Governing the Foundation: An Examination of the AI Act's New Rules for General-Purpose AI Models (GPAI)
This paper examines how the European Union’s Artificial Intelligence Act (AI Act) seeks to govern risks associated with foundation-model–scale AI systems through the introduction of a dedicated regulatory category for General-Purpose AI (GPAI) models. Focusing on Chapter V of Regulation (EU) 2024/1689, the analysis explores the rationale, structure and limits of the AI Act’s model-level governance approach, with particular attention to the enhanced obligations imposed on GPAI models designated as presenting systemic risk. The paper situates the GPAI regime against the technical notion of foundation models, highlighting the deliberate divergence between a research-driven, architectural understanding of such models and the AI Act’s functional, deployment-oriented legal definition. This divergence, while central to the Act’s regulatory strategy, raises challenges for legal certainty and for the operationalization of concepts such as “generality” and task breadth. Tracing the evolution from the Commission’s 2021 proposal—focused exclusively on system-level, use-based risk classification—to the final 2024 text, the paper shows how the Act extends regulatory attention upstream, placing direct obligations on model providers prior to downstream integration.
Paper
Full text
Governing the Foundation: An Examination of the AI Act's New Rules for General-Purpose AI Models (GPAI)
Semantic Scholar · 2026
Abstract
This paper examines how the European Union’s Artificial Intelligence Act (AI Act) seeks to govern risks associated with foundation-model–scale AI systems through the introduction of a dedicated regulatory category for General-Purpose AI (GPAI) models. Focusing on Chapter V of Regulation (EU) 2024/1689, the analysis explores the rationale, structure and limits of the AI Act’s model-level governance approach, with particular attention to the enhanced obligations imposed on GPAI models designated as presenting systemic risk. The paper situates the GPAI regime against the technical notion of foundation models, highlighting the deliberate divergence between a research-driven, architectural understanding of such models and the AI Act’s functional, deployment-oriented legal definition. This divergence, while central to the Act’s regulatory strategy, raises challenges for legal certainty and for the operationalization of concepts such as “generality” and task breadth. Tracing the evolution from the Commission’s 2021 proposal—focused exclusively on system-level, use-based risk classification—to the final 2024 text, the paper shows how the Act extends regulatory attention upstream, placing direct obligations on model providers prior to downstream integration.