GPAI obligations under the EU AI Act: what changes in August 2026

Professional facing an AI brain among legal documents and EU stars, representing GPAI obligations under the EU AI Act

August 2026 is one of those dates I have long marked in red in regulated projects. The EU AI Act timeline advances in phases, and this milestone activates the GPAI obligations, the specific requirements for general-purpose models that many organisations have not yet prepared for. It is worth reviewing what comes into force and, above all, what to do if you are behind.

The EU AI Act’s staggered timeline

The regulation does not apply all at once, but in tranches. After the general entry into force and the initial prohibitions, August 2026 marks the activation of relevant obligations, especially around general-purpose models and governance. Knowing where you are on the timeline is the first step to not arriving late, something I detail in my EU AI Act compliance checklist.

Which GPAI obligations activate in August 2026

General-purpose models (GPAI)

The GPAI obligations fall on the providers of general-purpose models, who face duties of transparency, technical documentation and, for models with systemic risk, additional requirements. If your company integrates these models, it is wise to demand from providers the documentation that the EU AI Act now obliges them to supply.

Governance and authorities

The European and national governance structure is consolidated, with the authorities that will supervise compliance. This means the regulation is no longer theory: there start to be those who watch and those who penalise.

What to do if you are behind

The first thing is not to panic or try to comply with everything at once. I always prioritise by risk: identifying the most exposed systems and ensuring their compliance before the peripheral ones. Having a good AI asset inventory is what enables that intelligent prioritisation.

Then, document. Much of EU AI Act compliance consists of being able to demonstrate what you do: assessments, controls and decisions. Without documentation, even if you do things well, you will not be able to prove it to an authority.

What GPAI models are exactly

Before talking about obligations it is worth clarifying the concept. A general-purpose model, or GPAI, is an AI model trained on large volumes of data and capable of performing very diverse tasks, from writing text to generating code or images. It is not designed for a single use, but serves as a base on which other companies build their applications. The large language models we use daily today are the clearest example. That versatility is precisely what has led the European legislator to focus on them: when a single model underpins thousands of applications, a fault or a bias spreads on a large scale.

That is why the GPAI obligations distinguish between ordinary models and those with systemic risk, which exceed certain capability thresholds. More is required of the latter: safety assessments, adversarial testing and notification of serious incidents. Understanding which category the model you use falls into is the first step to knowing what applies to you as a company that integrates it.

What your company must do if it integrates a GPAI

Although the obligations fall on the model providers, the companies that integrate them are not off the hook. My recommendation is to demand from your provider the technical documentation the regulation now obliges them to deliver, check what data they used for training and put in writing who is accountable if the model fails. That due diligence protects you and saves you surprises in an audit. It is also wise to train your team, because much of the risk appears in everyday use; I develop this in my article on the mandatory AI literacy of Article 4.

In regulated projects I always add one more layer: tracing which decisions the model makes and being able to explain them. The transparency the regulation demands of providers is only truly useful if you, as an integrator, carry it into your own processes. There is little point in having the model’s technical sheet if then no one in your organisation knows how to interpret it.

One more piece of the regulatory timeline

The GPAI obligations are not an isolated milestone, but a piece within a broader timeline that will keep unfolding over the coming years. Seeing them in context helps you not to experience each date as a separate emergency. That overall view, of what the rollout of AI regulation has taught us, is what I gather in my review of the year in AI regulation, where I order the milestones and the lessons learned.

My final advice is not to wait for the deadline to prepare the documentation. Companies that arrive with their homework done not only avoid penalties: they negotiate better with their providers and convey seriousness to their clients. Meeting the GPAI obligations, well approached, is a competitive advantage rather than a burden.

Conclusion: the regulation is now real

August 2026 confirms something I have been repeating for a long time: the EU AI Act is not a distant future, it is a present with deadlines. The organisations that built it into the design of their projects arrive calm; those that left it for later, running. My advice is clear: get up to date now, because the dates do not wait.

Frequently asked questions about the EU AI Act in August 2026

What comes into force under the EU AI Act in August 2026?

Relevant obligations activate, especially those relating to general-purpose models (GPAI) and the consolidation of the European and national governance structure that will supervise compliance.

What obligations do GPAI models have?

Transparency, technical documentation and, for models with systemic risk, additional requirements. Companies that integrate these models must demand from their providers the documentation the regulation now obliges them to supply.

What do I do if I am behind on the EU AI Act?

Prioritise by risk: identify the most exposed systems and ensure their compliance first, relying on a good AI asset inventory, and document everything so you can prove it to the authorities.

Can the EU AI Act now be enforced with penalties?

With the consolidation of the supervisory authorities, the regulation stops being theory and there start to be those who watch and those who penalise, so documented compliance becomes essential.

Are you taking AI from pilot to real work? Let us talk.

Book 20 minutes

Leave a Reply

Your email address will not be published. Required fields are marked *