General-Purpose AI (GPAI)
General-Purpose AI (GPAI) refers to AI models trained on broad data at scale and capable of performing a wide range of distinct tasks, a category defined and regulated specifically under the EU AI Act.
How GPAI Is Defined
The EU AI Act defines a GPAI model as an AI model displaying significant generality and capable of competently performing a wide range of distinct tasks, regardless of how it is placed on the market. In practice, this captures most commercially available foundation models, including LLMs, image generators, and multimodal systems.
GPAI is a category of models, not systems. A model becomes a GPAI system when integrated into a specific application. The obligations attach at both levels.
What Obligations Apply to GPAI
Providers of GPAI models face obligations from August 2, 2025, including technical documentation, information provision to downstream deployers, copyright policy compliance, and publication of a training data summary. Additional obligations apply to GPAI models classified as posing systemic risk.
Why GPAI Matters for Enterprises
Most enterprises are not GPAI providers, but they are GPAI deployers. That means they inherit downstream obligations, including verifying provider compliance, using models within provider-documented capabilities, and integrating GPAI documentation into their own AI governance work.
See EU AI Act compliance explained for CISOs and GRC leaders.
Related Terms
Full AI Visibility. Full Control. One Connected Platform.
Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.


