Article 53 · Enforceable since 2 Aug 2026

GPAI and Article 53

Most companies building on foundation models owe nothing here — and should stop worrying about it. A minority became model providers without noticing.

Last updated 7 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

If you build on GPT, Claude, Gemini, Llama or Mistral, there is one question worth answering properly: did you do enough to the model to become its provider?

For most companies the answer is no, comfortably, and it is worth knowing that because the fear is doing real damage — teams are budgeting for obligations they do not have. For a minority the answer is yes, and they usually have no idea, because the thing that triggered it was an engineering decision made months before anyone thought about regulation.

Where you almost certainly sit

What you didYour positionArticle 53 duties?
Call the model through an APIDownstream deployerNo
Prompt engineering, system prompts, RAG over your own dataDownstream deployerNo
Light fine-tune, same domain, modest datasetDownstream, ordinarilyGenerally no
Substantial retrain, major parameter changes, or a new task domainPossible GPAI providerLikely yes
Trained your own general-purpose modelGPAI providerYes
Rule-based system, no learned modelNot an AI system at allNo

Say this out loud to your team if it applies: "We call an API. Article 53 is Anthropic's problem, or OpenAI's, not ours." It removes a fear that is currently costing small companies planning time and consultancy fees. Retrieval-augmented generation does not change it. Neither does a long system prompt, however clever.

Where the line actually sits

The Act does not publish a compute threshold below which fine-tuning is safe, which is unhelpful but not unusual. What it does is attach provider status to whoever places a general-purpose model on the market, and treat a party who modifies a model substantially as having done so for the modified version.

In practice, four factors decide it. None is individually conclusive; together they are.

1. Scale of the modification

A few hundred examples of LoRA fine-tuning to fix tone is not a new model. Continued pre-training on billions of tokens is. The greater the compute and data relative to the original training run, the more you look like a provider.

2. Whether the parameters materially changed

Adapter layers that leave base weights untouched sit at one end. Full-parameter retraining sits at the other.

3. Whether the task domain changed

This is the factor people underweight. Fine-tuning a general model to be better at your existing domain is refinement. Taking a general model and turning it into something that does a materially different job — a code model into a clinical summariser — looks much more like creating a new model.

4. Whether it is still general-purpose

Article 53 is about general-purpose AI models — models displaying significant generality, capable of competently performing a wide range of distinct tasks. If you have narrowed a general model into a single-purpose tool, you may have moved out of GPAI territory even though you modified heavily. You may then be the provider of an AI system, which is a different question with different duties.

The honest position: the middle of this range is genuinely unsettled, and anyone telling you there is a bright line is overselling. If you are near it, this is one of the few places where an hour of specialist legal time is worth buying — the obligations on the other side are substantial enough to justify it.

What Article 53 actually requires

If you are a GPAI provider, four obligations. Applied from 2 August 2025, enforceable since 2 August 2026.

ObligationWhat it means
Technical documentation (Annex XI)Training process, evaluation results, intended tasks, architecture, energy consumption. Kept current and available to the AI Office on request.
Downstream information (Annex XII)Documentation enabling companies building on your model to understand its capabilities and limitations well enough to meet their own duties.
Copyright policyA policy to comply with EU copyright law, including honouring text-and-data-mining reservations under Article 4(3) of the DSM Directive.
Training-data summaryA sufficiently detailed public summary of the content used for training, following the AI Office template.

Two further points. Providers of models released under a free and open-source licence, with weights and architecture publicly available, are exempted from the first two — but not from the copyright policy or the training-data summary, and not at all if the model presents systemic risk. And models above the systemic-risk threshold carry additional Article 55 duties: model evaluation, adversarial testing, incident reporting and cybersecurity. If you are reading this page to work out your position, you are not training a systemic-risk model.

The group most exposed

Not the labs — they have compliance teams. It is companies who did a serious fine-tune in 2024 or 2025 for performance reasons, when no regulatory consideration attached to that decision, and have not revisited it since.

A recognisable example: a team takes an open-weights model, continues pre-training on a large proprietary corpus to specialise it, and ships it inside their product. Eighteen months later that was a substantial modification, they are arguably a GPAI provider, the obligations are enforceable, and nobody in the company has ever read Article 53 because they think of themselves as a SaaS company rather than a model provider.

If that shape is familiar, the training-data summary is the obligation to look at first. It is public, so its absence is the most visible.

Two things this is not

Not the same as your risk tier. Article 53 is about being a model provider. Whether your system is high-risk, limited-risk or minimal is a separate question answered through Annex III and Article 6(3). You can be a GPAI provider whose system is minimal risk, or a downstream deployer whose system is high-risk. They do not track each other.

Not the same as being an AI system provider. Under Article 25 you can become the provider of an AI system by putting your name on it or changing its intended purpose — without touching any model weights. Different route, different obligation set. Both can apply at once.

Four questions to settle it

  1. Did you modify model weights at all? No → you are downstream. Done.
  2. If yes, how much? Adapters and small in-domain datasets sit safely downstream. Full retraining on a large corpus does not.
  3. Did the task domain change? Pushing a model into a materially different job weighs heavily toward provider status.
  4. Is the result still general-purpose? If you narrowed it to one task, GPAI duties may not apply — but check whether you are now the provider of an AI system instead.

Write the answers down with your reasoning and date them. If you land near the line, that document is what makes the next conversation — with a lawyer, an acquirer, or an enterprise customer's legal team — a short one.

Check whether Article 53 reaches you

The full assessment asks what you did to the model, and tells you plainly when the answer is nothing — which removes a duty most teams assume they have.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.