Skip to content
Tuesday, September 1, 2026
Honey Badgers AIStartup News · Company Reviews
Home / Tech News
Tech News

EU AI Act GPAI Obligations: What Startups Must Track

The AI Act's general-purpose AI rules took effect August 2, 2025 — and the obligations that matter to startups are documentation, transparency, and where liability flows down the chain.

Owen Blackwood, · May 11, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Infographic timeline of AI Act compliance dates by risk tier
AI-generated photorealistic reconstruction — not a documentary photograph.

The European Union's AI Act, adopted in 2024, phased into force across 2025-2027, and its obligations for general-purpose AI models — the GPAI provisions — applied from August 2, 2025. The law's structure matters more to startups than its headlines: most startups are not regulated as model providers at all, but nearly every AI startup selling into Europe inherits obligations through the supply chain. This is an explanatory map of the documented regulation; it is not legal advice. Honey Badgers publishes information, not professional advice.

What does the AI Act actually regulate?

The Act sorts AI by risk. Prohibited practices — social scoring, manipulative techniques, some biometric uses — banned from February 2025. High-risk systems — employment, credit, education, critical infrastructure, law enforcement — face the heaviest obligations, phased from 2026-2027: risk management, data governance, human oversight, logging, and conformity assessment. GPAI models — the general-purpose systems like frontier language models — carry their own obligations from August 2, 2025: technical documentation, copyright-compliance policies, and training-content summaries, with additional duties for models trained above a compute threshold presumed to pose systemic risk. Transparency rules — labeling synthetic content, disclosing AI interaction — apply broadly from August 2026.

Who do the GPAI obligations actually bind?

The provider of the model — typically the lab or the company that puts the model on the EU market under its own name. A startup fine-tuning an open-weights model for its own product generally is not a GPAI provider; the market practice through 2025 was that fine-tuning does not reassign provider status unless the fine-tuner markets the model itself as general-purpose. But two documented flows pull obligations down the chain: deployers of high-risk systems — a startup whose AI screens job applicants or prices credit inside the EU — carry their own obligations regardless of who built the model; and downstream contracts increasingly pass through provider requirements by agreement, since model providers must ensure their outputs are used in compliance and request information from deployers to do so.

What are the concrete obligations with dates?

The startup-relevant calendar. From August 2, 2025: GPAI providers must publish training-content summaries sufficient for rights holders to enforce copyrights, maintain technical documentation, and — for systemic-risk models — report serious incidents, evaluate and mitigate systemic risks, and maintain cybersecurity. From August 2, 2026: transparency obligations bite deployers — AI-generated content must be labeled, chatbots must disclose they are not human, and synthetic media must be machine-detectable where feasible. From August 2, 2026 into 2027: the high-risk regime's full requirements phase in by category. Enforcement: national authorities with fines up to 7 percent of worldwide turnover for prohibited practices and 3 percent for other violations, though the first enforcement cycle's real risk for startups is product-blocking noncompliance rather than maximal fines.

What did the implementation debates actually settle?

The Code of Practice for GPAI providers, finalized in 2025 after heavy lobbying from both directions, set the compliance template for documentation and copyright summaries — and the documented fault lines: the compute threshold (10^25 FLOPs) that triggers systemic-risk duties, contested as arbitrary by some labs and too low by safety advocates; open-weights treatment, where the released code settled on lighter duties for openly licensed models; and the standardization question of what a 'training-content summary' sufficient for rights holders means in practice — the first test cases of which arrived with rights holders' complaints in late 2025 and early 2026. None of these is settled law; all of them are live.

What should a startup selling into Europe actually do?

Four practical tracks from the documented compliance practice. Classification: inventory your products against the risk tiers — if you touch hiring, credit, education, or biometrics, you are in the high-risk regime's calendar and should be building its documentation now. Contract flow-down: your model providers' terms now demand compliance cooperation — read them; the information requests are mutual and documented noncompliance can cut off model access. Transparency build: synthetic-content labeling is cheap to implement before August 2026 and expensive to retrofit into product surfaces afterward. And documentation hygiene: the GPAI experience's general lesson is that the Act's obligations are overwhelmingly documentation obligations — the startups struggling in the first cycle are those that treated compliance as a legal memo rather than a product requirement with a calendar.

The AI Act is the world's broadest AI regulation and Europe's bet that compliance cost buys market trust. For startups, the record's practical summary: the law reaches you through your product's function and your contracts, not your location — and its calendar is public, which makes every deadline a planning fact rather than a surprise.

Frequently Asked Questions

When did the EU AI Act's GPAI rules start applying?
August 2, 2025. Providers of general-purpose AI models must maintain technical documentation, publish training-content summaries for copyright enforcement, and — above the compute threshold for systemic risk — evaluate and mitigate systemic risks and report serious incidents.
Does the AI Act apply to startups outside the EU?
Yes, extraterritorially: placing an AI system on the EU market or whose output is used in the EU brings obligations regardless of the provider's location. Reach is determined by product function and market, not headquarters.
Is a startup fine-tuning an open model a GPAI provider?
Generally not: fine-tuning for a specific product does not make you the model's provider unless you market the model itself as general-purpose. Deployers of high-risk systems carry their own separate obligations.
What are the AI Act's fines?
Up to 7 percent of worldwide turnover for prohibited practices, 3 percent for other violations, or fixed amounts — mirroring GDPR's structure. For startups the operative early risk is noncompliance blocking products, not maximal fines.

Sources

  1. European Commission artificial intelligence policy pages