Back to Publications
Regulatory Brief · AI Act

AI Act general-purpose AI obligations: developer + deployer split and the 10^25 FLOP threshold

17 May 2026By NexCyber Editorial AI Act

As the European Union moves towards implementing the AI Act, the distinction between developers and deployers of general-purpose AI (GPAI) systems becomes crucial, especially for those working with advanced models like Llama 4. Chapter V of the AI Act introduces specific obligations for GPAI providers, with additional responsibilities triggered when the training compute exceeds 10^25 floating-point operations per second (FLOPs). This article explores the implications for foundation model provide

As the European Union moves towards implementing the AI Act, the distinction between developers and deployers of general-purpose AI (GPAI) systems becomes crucial, especially for those working with advanced models like Llama 4. Chapter V of the AI Act introduces specific obligations for GPAI providers, with additional responsibilities triggered when the training compute exceeds 10^25 floating-point operations per second (FLOPs). This article explores the implications for foundation model providers and downstream integrators, providing guidance on navigating these new regulatory landscapes.

GPAI Default vs Systemic Risk

The AI Act establishes a dual-track approach to regulating GPAI systems, distinguishing between default obligations and those applicable to systems posing systemic risks.

Default Obligations

Under the AI Act, GPAI providers are subject to a set of baseline requirements aimed at ensuring transparency, safety, and accountability. These include obligations to maintain technical documentation, ensure data quality, and implement risk management systems. Providers must also facilitate traceability and ensure that their systems can be monitored effectively post-deployment.

Systemic Risk Obligations

When a GPAI system is deemed to pose a systemic risk, additional obligations come into play. These are designed to address the broader impact such systems may have on society and the economy. The criteria for systemic risk are not solely based on the system's capabilities but also on its potential use cases and the scale of its deployment. For instance, a startup fine-tuning Llama 4 for large-scale applications may find itself subject to these heightened obligations, requiring more rigorous compliance measures.

The 10^25 FLOP Threshold: How to Compute, Who Certifies

One of the key determinants of whether a GPAI system is subject to systemic risk obligations is the computational power used during its training phase, specifically if it exceeds 10^25 FLOPs.

Calculating FLOPs

To compute the FLOPs used in training an AI model, developers need to consider the number of operations performed per second during the training process. This involves accounting for the complexity of the model, the size of the datasets used, and the duration of the training period. The calculation must be precise, as underestimating can lead to non-compliance, while overestimating may unnecessarily trigger systemic risk obligations.

Certification and Verification

The AI Act stipulates that the determination of whether a system meets the 10^25 FLOP threshold must be verified by a competent authority. This ensures that the assessment is objective and consistent across different providers. The certification process involves a detailed review of the training logs, computational resources, and methodologies used. Providers are encouraged to maintain comprehensive records and engage with certification bodies early in the development process to facilitate smooth compliance.

Developer vs Deployer Duties: Technical Documentation, Copyright Compliance

The AI Act delineates distinct responsibilities for developers and deployers of GPAI systems, emphasizing the need for collaboration and information sharing.

Developer Responsibilities

Developers are primarily responsible for creating and maintaining comprehensive technical documentation that outlines the design, development, and intended use of the AI system. This documentation must include details on the datasets used, the model architecture, and the training process. Furthermore, developers must ensure that their systems comply with copyright laws, particularly when using third-party data or pre-trained models.

Deployer Responsibilities

Deployers, on the other hand, are tasked with implementing the AI system in a manner that aligns with its intended use and the regulatory framework. This includes conducting impact assessments to identify potential risks and ensuring that the system operates within the parameters set by the developer. Deployers must also monitor the system's performance and report any incidents or deviations from expected behavior to the appropriate authorities.

Next Step with NexCyber

Navigating the AI Act's requirements for general-purpose AI systems can be complex, especially when determining the obligations triggered by the 10^25 FLOP threshold. NexCyber offers a comprehensive GPAI obligation classifier to assist developers and deployers in assessing their compliance requirements. For more information and to access our tools, visit [NexCyber GPAI Obligation Classifier](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=ai-act-gpai-developer-deployer-flop-threshold).