CSOAI - GPAI obligations
If you ship a model, this is your 2 Aug 2026 list
General-purpose AI provider obligations have applied since 2 August 2025 - and since 2 August 2026 the AI Office can enforce them with penalties. Here is exactly what every model provider owes - and the extra duties if your model carries systemic risk.
You are interacting with an AI system.
The embedded 'Ask your Council assistant' panel (SovereignSpot) sends questions to the configured /api/chat model endpoint, where a single model writes the answer; no Council review, vote, or signature is implied. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.
Disclosed under EU AI Act Article 50(1). Every surface and its classification
Every GPAI provider
Keep up-to-date docs on the model's design, training, and evaluation for regulators and downstream providers.
Publish a sufficiently detailed public summary of the content used to train the model.
Put a policy in place to comply with EU copyright law and honour text-and-data-mining opt-outs.
Give downstream deployers what they need to understand capabilities and limitations.
Systemic-risk models (additional)
Adversarial testing / red-teaming to find and mitigate systemic risks.
Track and report serious incidents and corrective actions to the AI Office.
Protect the model and its physical infrastructure to an adequate level.
Assess and mitigate risks at the Union level on an ongoing basis.
Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.
Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps