CSOAI - GPAI obligations

If you ship a model, this is your 2 Aug 2026 list

General-purpose AI provider obligations become enforceable on 2 August 2026. Here is exactly what every model provider owes - and the extra duties if your model carries systemic risk.

You are interacting with an AI system.

The embedded 'Ask the Sovereign' panel (SovereignSpot) sends questions to the live Sovereign chat endpoint (os.meok.ai/api/chat), where a model writes the answer. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.

Disclosed under EU AI Act Article 50(1). Every surface and its classification

Every GPAI provider

Technical documentation

Keep up-to-date docs on the model's design, training, and evaluation for regulators and downstream providers.

Training-data summary

Publish a sufficiently detailed public summary of the content used to train the model.

Copyright policy

Put a policy in place to comply with EU copyright law and honour text-and-data-mining opt-outs.

Downstream information

Give downstream deployers what they need to understand capabilities and limitations.

Systemic-risk trigger: if training compute exceeds 10^25 FLOP, your model is presumed systemic and the four duties below apply on top of the base list.

Systemic-risk models (additional)

Model evaluation

Adversarial testing / red-teaming to find and mitigate systemic risks.

Serious-incident reporting

Track and report serious incidents and corrective actions to the AI Office.

Cybersecurity

Protect the model and its physical infrastructure to an adequate level.

Systemic-risk assessment

Assess and mitigate risks at the Union level on an ongoing basis.

Ask the Sovereign — GPAI / foundation-model provider obligations
Governed answer · AI governance & cybersecurity only · signed to Layer 0
Open the full AI OS →