---
title: "EU AI Act GPAI Provider Obligations: Articles 53 and 55"
canonical_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/gpai-and-foundation-model-obligations"
source_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/gpai-and-foundation-model-obligations"
author: "Sorena AI"
description: "Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "EU AI Act"
  - "GPAI"
  - "general-purpose AI model"
  - "Article 53"
  - "Article 55"
  - "systemic risk"
  - "AI Office"
  - "training content summary"
  - "copyright policy"
  - "general-purpose AI models"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU AI Act GPAI Provider Obligations: Articles 53 and 55

Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.

*Artifact Guide* *EU AI Act*

## EU AI Act GPAI Provider Obligations

This page helps separate baseline Article 53 duties for general-purpose AI model providers from the extra Article 55 duties for models with systemic risk.

Covers technical documentation, downstream information, Union copyright policy, public training-content summaries, systemic-risk controls, serious-incident reporting, and Code of Practice caveats.

The AI Act uses the term general-purpose AI model, not foundation model, for models with significant generality that can be integrated into many downstream systems or applications. This page focuses on provider duties for those GPAI models: the baseline Article 53 duties that apply to GPAI model providers and the additional Article 55 duties that apply when a GPAI model is classified as having systemic risk.

## Who is this GPAI provider page for?

Start with role and model classification. A provider is the organisation that develops a general-purpose AI model, or has one developed, and places it on the market under its own name or trademark. A deployer, downstream AI-system provider, reseller, or customer may have AI Act duties, but Article 53 and Article 55 are written for GPAI model providers.

Use foundation model as a search synonym only. The public compliance record should use the AI Act term general-purpose AI model, because the obligations and annexes are tied to that defined term.

- Confirm whether the asset is a GPAI model before treating it as an AI system or high-risk AI system.
- Record whether the model is placed on the Union market directly, through an API, by download, through a library, or as part of the provider's own AI system.
- Separate model-provider obligations from downstream AI-system obligations so Article 53 information can actually support integrators.
- If the model is only used for purely internal processes that are not essential for providing a third-party product or service and do not affect natural persons' rights, record why the GPAI placing-on-market trigger is absent.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Primary legal text defining providers, general-purpose AI models, systemic risk, and Chapter V obligations.
- [European Commission - GPAI provider guidelines](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) - Commission page explaining that its GPAI guidelines clarify who is expected to follow provider obligations.

## Article 53 baseline duties for GPAI model providers

Article 53 requires four core workstreams for providers of general-purpose AI models: model technical documentation for the AI Office and authorities, information for downstream AI-system providers, a Union copyright-law policy, and a public summary of training content using the AI Office template.

The documentation workstream is not just a model card. Annex XI points to model purpose, acceptable-use policies, release and distribution method, architecture, parameters, modality, licence, training and testing process, data provenance and curation, compute used for training, training time, and known or estimated energy consumption where relevant.

- Maintain Article 53(1)(a) technical documentation for the model, including training and testing process and evaluation results, so it can be provided to the AI Office and national competent authorities on request.
- Maintain Article 53(1)(b) information for downstream providers that intend to integrate the GPAI model into their AI systems, with at least the Annex XII elements.
- Put in place an Article 53(1)(c) policy to comply with Union copyright and related-rights law, including identifying and complying with rights reservations under Article 4(3) of Directive (EU) 2019/790.
- Publish an Article 53(1)(d) sufficiently detailed summary of the content used for training the GPAI model, using the AI Office template.
- Cooperate as necessary with the Commission and national competent authorities when they exercise their AI Act powers.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Article 53 and Annexes XI-XII set the baseline GPAI provider documentation, downstream-information, copyright-policy, and training-summary duties.
- [European Commission - Model Documentation Form](https://ec.europa.eu/newsroom/dae/redirection/document/118118?ref=sorena.io) - Commission Code of Practice form for organising the model documentation used for Article 53 transparency commitments.
- [European Commission - Public Summary of Training Content template](https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models?ref=sorena.io) - Commission explanatory notice and template for the public training-content summary required by Article 53(1)(d).

## Open-source and modified model caveats

Article 53 has a limited open-source exception for the documentation and downstream-information duties in Article 53(1)(a) and (b). It applies only when the model is released under a free and open-source licence allowing access, use, modification, and distribution, and when parameters, weights, architecture information, and model-usage information are made publicly available.

That exception does not remove the copyright-policy duty or the public training-summary duty, and it does not apply to GPAI models with systemic risk. The Commission's GPAI provider guidelines also warn that significant modifications can make the modifier a provider for the relevant model changes, while minor changes are treated differently.

