EU AI Act Kicks In for GPAI: What Tech and SaaS Companies Need to Know

The EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689) is phasing in, and one of the first targets are providers of general-purpose AI (GPAI) models. These rules matter not only for companies building GPAI models but also for SaaS providers integrating them into their platforms.

When Do the Rules Apply?

  • The AI Act entered into force on 1 August 2024.
  • Chapter V (obligations for GPAI models) applies from 2 August 2025.
  • Models already on the market before that date have until 2 August 2027 to comply.
  • Enforcement powers (and fines) only start from 2 August 2026 – but the obligations themselves bite earlier.

What GPAI Providers Must Do

The Act introduces new rules on transparency and accountability. Providers must:

  • Keep comprehensive technical documentation up to date (training, testing, evaluation).
  • Provide documentation to downstream developers who integrate GPAI models.
  • Publish a summary of training data sources.
  • Put in place a copyright compliance policy.
  • For non-EU providers: appoint an authorised representative in the EU.

A Practical Approach to Transparency

For most GPAI providers, the real challenge will not be understanding what the Act requires – it will be to produce and make available documentation that is both complete and sustainable. A “paper exercise” approach is unlikely to hold up over time.

A smarter strategy is to treat documentation as part of their development process rather than an afterthought. That means embedding compliance into their workflows, logging training and testing data automatically, and relying on standardised templates so that updates remain consistent across models. Version control and audit trails can then serve both as evidence of compliance and as a shield against liability.

For SaaS providers that rely on third-party GPAI, the message is simple: you will need to demand this transparency from your suppliers. Without it, not only regulatory compliance but also customer trust becomes a serious risk.

Higher Bar for “Systemic Risk” Models

Not every GPAI model will be judged by the same standard. Those that the EU designates as bearing “systemic risk” – because of their scale, reach, or potential to affect fundamental rights – will face an even tougher regime. In practice, that means more rigorous testing and evaluation, structured risk assessments, mandatory reporting of serious incidents to the AI Office and national authorities, and reinforced cybersecurity standards.

For companies building or deploying a model that could fall into this category, early preparation is critical, since obligations are heavier, the scrutiny will be sharper, and the reputational stakes are much higher.

Tools to Support Compliance

To ease the transition, the European Commission has published non-binding guidelines for GPAI providers and, more recently, launched a voluntary Code of Practice (July 2025). The Code provides a framework for transparency, copyright, and safety obligations and may help reduce some of the administrative burden.

Still, these tools should be seen as signposts rather than a full roadmap. They provide useful guidance, but they do not replace the need for a tailored compliance strategy. Each provider – and each SaaS company relying on GPAI – will need to decide how to operationalise these principles within their own business models.

Why This Matters for SaaS Providers

For SaaS companies, the immediate question is:

Am I a provider of GPAI, or just an integrator?

If you are an integrator only, you do not carry the Chapter V duties directly – but you will rely heavily on upstream GPAI providers fulfilling theirs, and you will have obligations elsewhere in the Act when making available AI systems on the market.

This increases the importance of vendor diligence, contractual protections, and risk management central.

Bottom Line

The phased timeline of the AI Act is deliberate: obligations apply from August 2025, enforcement begins in 2026, and pre-existing models gain until 2027 to catch up. But waiting is not an option—duties like documentation, training data summaries, and implementing copyright policies will apply as soon as Chapter V is in force.

For SaaS providers, the critical step is to classify your role correctly: are you a GPAI provider, an integrator, or both? Even if only an integrator, you will depend on upstream compliance and must be ready to show customers how your integration aligns with EU standards.

As these obligations take shape, many companies are finding it useful to get an early compliance strategy in place rather than scramble once enforcement begins. If you woud like to discuss where your business fits in and what practical steps to take now.

Do not hesitate to reach out to Cresco’s innovation team in case you would have any questions and/or advice to guide you through this regulatory labyrinth.

 


 

Olivier Van Raemdonck, Managing Partner

Ward Verwaeren, Managing Associate

Marie Vercambre, Associate

Aida Kaloci, Associate

Axel Desmet, Associate

Team

Axel Desmet
Associate
Ward Verwaeren
Counsel
Aida Kaloci
Associate
Olivier Van Raemdonck
Managing Partner

Expertises

data & privacy
intellectual property rights