EU AI Act GPAI Rules: What Changed in August 2026
Quick answer: The EU AI Act's general-purpose AI (GPAI) rules have applied to model providers since 2 August 2025. What changed on 2 August 2026 is enforcement: the Commission can now fine a GPAI provider up to 3% of worldwide annual turnover or €15 million, whichever is higher. All GPAI providers owe technical documentation, downstream information, a copyright policy and a public training-data summary, with extra evaluation and cybersecurity duties for systemic-risk models; models placed on the market before 2 August 2025 have until 2 August 2027 to comply fully. The trap for Luxembourg companies building on GPT, Claude, Gemini, Mistral or Llama is role classification — wrap a model under your own brand or substantially modify it and you become a provider, not a deployer. Four actions: build a model inventory, classify your role per system, collect the upstream documentation, and get your Article 50 disclosures in place, because those are due now.
Last verified 7 August 2026.
Most of the Luxembourg AI Act conversation has been about high-risk systems and the literacy obligation. We covered both — the high-risk roadmap and the Article 4 literacy duty. But there is a third payload that almost every Luxembourg company touches and almost none has mapped: the general-purpose AI rules. If you build anything on top of GPT, Claude, Gemini, Mistral or Llama — and that is most of you — this one is yours.
The three dates that actually matter here
- 2 August 2025 — GPAI obligations (Chapter V) became applicable to model providers.
- 2 August 2026 — the Commission's power to impose fines on GPAI providers became exercisable, at up to 3% of worldwide turnover or €15 million. Separately, and far more relevant to you: the Article 50 transparency duties took effect the same day.
- 2 August 2027 — the compliance deadline for GPAI models that were already on the market before 2 August 2025.
And one date that moved: the high-risk regime for stand-alone Annex III systems slipped from 2 August 2026 to 2 December 2027 under Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026. The GPAI chapter was not deferred. See what actually applies now for the full corrected timeline.
If GPAI classification is keeping your compliance file open, book a free 30-minute call and we'll walk your specific case through the rules.
What GPAI actually means
A general-purpose AI model is a foundation model that can do many things and be adapted into many systems — the large language and multimodal models everyone is building on. The AI Act treats the model as a regulated object in its own right, separate from any specific application built on it. That is the conceptual shift most companies working on AI implementation in Luxembourg have not internalised: there are obligations attached to the model layer, not only to your use case.
The Act splits GPAI into two tiers:
- All GPAI models: baseline transparency obligations on the model provider — technical documentation, information for downstream integrators, a copyright policy, and a public summary of training-data content.
- GPAI with systemic risk: the largest, highest-capability models carry an additional layer — model evaluation, adversarial testing, serious-incident tracking, and cybersecurity obligations.
The relevant question for a Luxembourg SME or mid-cap is rarely "do I train a foundation model?" — almost none do. It is "what does this make me responsible for as the company that builds on one?" That is where the real trap is.
The provider-vs-deployer trap
This is the single most-confused point in every AI Act conversation we have in a Luxembourg client room, and it is the one that decides who owns which obligation.
- A provider develops an AI system (or GPAI model) or has one developed and places it on the market or puts it into service under its own name or brand.
- A deployer uses an AI system under its own authority in the course of a professional activity.
Most Luxembourg companies assume they are deployers — they are "just using" an API. That assumption is often wrong. The moment you take a foundation model, wrap it, give it your own name, and put it in front of customers or substantially modify how it behaves, you can become a provider of an AI system in the Act's sense — with the heavier obligation set that goes with it. The label is not a formality; it determines your documentation, transparency and, for some use cases, conformity duties.
A short, honest test for which side of the line you are on:
- Are you reselling or rebranding an AI system under your own name? That pulls you toward provider.
- Are you substantially modifying the system or repurposing it for a use the original provider didn't intend? Same direction.
- Are you building a downstream system on a GPAI model and putting it on the market? You likely have provider-side obligations for that system, even though you didn't build the model.
- Are you genuinely just using a tool internally, as delivered, for its intended purpose? That is the cleaner deployer position.
Most Luxembourg companies sit on point 3 and have been planning as if they were on point 4. The fix is not panic — it is mapping it before August, not after.
What this means concretely for a Luxembourg company
Translate the legal text into four actions:
1. Build a model inventory
List every GPAI model in production use across the company — the obvious API integrations and the shadow ones (a team using a consumer chatbot for client work is in scope). You cannot manage obligations on an inventory you do not have. This is the same governance backbone the high-risk roadmap needs, so build it once and reuse it.
2. Classify your role per system
For each AI system you operate, decide — and document — whether you are provider or deployer for that system. Not company-wide; per system. You can be a deployer of one tool and a provider of another in the same week. This document is the artefact a regulator or a customer's due-diligence team will ask for first.
3. Collect the upstream documentation
As a downstream builder you are entitled to specific technical information from the model provider. Collect it now and store it with the inventory: it is both your compliance evidence and exactly what your own customers will demand in their vendor due diligence. The major providers (OpenAI, Anthropic, Google, Mistral) publish this; the work is collecting and version-tracking it, not chasing it.
