Blog

AI Act GPAI enforcement: 8 questions for your AI vendor

Pascal Di Prima 11 min read
AI Act GPAI enforcement: 8 questions for your AI vendor

In short: Since 2 August 2026 the European Commission, through its AI Office, can enforce the obligations of providers of large AI models (GPAI models), up to fines and recalls. Law firms and legal departments are not the addressees of the rules, but they are affected as soon as their tool runs on such a model. They should put eight specific questions to their tool vendor, and document and date the answers.

Since 2 August 2026 the European Commission has been able to enforce the obligations that Regulation (EU) 2024/1689 on artificial intelligence places on providers of general-purpose AI models, known as GPAI models. The obligations themselves have applied since 2 August 2025. What changed this summer is that the Commission’s AI Office can now request information, evaluate models, require measures and impose fines. The Commission announced the start of enforcement on 31 July 2026.

Law firms and legal departments are, as a rule, not GPAI providers. They do not train large models; they use tools built on top of them. That means they are not the addressees of enforcement. They are affected all the same, because they sit at the end of a supply chain that is now supervised. Whatever the Commission requires of a model provider can affect the tool in use in your own organisation – sometimes at very short notice.

The article is written for partners, legal operations and in-house legal departments that use AI tools built on third-party models. It is not a substitute for advice on a specific case.

What has been enforceable since 2 August 2026?

Chapter V of the AI Act sets out the obligations of GPAI model providers. Law firms and legal departments do not bear these obligations themselves. They do, however, determine which documents have to exist along the supply chain and what you can ask your tool vendor for. Under Article 53, every provider must

  • draw up and keep current technical documentation of the model,
  • provide information and documentation to companies that integrate the model into their own AI systems,
  • put in place a policy to comply with Union copyright law, including respect for text-and-data-mining opt-outs,
  • publish a sufficiently detailed summary of the content used for training, following a Commission template.

For models with systemic risk, Article 55 adds:

  • model evaluations including adversarial testing,
  • assessment and mitigation of systemic risks,
  • tracking and reporting serious incidents to the AI Office,
  • an adequate level of cybersecurity.

Systemic risk is presumed, among other things, where more than 10²⁵ floating-point operations were used for training.

These obligations have applied since 2 August 2025. Models placed on the market before that date have a transition period under Article 111 that runs until 2 August 2027. The Commission has explained the obligations in its guidelines for GPAI providers. Alongside them sit a code of practice, which providers can use to demonstrate compliance, and the template for the training-content summary.

On 2 August 2026 the powers changed. According to the Commission’s AI Act Service Desk, the AI Office can now request information and documents, require access to a model in order to evaluate it, require risk mitigation measures and impose fines. Article 101 provides for fines on GPAI model providers of up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher. Article 93 also allows the Commission to restrict a model’s availability on the market, or to have it withdrawn or recalled.

For legal practice, that last point matters most. A fine hits the provider. A restriction on the model hits everyone whose tool is connected to it and works with it.

Shortly before the deadline, the so-called Digital Omnibus also entered into force: Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. Its main effect is to push back the deadlines for high-risk AI systems: to 2 December 2027 for systems under Annex III, and to 2 August 2028 for systems under Annex I. It did not change the start of GPAI enforcement on 2 August 2026. For deployers it changes two points that come up below: AI literacy under Article 4, and the AI Office’s competence for certain AI systems.

Who is affected: model provider, tool vendor or deployer?

Between a law firm and the model provider there is usually another company: the vendor of the tool that was purchased. The tool provider builds features around the model, and that is where Article 53(1)(b) comes in: the model provider must give such downstream providers the information they need to understand the model’s capabilities and limitations and to meet their own obligations.

For deployers, this produces a simple division of labour. You have no direct claim against the model provider, and you do not need to track which information requests go out from Brussels. What you can do is require your tool vendor to pass on the information it receives, and to commit contractually to telling you when something changes underneath.

