article 50(1). Every surface and its classification
Every GPAI provider
Keep up-to-date docs on the model's design, training, and evaluation for regulators and downstream providers.
Publish a sufficiently detailed public summary of the content used to train the model.
Put a policy in place to comply with EU copyright law and honour text-and-data-mining opt-outs.
Give downstream deployers what they need to understand capabilities and limitations.
Systemic-risk models (additional)
Adversarial testing / red-teaming to find and mitigate systemic risks.
Track and report serious incidents and corrective actions to the AI Office.
Protect the model and its physical infrastructure to an adequate level.
Assess and mitigate risks at the Union level on an ongoing basis.