The EU AI Act introduces a tiered regulatory framework that treats general-purpose AI (GPAI) models and high-risk AI systems as distinct but potentially overlapping categories. For AI vendors, misclassification risks delayed market access, fines up to 35 million EUR or 7% of global turnover, and reputational damage. This article provides a visual decision flow to determine whether your AI system falls under GPAI obligations (Articles 53-55), high-risk obligations (Annex III), or both—along with
The EU AI Act introduces a tiered regulatory framework that treats general-purpose AI (GPAI) models and high-risk AI systems as distinct but potentially overlapping categories. For AI vendors, misclassification risks delayed market access, fines up to 35 million EUR or 7% of global turnover, and reputational damage. This article provides a visual decision flow to determine whether your AI system falls under GPAI obligations (Articles 53-55), high-risk obligations (Annex III), or both—along with a downstream impact matrix for compliance planning.
---
1. AI Act Classification Overview: Four Risk Tiers
The AI Act establishes four regulatory tiers, each with escalating compliance requirements:
- 1Prohibited AI (Article 5): Systems posing unacceptable risk, such as social scoring or real-time biometric identification in public spaces. These are banned outright, with limited exceptions for law enforcement.
- 2High-risk AI (Title III, Annex III): Systems used in critical infrastructure, education, employment, law enforcement, or migration control, among others. These require conformity assessments, technical documentation, and post-market monitoring.
- 3Limited-risk AI (Title IV): Systems subject to transparency obligations, such as chatbots or deepfakes, which must disclose their artificial nature to users.
- 4General-purpose AI (GPAI) models (Title VIIIa): Models capable of performing a wide range of tasks, regardless of their specific application. These are regulated separately from high-risk systems but may overlap if deployed in high-risk use cases.
The Act’s dual-layered approach means a single AI system could trigger obligations under both the GPAI regime (for the model itself) and the high-risk regime (for its specific application). Vendors must assess both dimensions to avoid gaps in compliance.
---
2. Decision Flow: Six Questions to Determine Your Obligations
The following Mermaid decision flow maps the classification process for AI vendors. Answer each question sequentially to identify your regulatory obligations.
graph TD
A[Start: Is your AI system or model intended for the EU market?] -->|Yes| B[Is the system/model prohibited under Article 5?]
A -->|No| Z[No AI Act obligations]
B -->|Yes| C[Prohibited AI: Do not deploy]
B -->|No| D[Is the system a general-purpose AI model?]
D -->|Yes| E[GPAI obligations apply (Art. 53-54)]
D -->|No| F[Is the system used in a high-risk area (Annex III)?]
E --> G[Does the model have systemic risk (Art. 55)?]
G -->|Yes| H[Systemic GPAI obligations apply (Art. 55)]
G -->|No| I[Standard GPAI obligations apply (Art. 53-54)]
F -->|Yes| J[High-risk obligations apply (Title III)]
F -->|No| K[Limited-risk or minimal-risk: Transparency or no obligations]
J --> L[Is the high-risk system also a GPAI model?]
L -->|Yes| M[Both GPAI and high-risk obligations apply]
L -->|No| N[High-risk obligations only]Key Questions Explained:
- 1Prohibited AI (Article 5): If your system falls under the banned use cases (e.g., manipulative subliminal techniques or predictive policing), it cannot be lawfully deployed in the EU.
- 2General-purpose AI (GPAI): If your model is designed to perform a wide range of tasks (e.g., large language models, image generators), it is a GPAI and subject to Title VIIIa obligations.
- 3Systemic GPAI (Article 55): If your GPAI model meets the systemic risk threshold (10^25 FLOPs or equivalent computational power), additional obligations apply (see Section 3).
- 4High-risk AI (Annex III): If your system is deployed in a high-risk use case (e.g., medical devices, critical infrastructure management, or employment screening), it is subject to Title III obligations.
- 5Overlap: If your GPAI model is deployed in a high-risk use case, both GPAI and high-risk obligations apply (see Section 4).
---
3. GPAI vs Systemic GPAI: The 10^25 FLOPs Threshold
The AI Act distinguishes between standard GPAI models and systemic GPAI models based on their computational power. This threshold is critical for vendors, as systemic GPAI models face stricter obligations under Article 55.
What Triggers Systemic GPAI Status?