- Do not mark Article 53 complete merely because weights are public; check the exact licence and public availability of parameters, architecture, and usage information.
- For open-source GPAI models, still maintain the Article 53 copyright-policy and training-summary workstreams unless an official exemption applies.
- For fine-tuned or modified models, keep a record of what changed, new training-data sources, and whether the change is significant enough to create provider obligations.
- If the model has systemic risk, treat the open-source exception as unavailable for Article 53(1)(a) and (b) and apply Article 55 as well.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Article 53(2) states the limited open-source exception and expressly excludes systemic-risk GPAI models from it.
- [European Commission - GPAI provider guidelines](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) - Commission guidance page summarising its position on significant modifications and open-source GPAI conditions.

## Systemic-risk classification and Article 55 duties

A GPAI model is classified as having systemic risk if it has high-impact capabilities evaluated with appropriate tools and methodologies, including indicators and benchmarks, or if the Commission designates it based on equivalent capabilities or impact. Article 51 creates a presumption of high-impact capabilities when training compute is greater than 10^25 floating point operations.

When the systemic-risk classification applies, Article 55 adds duties on top of Articles 53 and 54. The provider must evaluate the model, assess and mitigate Union-level systemic risks, track and report serious incidents without undue delay, and ensure an adequate level of cybersecurity protection for the model and its physical infrastructure.

- If the Article 51 high-impact-capabilities condition is met, notify the Commission without delay and in any event within two weeks after the requirement is met or becomes known.
- Document any substantiated argument that the model exceptionally should not be classified as systemic risk despite meeting the high-impact-capability condition.
- Run and document model evaluations, including adversarial testing, against systemic-risk scenarios before treating Article 55 controls as complete.
- Keep a systemic-risk register covering sources, mitigations, residual risk acceptance, cybersecurity controls, incident triggers, and corrective measures.
- Use the Commission serious-incident reporting template for incidents involving GPAI models with systemic risk when reporting relevant information and corrective measures.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Articles 51, 52, and 55 define systemic-risk classification, notification timing, and the additional duties for GPAI models with systemic risk.
- [European Commission - Serious incident template for GPAI models](https://digital-strategy.ec.europa.eu/en/library/ai-act-commission-publishes-reporting-template-serious-incidents-involving-general-purpose-ai?ref=sorena.io) - Commission page for the reporting template covering serious incidents involving GPAI models with systemic risk.
- [European Commission - GPAI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai?ref=sorena.io) - Commission page explaining that the Safety and Security chapter is for GPAI models subject to Article 55 systemic-risk obligations.

## What downstream information should be ready?

The downstream package should let AI-system providers understand capabilities and limitations and meet their own AI Act duties. Annex XII requires more than marketing claims: it points to tasks, integration types, acceptable-use policies, release and distribution details, external hardware or software interactions, relevant software versions, architecture and parameters, input and output modality and format, licence, integration means, input and output limits, and training, testing, and validation data information where applicable.

The Transparency chapter of the GPAI Code of Practice adds a practical access pattern for signatories: disclose contact information for the AI Office and downstream providers, provide the most up-to-date model documentation intended for downstream providers, and provide necessary additional information within a reasonable timeframe, no later than 14 days after receiving the request except in exceptional circumstances.

- Keep a downstream-provider version of the model documentation separate from authority-only material and trade-secret material.
- Publish or otherwise provide a clear request channel for downstream providers that need Article 53 information.
- Map each downstream field to a source system: model registry, release notes, training-data governance, licence repository, acceptable-use policy, evaluation reports, or security review.
- Version the downstream package with the model release so integrators can prove which information they relied on.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Annex XII lists the minimum downstream transparency information for providers integrating GPAI models into AI systems.
- [GPAI Code of Practice - Transparency Chapter](https://ec.europa.eu/newsroom/dae/redirection/document/118120?ref=sorena.io) - Transparency chapter describing model documentation, downstream-provider information, and request handling for signatories.

## Code of Practice caveats

The GPAI Code of Practice is voluntary. The Commission and AI Board have confirmed it as an adequate voluntary tool for GPAI model providers to demonstrate AI Act compliance, but Article 53 and Article 55 still allow other routes: harmonised standards grant presumption of conformity where they cover the obligations, and providers that do not adhere to an approved code or harmonised standard must demonstrate alternative adequate means of compliance for Commission assessment.

The Code should not be treated as a copyright safe harbour. Its Copyright chapter states that adherence to the Code does not constitute compliance with Union copyright law and does not affect copyright enforcement by Member State courts or the Court of Justice of the European Union.

- Use the Transparency and Copyright chapters for Article 53 only if the provider signs and implements the relevant commitments.
- Use the Safety and Security chapter only for GPAI models with systemic risk under Article 55 or when voluntarily applying equivalent controls.
- Keep evidence of Code signature, implemented commitments, model documentation, copyright-policy measures, safety and security controls, and any alternative adequate means used instead.
- When relying on a Code chapter, still retain the legal mapping to Article 53 or Article 55 because the Code is a means of demonstrating compliance, not the obligation itself.