It is different when model and tool come from the same company, as with ChatGPT Enterprise from OpenAI. There is no intermediary to ask, only the model provider itself. For this case, Article 75(1) already gave the AI Office powers to supervise the AI system. Since 2 August 2026, the Digital Omnibus has made that competence exclusive and extended it to cases where model and system come from different companies within the same undertaking. There are exceptions for areas with their own sectoral supervision. The AI Office has also gained its own investigative powers, up to on-site inspections. Supervision from Brussels then reaches all the way to the tool your people work with.

One special case concerns vendors that do more than integrate a model and actually modify it, for example by fine-tuning it on legal texts. According to the Commission’s guidelines, a company that modifies a GPAI model to a significant extent can itself become a provider in respect of that modification. As an indicative threshold, the guidelines point to modification compute of more than one third of the compute used to train the original model. Most tools in the legal market will not come close. Ask anyway. A vendor that has substantially modified a model has to keep its own documentation for that modification, and that is the documentation you will want to see if there is ever a dispute.

Your own obligations continue alongside, and they have nothing to do with the GPAI rules. Article 4 has required deployers to address their staff’s AI literacy since February 2025. The Digital Omnibus turned this into a best-efforts obligation: providers and deployers take measures to support the development of AI literacy among their staff. They no longer have to guarantee any particular level of AI literacy for any individual. Since August 2026, the transparency obligations in Article 50 have also applied wherever the actual use triggers them. The GDPR requires a data processing agreement and clarity on sub-processors. Law firms also have to meet their professional secrecy rules when engaging service providers; in Germany, for example, Section 43e of the Federal Lawyers’ Act (BRAO). None of these obligations is met simply because the model provider meets its own.

How precisely anyone can answer the questions below also depends on how deeply a model is embedded in your workflows. In e! by Lexemo, a language model works only at specific, deliberately placed steps of a process, and many processes run with no model at all. That makes it possible to say, step by step, what a restriction on the model would affect and what would keep running. And because e! supports multiple AI models and lets you choose which model to use for which task, a restricted model can be replaced by another. That freedom of choice is the most important step towards being future-proof against measures taken against any single model. Further details on data processing and security at Lexemo are documented in our Trust Center.

The questions below are phrased so that you can drop them unchanged into a vendor questionnaire. They ask for documents and commitments. A general assurance such as “we are fully compliant” answers none of them.

  1. Model and classification: Which GPAI model from which provider does the tool rely on, and in which version? Is the model classified as a GPAI model with systemic risk? Are different models used for specific features?

  2. Evidence of provider obligations: Has the model provider signed the Commission’s code of practice? If not, how does it demonstrate compliance with Article 53 and, where relevant, Article 55?

  3. Training summary and copyright: Where can the public summary of training content be found? Where is the copyright policy described, and how are opt-outs respected?

  4. Passing on documentation: What information has the vendor received from the model provider under Article 53(1)(b)? Which parts does it make available to you, and how often are they updated?

  5. Modification of the model: Has the model been fine-tuned or otherwise modified? To what extent, and has the vendor assessed whether this makes it a provider in its own right?

  6. Incidents and regulatory measures: How, and within what time frame, will you be told if the model is involved in a serious incident, if the AI Office requires measures, or if the model provider restricts functionality? Is that commitment in the contract?

  7. Data: Which sub-processors are involved, in which region are inputs processed, and is the use of your inputs for training contractually excluded?

  8. Outage and switch: What happens to your workflows if the model is restricted, suspended or recalled? Is there a fallback model, how long does a switch take, and how do you get your data and configurations back?

Questions one to four can usually be answered with documents that have to exist anyway. Questions five to eight are more revealing, because they show whether the vendor has already thought about its own dependency on the model.

OpenAI showed in late September 2026 how quickly a model provider can act on its own. After an agent got around safeguards in an internal training environment, the company paused training, evaluation and tool use of its most capable models, with no regulator involved. According to the available reports, customers were not affected. The episode still shows how short the path from an incident to a restriction can be, and that is exactly what questions six and eight are about.

How do you recognise a good answer?

Asking the questions is the easy part. Judging the answers is harder. The overview gives, for each question, the legal basis, what a solid answer contains, and how to spot an evasive one.