- Computational threshold: A GPAI model is presumed to have systemic risk if it was trained using a total computing power of 10^25 floating-point operations (FLOPs) or more. This is the primary quantitative criterion.
- Qualitative criteria: The European Commission may also designate a model as systemic if it poses a "high impact risk" based on its capabilities, such as: - The number of business users or end-users. - The model’s autonomy and adaptability. - The breadth of tasks it can perform. - Its potential to propagate biases or generate harmful content at scale.
Article 55 Obligations for Systemic GPAI Models
If your model meets the systemic threshold, you must comply with Article 55, which includes:
- Model evaluations: Conducting adversarial testing to identify and mitigate systemic risks (e.g., bias, toxicity, or misalignment).
- Incident reporting: Notifying the European Commission and national authorities of serious incidents, such as model failures leading to harm.
- Cybersecurity measures: Implementing robust protections against model inversion attacks, data poisoning, or unauthorized access.
- Energy efficiency: Documenting and minimizing the model’s environmental footprint, including energy consumption during training and inference.
For standard GPAI models (below the 10^25 FLOPs threshold), obligations under Articles 53-54 include:
- Transparency: Providing technical documentation to downstream deployers, including training data sources, model architecture, and evaluation results.
- Copyright compliance: Ensuring training data does not infringe on copyrighted material, with opt-out mechanisms for rights holders.
- Instructions for use: Supplying clear guidelines for safe and compliant deployment.
---
4. High-Risk Overlay: When an AI System Is Both Foundation Model and High-Risk
A GPAI model deployed in a high-risk use case triggers dual obligations: compliance with both the GPAI regime (Title VIIIa) and the high-risk regime (Title III). This overlap is common for vendors offering "off-the-shelf" AI models adapted for specific applications, such as:
- A large language model fine-tuned for medical diagnosis (high-risk under Annex III, point 1).
- A computer vision model used for biometric identification in law enforcement (high-risk under Annex III, point 6).
- A predictive analytics model deployed in credit scoring (high-risk under Annex III, point 5a).
Key Challenges of Dual Compliance
- 1Conformity assessment: High-risk systems require a conformity assessment (either self-assessment or third-party certification, depending on the use case). GPAI models do not undergo conformity assessment unless deployed in a high-risk context.
- 2Technical documentation: High-risk systems must maintain a technical file (Annex IV), while GPAI models require model cards and training data documentation (Article 53). Vendors must reconcile these requirements without duplication.
- 3Post-market monitoring: High-risk systems require continuous monitoring and reporting of performance issues (Article 61), while systemic GPAI models must report serious incidents (Article 55). Vendors must integrate these processes.
- 4Instructions for use: High-risk systems must provide detailed instructions for safe deployment (Annex IV), while GPAI models must include guidelines for downstream compliance (Article 53). These should be combined into a single, coherent document.
Practical Example: An EU Mid-Cap AI Vendor
Consider an AI vendor developing a large language model (LLM) for two use cases:
- 1General-purpose chatbot: Deployed as a customer service tool for an e-commerce platform (limited-risk, subject to transparency obligations).
- 2Medical diagnosis assistant: Fine-tuned for healthcare providers to analyze patient symptoms (high-risk under Annex III, point 1).
For the chatbot, the vendor must comply with GPAI obligations (e.g., transparency, copyright compliance). For the medical assistant, the vendor must comply with both GPAI and high-risk obligations, including:
- A conformity assessment for the high-risk use case.
- A technical file documenting the model’s performance in medical contexts.
- Post-market monitoring for adverse events in clinical settings.
---
5. Compliance Roadmap: Key Deadlines for AI Vendors
The AI Act’s phased implementation means vendors must prioritize obligations based on their classification and the Act’s timelines:
| Date | Obligation | Applicability |
|---|---|---|
| 2 February 2025 | Prohibited AI ban in force | All AI systems falling under Article 5. |
| 2 August 2025 | GPAI obligations in force | All GPAI models, including systemic GPAI (Article 55). |
| 2 August 2026 | High-risk obligations in force | High-risk AI systems (Annex III), including those using GPAI models. |
| 12 July 2027 | Codes of practice for GPAI models | Voluntary but recommended for demonstrating compliance. |
| 11 December 2027 | Full applicability of the AI Act, including conformity assessment procedures | All high-risk systems must be certified