**Does the EU AI Act still use the term foundation model for these obligations?**

No. The enforceable AI Act term for this page is general-purpose AI model. Foundation model may describe the same search intent in market language, but Article 53, Article 55, Annex XI, and Annex XII use general-purpose AI model.

**What are the minimum Article 53 duties for a GPAI model provider?**

Article 53 requires up-to-date model technical documentation, information for downstream AI-system providers, a Union copyright-law policy, a public training-content summary using the AI Office template, and cooperation with the Commission and national competent authorities.

**When do Article 55 GPAI systemic-risk duties apply?**

Article 55 applies when a GPAI model is classified as having systemic risk under Article 51 and Article 52. The provider then has extra duties for model evaluation, adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity protection.

Sources for this answer:

- [European Commission - GPAI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai?ref=sorena.io) - Commission page identifying the Code as a voluntary tool and distinguishing the Transparency, Copyright, and Safety and Security chapters.
- [GPAI Code of Practice - Copyright Chapter](https://ec.europa.eu/newsroom/dae/redirection/document/118115?ref=sorena.io) - Copyright chapter caveat that Code adherence does not itself constitute compliance with Union copyright law.
- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Articles 53 and 55 explain use of codes of practice, harmonised standards, and alternative adequate means of compliance.

*Recommended next step*

*Placement: before sources*

## This guide helps structure Article 53 and Article 55 evidence

Sorena can help convert GPAI model facts into an Article 53 documentation pack, downstream-provider information, copyright-policy evidence, public training-summary support, and systemic-risk controls where Article 55 applies.

- [Open Research Copilot for EU AI Act](/solutions/research-copilot.md): Ask questions tied to cited sources about GPAI model provider duties, systemic risk, documentation, copyright policy, and public training-content summaries.
- [Talk through implementation](/contact.md): Review whether your model evidence pack covers Article 53 baseline duties and Article 55 systemic-risk duties.

## Primary sources

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj?ref=sorena.io) - Primary legal text for GPAI model definitions, Article 53 baseline duties, Article 55 systemic-risk duties, Annex XI, Annex XII, and systemic-risk classification.
  - Quote: "general-purpose AI model"
- [European Commission - GPAI provider guidelines](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) - Commission guidance page for interpreting the scope of GPAI model provider obligations, significant modifications, open-source conditions, application dates, and EU SEND submissions.
  - Quote: "scope of obligations"
- [European Commission - GPAI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai?ref=sorena.io) - Commission page describing the voluntary GPAI Code of Practice and its Transparency, Copyright, and Safety and Security chapters.
  - Quote: "voluntary tool"
- [GPAI Code of Practice - Transparency Chapter](https://ec.europa.eu/newsroom/dae/redirection/document/118120?ref=sorena.io) - Transparency chapter support for model documentation, downstream-provider information, request channels, and information quality controls.
  - Quote: "model documentation"
- [GPAI Code of Practice - Copyright Chapter](https://ec.europa.eu/newsroom/dae/redirection/document/118115?ref=sorena.io) - Copyright chapter support for maintaining a Union copyright-policy document and respecting rights reservations, with the caveat that Code adherence is not copyright-law compliance by itself.
  - Quote: "copyright policy"
- [European Commission - Public Summary of Training Content template](https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models?ref=sorena.io) - Commission explanatory notice and template for the Article 53(1)(d) public summary of GPAI model training content.
  - Quote: "summary of training content"
- [European Commission - Serious incident template for GPAI models](https://digital-strategy.ec.europa.eu/en/library/ai-act-commission-publishes-reporting-template-serious-incidents-involving-general-purpose-ai?ref=sorena.io) - Commission reporting-template page for serious incidents involving GPAI models with systemic risk.
  - Quote: "serious incidents"