1. Model and classification (Art. 51, 53)

  • Solid answer: Model name, provider and version; classification with or without systemic risk; overview of which feature uses which model
  • Warning sign: “the latest OpenAI model” with no version; nothing on individual features

2. Evidence of provider obligations (Art. 53, 55; code of practice)

  • Solid answer: Code signed, with reference to the Commission’s list of signatories, or another method of demonstrating compliance, described
  • Warning sign: “That’s the model provider’s job, not ours”

3. Training summary and copyright (Art. 53(1)(c), (d))

  • Solid answer: Links to the public summary and the copyright policy
  • Warning sign: No links; appeal to confidentiality

4. Passing on documentation (Art. 53(1)(b), Annex XII)

  • Solid answer: List of documents received, with dates; update cycle; access, under NDA if necessary
  • Warning sign: “We have it but can’t share it”, with no alternative

5. Modification of the model (Commission guidelines, one-third threshold)

  • Solid answer: Clear statement: prompting and retrieval only, or fine-tuning with an order of magnitude; documented assessment of provider status
  • Warning sign: Unclear whether any fine-tuning took place

6. Incidents and regulatory measures (Art. 55(1)(c), Art. 93)

  • Solid answer: Contract clause with a fixed deadline and a named contact
  • Warning sign: Pointer to a blog or status page instead of a contractual commitment

7. Data (GDPR Art. 28; professional secrecy rules)

  • Solid answer: Data processing agreement; sub-processor list with regions; contractual exclusion from training
  • Warning sign: Training exclusion only as a setting; region “global”

8. Outage and switch (Art. 93)

  • Solid answer: Named fallback model; tested switchover time; export formats for data and configurations
  • Warning sign: “That doesn’t happen with us”

Date the answers, give them an owner, and renew them every year and whenever the model changes. Each set of answers describes the model as it was on the day you asked.

Frequently asked questions

Since when can the European Commission enforce the AI Act’s GPAI obligations?

Since 2 August 2026. The obligations of GPAI model providers under Articles 53 and 55 have applied since 2 August 2025, with a transition period until 2 August 2027 for older models. The enforcement powers the Commission exercises through the AI Office have only applied since 2 August 2026. They include requests for information, model evaluations, orders to mitigate risks, fines of up to 3% of worldwide annual turnover or EUR 15 million, and restricting, withdrawing or recalling a model.

Not as addressees, but indirectly. Anyone using a tool built on a GPAI model is generally a deployer of an AI system, not a GPAI provider. Measures against the model provider, such as a recall under Article 93, flow straight through to every tool built on that model. Their own obligations remain in place: AI literacy under Article 4, transparency under Article 50, data protection and, for law firms, professional secrecy rules.

What does the Digital Omnibus change for deployers of AI tools?

For law firms and legal departments, mainly two things. Article 4 is now a best-efforts obligation: deployers take measures to support the development of their staff’s AI literacy and do not have to guarantee a particular level. And where model and tool come from the same provider or the same undertaking, the AI Office has had exclusive competence to supervise the tool since 2 August 2026. GPAI enforcement started on 2 August 2026 as planned. High-risk obligations apply only from 2 December 2027 (Annex III) or 2 August 2028 (Annex I). Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking requirement in Article 50(2).

Do the eight questions also apply to Microsoft 365 Copilot or ChatGPT Enterprise?

Yes. With Microsoft 365 Copilot, Microsoft is the tool vendor and uses models from other providers, including OpenAI. The questions go to Microsoft. With ChatGPT Enterprise, model provider and tool vendor are the same company. Questions four and five then largely merge, and you put the rest directly to OpenAI.

Is a vendor’s assurance that its tool is “AI Act compliant” enough?

No. A general assurance does not replace any of the documentation the AI Act provides for along the supply chain, and it does not answer the practical questions about incidents, restrictions and switching. Whether transparency obligations apply, or whether your own AI literacy measures are sufficient, also depends on how you use the tool, and no vendor can guarantee that on its customers’ behalf.

Sources

This article reflects the position as of 2 October 2026.

Ready to automate your legal workflows?

Discover how e! can transform your legal operations with no-code automation.

Related Articles