We use cookies to improve your experience and analyse site traffic.
Whether you're training foundation models or shipping AI-enabled software, the EU AI Act creates specific obligations for providers placing AI systems on the EU market. Articles 51-56 establish the GPAI regime. The broader AI system requirements apply to every ISV releasing AI-powered products to European customers. The question isn't whether these obligations apply — it's whether you're ready to evidence compliance when the market surveillance authority asks.
GPAI Obligations
Six core obligations for providers of general-purpose AI models placed on the EU market — regardless of where the provider is headquartered.
Systemic Risk
GPAI models with systemic risk face additional obligations — adversarial testing, incident reporting, and enhanced cybersecurity.
For ISVs
You don't need to be training foundation models to have GPAI obligations. Every ISV releasing AI-powered software to European customers is a provider under the AI Act.
Copyright & Data Rights
Copyright law and GDPR create overlapping obligations for training data — from text and data mining rights to data subject access requests.
| Regulation | Reference | Obligation |
|---|---|---|
| Text & Data Mining Directive | Art. 3 & 4 TDM | Lawful access to copyrighted works for TDM purposes. Respect opt-out mechanisms for commercial TDM (Art. 4). Scientific research exemption under Art. 3. |
| GDPR — Lawful Basis | Art. 6 GDPR | Every piece of personal data in training sets requires a lawful basis. Legitimate interest (Art. 6(1)(f)) is common but requires a documented balancing test. |
| GDPR — Data Subject Rights | Art. 15-22 GDPR | Data subjects whose personal data was used in training retain their rights — including access, rectification, erasure, and objection to processing. Technical measures may be required to honour these rights for data embedded in model weights. |
| Database Directive | Directive 96/9/EC | Extraction and re-utilisation of substantial parts of databases for model training may infringe the sui generis database right. Licensing and provenance documentation is essential. |