## Related Topic Guides

- [Are industry AI use cases high-risk under EU AI Act Annex III?](/artifacts/eu/artificial-intelligence-act/faq/annex-iii-industry-use-cases.md): FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
- [EU AI Act AI System Classification Edge Cases FAQ](/artifacts/eu/artificial-intelligence-act/faq/ai-system-classification-edge-cases.md): Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
- [EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence](/artifacts/eu/artificial-intelligence-act/applicability-and-roles.md): Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
- [EU AI Act applicability test: scope, role, and risk classification](/artifacts/eu/artificial-intelligence-act/applicability-test.md): Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
- [EU AI Act Article 5 Prohibited AI Practices Screening Guide](/artifacts/eu/artificial-intelligence-act/prohibited-ai-practices.md): Screen AI systems against the EU AI Act Article 5 prohibitions, including manipulation, exploitation, social scoring, biometric and law-enforcement exceptions.
- [EU AI Act Article 50 transparency disclosures FAQ](/artifacts/eu/artificial-intelligence-act/faq/article-50-transparency-disclosures.md): Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
- [EU AI Act Article 50 transparency, labeling, and user disclosures](/artifacts/eu/artificial-intelligence-act/transparency-labeling-and-user-disclosures.md): Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
- [EU AI Act Article 73 serious incident FAQ](/artifacts/eu/artificial-intelligence-act/faq/serious-incidents.md): FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
- [EU AI Act Compliance Checklist by Risk Class](/artifacts/eu/artificial-intelligence-act/checklist.md): A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
- [EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents](/artifacts/eu/artificial-intelligence-act/compliance.md): Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
- [EU AI Act conformity assessment and notified bodies for high-risk AI](/artifacts/eu/artificial-intelligence-act/conformity-assessment-and-notified-bodies.md): Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
- [EU AI Act deadlines and compliance calendar | Article 113 dates](/artifacts/eu/artificial-intelligence-act/deadlines-and-compliance-calendar.md): EU AI Act compliance calendar for Article 113 staged application dates, Article 111 transitions, GPAI, prohibited practices, AI literacy, and high-risk AI planning.
- [EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates](/artifacts/eu/artificial-intelligence-act/faq.md): Source-backed EU AI Act FAQ covering scope, provider and deployer roles, prohibited practices, high-risk classification, GPAI duties, transparency notices, FRIAs, EU database registration, serious incidents, and staged application dates.
- [EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification](/artifacts/eu/artificial-intelligence-act/faq/fria.md): Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
- [EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence](/artifacts/eu/artificial-intelligence-act/fria-and-high-risk-impact-assessments.md): Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
- [EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ](/artifacts/eu/artificial-intelligence-act/faq/gpai-and-systemic-risk-duties.md): FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
- [EU AI Act GPAI evidence pack checklist for Article 53 and 55](/artifacts/eu/artificial-intelligence-act/gpai-evidence-pack-workflow.md): Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
- [EU AI Act High-Risk AI Requirements: Articles 8-16 and 26](/artifacts/eu/artificial-intelligence-act/requirements.md): Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
- [EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide](/artifacts/eu/artificial-intelligence-act/high-risk-ai-use-cases-by-industry.md): Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
- [EU AI Act high-risk conformity assessment route selector](/artifacts/eu/artificial-intelligence-act/high-risk-conformity-route-selector-workflow.md): Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
- [EU AI Act high-risk requirements checklist: Articles 8-15](/artifacts/eu/artificial-intelligence-act/high-risk-requirements-checklist.md): Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
- [EU AI Act penalties and fines: Article 99 tiers and GPAI exposure](/artifacts/eu/artificial-intelligence-act/penalties-and-fines.md): EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
- [EU AI Act post-market monitoring and serious incident reporting](/artifacts/eu/artificial-intelligence-act/post-market-monitoring-and-serious-incidents.md): Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
- [EU AI Act post-market monitoring FAQ for high-risk AI systems](/artifacts/eu/artificial-intelligence-act/faq/post-market-monitoring.md): Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
- [EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ](/artifacts/eu/artificial-intelligence-act/faq/provider-and-deployer-role-boundaries.md): FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
- [EU AI Act risk classification intake workflow](/artifacts/eu/artificial-intelligence-act/risk-classification-intake-workflow.md): A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
- [EU AI Act serious incident reporting triage workflow: Article 73 and Article 55](/artifacts/eu/artificial-intelligence-act/serious-incident-reporting-triage-workflow.md): Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
- [EU AI Act Technical Documentation and Provider Evidence Templates](/artifacts/eu/artificial-intelligence-act/technical-documentation-and-provider-evidence-templates.md): Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
- [EU AI Act technical documentation FAQ | Article 11 and Annex IV](/artifacts/eu/artificial-intelligence-act/faq/technical-documentation.md): What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
- [EU AI Act Timeline and Phasing Roadmap: practical obligations and evidence guide](/artifacts/eu/artificial-intelligence-act/timeline-and-phasing-roadmap.md): Practical EU AI Act guide to Timeline and Phasing Roadmap: scope, owners, evidence, edge cases, checklist steps, and external citations.
- [EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits](/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-iso-42001.md): Compare the EU AI Act and ISO/IEC 42001 across legal status, risk classification, high-risk AI, GPAI, transparency, conformity, evidence, and assurance limits.
- [EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries](/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-nist-ai-rmf.md): Compare the binding EU AI Act with the voluntary NIST AI RMF, including role classification, high-risk duties, GPAI, transparency, conformity evidence, and reuse limits.
- [FAQ: EU AI Act conformity assessment procedures and notified body selection](/artifacts/eu/artificial-intelligence-act/faq/conformity-assessment-and-notified-bodies.md): cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/artificial-intelligence-act/gpai-and-foundation-model-obligations
