NO AI ACT.

GPAI · Generative AI

General-purpose AI

Most of the regulation reasons about systems built for a purpose. General-purpose models — including the generative models behind modern chatbots — are built for almost any purpose. That mismatch is why they get their own treatment, and why they make such a good final lesson.

01What GPAI is, plainly

A general-purpose AI model displays broad capabilities and can be integrated into countless downstream applications: drafting, coding, answering, summarising. "Generative AI" is the familiar face of the category — models that produce text, images or audio.

The regulation's own definition is narrower than everyday usage. Article 3 describes a model trained on a large amount of data with self-supervision at scale, displaying significant generality, able to perform competently across a wide range of distinct tasks, and integrable into many downstream systems. Models used only for research, development or prototyping before they reach the market fall outside it.

02How it differs from the usual examples

A CV-screening system has one purpose, one context, one risk profile you can assess in advance. A general model has none of that until someone deploys it: the same model can draft birthday poems and, plugged into a welfare office, draft benefit decisions. Risk lives in the integration, not the model card.

03Downstream use: the real lesson

The game's final case ("The do-it-all model") captures the pattern: an office quietly lets a general model draft decisions — no criteria, no review, no logging. The model isn't prohibited; nothing about it is automatically high-risk; and yet the use demands governance: defined limits, human review that actually reviews, traceability. The question "what is this model?" gives way to "what are we letting it decide?".

04What the regulation asks of the model's provider

Chapter V of the AI Act — Articles 51 to 56 — treats general-purpose models separately from AI systems. The split is worth teaching, because it explains who carries which duty.

  • Article 53 addresses the provider of the model: keep technical documentation, give downstream providers what they need to integrate it responsibly, adopt a copyright policy, and publish a summary of the training content.
  • Article 51 singles out a smaller group — models with systemic risk — identified through capability criteria that include a presumption based on training compute.
  • Article 55 adds heavier duties for that group: evaluating the model, mitigating systemic risks, reporting serious incidents, protecting against cyber threats.
  • Article 56 lets providers rely on codes of practice to demonstrate compliance while harmonised standards are still being written.

None of this settles the question the game asks. A model can satisfy Chapter V and still be integrated, downstream, into a decision that needs governance nobody has set up — and that ground belongs to the deployer, not to the model provider. The guide to providers and deployers maps that responsibility chain; for when each part of the regulation started to apply, see the application timeline.

05Educational cautions

  • GPAI rules are the newest, most-discussed part of the framework: teach the logic, not confident detail that may date quickly.
  • Avoid both reflexes: "generative AI is unregulated" is false; "generative AI is banned" is more false.
  • Anchor discussions in concrete integrations, not in the model as an abstraction — and check terms in the glossary (GPAI, provider, deployer).

Authoritative follow-up reading: the European AI Office, which oversees GPAI matters.