Module 3 has covered the GPAI compliance framework under Articles 51-56. The regulation's two-tier approach -- baseline obligations for all GPAI models and enhanced obligations for systemic risk models -- reflects the asymmetry in risks between standard and frontier models.
Key Distinctions to Remember
- All GPAI models: technical documentation (Annex XI), training summary (Annex XII), copyright policy, downstream information sharing
- Systemic risk GPAI models: above PLUS adversarial testing, systemic risk assessment, incident reporting, cybersecurity
- Open-source models: exempted from Article 53(1)(a) and (c) unless they have systemic risk
- Codes of practice create presumption of conformity -- non-adherence shifts burden of proof to the provider
- Role-switching: downstream providers who substantially modify a GPAI model become providers of the resulting model
Relationship to High-Risk AI Systems
A GPAI model integrated into a specific AI application may result in a high-risk AI system if the application falls under Annex III. In that case, the downstream provider is subject to both Article 53 downstream information obligations and the full high-risk AI system obligations under Articles 9-16. The GPAI model provider's obligations under Article 53 and 55 are separate from the downstream provider's obligations and do not substitute for them.