4. Set transparency where users interact with AI — this one is legally due
This stopped being good practice on 2 August 2026. Article 50 requires providers to design systems that interact directly with people so the person is informed they are dealing with an AI, and to mark generative outputs in a machine-readable format (with a grace period to 2 December 2026 for systems already on the market). Deployers must disclose deepfakes, disclose AI-generated public-interest text absent documented human editorial responsibility, and inform people exposed to emotion recognition or biometric categorisation.
For most Luxembourg companies the human-facing part is a small, cheap UI and policy change — in FR, DE and EN. The machine-readable marking is engineering, and it has a real December date. Breaches sit in the €15 million / 3% band, with SMEs facing the lower of the two under Article 99(6). Do it deliberately rather than discover it in an audit.
Rather resolve this in one conversation? Book a free 30-minute call — bring your use case and we'll walk it through together, in plain language.
How this chains with the rest of your AI Act work
GPAI is not a separate project. The model inventory feeds the high-risk classification; the provider/deployer mapping feeds your CSSF outsourcing file if you are supervised (the DORA + AI Act overlap); the literacy obligation makes the whole thing operable because staff who do not understand the provider/deployer distinction will misclassify systems. Companies treating these as one governance workstream finish before August. Companies treating them as four separate fire drills do not. Your model choice also interacts with this — the trade-offs are in our best AI model for Luxembourg business comparison, because different providers ship different downstream documentation.
Vous dirigez une PME luxembourgeoise ?
Réservez un audit IA gratuit de 30 minutes — nous vous dirons honnêtement où l’IA est rentable pour vous, et où elle ne l’est pas.
Réserver un audit IA gratuitThe honest timeline
The inventory, the role classification, the documentation collection and the transparency changes are a focused two-to-three-week effort for a typical Luxembourg SME or mid-cap — not a quarter. What takes longer is the remediation the classification surfaces: the provider/deployer test regularly turns up a system nobody realised the company was the provider of, and fixing that means product changes, not policy changes.
Which is why the sequencing now matters more than it did in the spring. Article 50 is live and visible from the outside — an undisclosed chatbot is something a regulator, a competitor or a customer can see without opening a single file. The high-risk regime is not due until December 2027 but takes twelve to eighteen months. Doing the classification once, now, serves both.
Map it once, and get the artefact you can hand to anyone
The 20 More AI Act Readiness Assessment folds the GPAI mapping into the same governance file as the high-risk and literacy work, so you end with one defensible artefact instead of four half-finished ones. Ten working days:
- The model and system inventory — every GPAI integration in production, including the shadow ones, and every AI feature inside tools you already bought.
- The per-system role determination — provider or deployer for each, evidenced against the Article 3 and Article 25 tests, dated and signed. This is the document a regulator or a customer's due-diligence team asks for first.
- The upstream documentation pack — the technical information and integration documentation you are entitled to receive from each model provider, collected and version-tracked, so it is ready when a client's procurement team asks for it rather than three weeks after.
- The Article 50 gap report — the disclosures legally due today, mapped to the exact surfaces missing them, with the 2 December 2026 machine-readable-marking items scheduled as engineering work.
You bring your real integrations. You leave with a per-system classification and a prioritised action list against real dates — not the ones the trade press is still repeating.
→ See the AI Act readiness service, or book the 30-minute scoping call.
Related reading:
- Is your AI high-risk? The new 2 December 2027 deadline
- EU AI Act August 2026: what actually applies now
- EU AI Act Article 4: the AI literacy obligation in Luxembourg
- DORA + EU AI Act: Luxembourg financial compliance in 2026
- Best AI model for business in Luxembourg — 2026 comparison
- EU sovereign cloud vs. hyperscalers vs. on-prem AI: Luxembourg 2026
- AI Knowledge Hub — 20 More Resources
Votre projet IA est-il éligible à 70 % de financement au Luxembourg ?
Jusqu’à 17 500 € par projet. Estimation immédiate — 4 questions rapides, sans e-mail.
Prêt à passer à la pratique ?
Deux façons de commencer — choisissez celle qui vous convient.
Ressources associées
L'implémentation de l'IA au Luxembourg
Découvrez notre guide complet sur l'adoption, l'implémentation et la gouvernance de l'IA au Luxembourg.
Lire le guideTravailler avec un consultant IA au Luxembourg
Découvrez ce que nous construisons, les tarifs, et comment vos projets peuvent obtenir jusqu'à 70 % de cofinancement PME.
Consultant IA au LuxembourgRelated Posts
EU AI Act August 2026: What Actually Applies Now
The August 2026 deadline changed. Article 50 transparency applies now; high-risk slipped to 2 December 2027. What Luxembourg firms owe today — and by when.
EU AI Act: Provider or Deployer? The 5-Minute Test
Deployer or provider under the EU AI Act? That one label sets your whole compliance burden — and the deadlines just moved. Four questions, four SME traps.
EU AI Act Article 4: The AI Literacy Duty, Rewritten
The Digital Omnibus softened Article 4 in July 2026 but did not remove it. What AI literacy now requires, plus a 90-day plan for Luxembourg SMEs.
