If your business isn’t based in the EU, it’s easy to assume EU AI Act GPAI obligations are someone else’s problem. They aren’t — not entirely, and not for much longer.
General-purpose AI (GPAI) model obligations under the EU AI Act — transparency and copyright rules for providers — actually took effect in August 2025. What changes on 2 August 2026 is enforcement: this is when the enforcement powers of the EU AI Office and national competent authorities become active, alongside the ban on prohibited AI practices. In practice, that means the GPAI rules businesses have technically been subject to for a year are about to start being actively policed — a meaningfully different moment for anyone whose AI vendors sit in that GPAI supply chain.
This is the layer of the law that touches the foundation models businesses everywhere already rely on — the large language models sitting underneath the AI tools your team uses every day, regardless of which country you operate from.
Understanding EU AI Act GPAI obligations doesn’t require a Brussels office. Here’s what’s actually changing, who it touches, and what a sensible SMB or mid-market business — in Australia, the UK, New Zealand, North America, or anywhere else — should do about it.
EU AI Act GPAI Obligations: What Counts as a “GPAI Model”?
The EU AI Act splits AI regulation into two broad layers: rules for specific AI systems (like a hiring tool or a credit-scoring tool) and separate rules for general-purpose AI models — the foundation models that get built into many different downstream systems. GPAI obligations scale with capability:
- Baseline transparency and copyright obligations — technical documentation for downstream providers, a public summary of training content, and a policy for respecting EU copyright law.
- Systemic risk assessment (for the largest, most capable models) — additional evaluation, incident reporting, and cybersecurity obligations.
If your business builds or fine-tunes its own foundation model — rare, but not impossible for larger tech companies outside the EU too — these obligations apply to you directly, regardless of where you’re headquartered, if you place that model on the EU market.
Why This Still Matters If You’re Just a User of AI Tools
Almost no SMB anywhere — EU included — is a GPAI provider. Most businesses aren’t building foundation models. They’re using them, through a chatbot, a copilot embedded in their CRM, an AI-powered analytics tool. So why does this deadline matter to an ordinary business, wherever it’s based?
Three reasons:
1. Your vendors are affected, and that flows downstream — wherever you are.
If a vendor’s AI tool relies on a GPAI model with EU exposure, that vendor now has compliance obligations — and increasingly, procurement teams (including Microsoft, per its SSPA Data Protection Requirements v12, Section K) are asking their own suppliers to demonstrate AI governance maturity as a condition of doing business. This isn’t an EU-only dynamic: any business selling into supply chains that touch EU-exposed vendors can expect the same question eventually. A structured AI Vendor Risk Assessment Questionnaire is the fastest way to have an answer ready.
2. “We don’t have an AI policy” is becoming a harder answer to give, globally.
Regulatory momentum has a way of resetting expectations well outside its own jurisdiction. As EU AI Act deadlines land through 2026 and 2027, “AI governance” stops being a nice-to-have and starts being something clients, insurers, and boards expect to see evidence of — a documented policy, a risk register, a use case inventory — no matter which country’s law technically applies to you.
3. Local regulation is converging on the same expectations.
This isn’t just an EU story playing out elsewhere unchanged. Australia’s Privacy Act reform is progressing, with new automated decision-making transparency obligations landing 10 December 2026; Colorado’s AI transparency law (SB 189) takes effect January 2027; the UK and other jurisdictions are developing their own frameworks. The direction of travel is consistent even where the specific rules differ — businesses that build basic AI governance now aren’t just responding to Europe, they’re getting ahead of where their own regulators are clearly heading.
What Happens If You Ignore It
For most SMBs outside the EU, the exposure isn’t a direct fine from Brussels — it’s the slower, more common cost of falling behind what counterparties now expect. A procurement questionnaire that asks about AI governance and gets an unconvincing answer can quietly remove a business from a shortlist before anyone explains why. A vendor renewal that surfaces a governance gap can trigger a longer, more expensive due-diligence cycle than it would have a year earlier. None of this shows up as a headline enforcement action — it shows up as deals that take longer to close, or don’t close at all.
What a Sensible Response Looks Like (Without Hiring a Consultant)
You don’t need an in-house compliance team or a six-figure engagement to respond sensibly to this, wherever your business is based. A proportionate response looks like:
- Know which AI tools your business actually uses. Most businesses underestimate this — AI is often adopted tool-by-tool, team-by-team, with no central register.
- Put a written AI Acceptable Use Policy in place. This is the single most requested AI governance document in procurement reviews and the fastest way to show you take this seriously — for staff, for clients, and for anyone auditing your supply chain.
- Ask your key AI vendors one direct question: “What GPAI model(s) underpin your product, and are you tracking EU AI Act compliance?” Their answer (or lack of one) tells you a lot about vendor risk. A structured AI Vendor Risk Assessment Questionnaire turns this into a repeatable process instead of a one-off email.
- Revisit this quarterly, not once. The compliance calendar doesn’t stop at August 2026 — prohibited-practice enforcement lands February 2027, and high-risk AI obligations follow in August 2027, with parallel deadlines emerging in other jurisdictions along the way.
Where to Start
Not sure yet how exposed your business actually is? Start with the free AI Governance Readiness Checklist — a one-page, plain-English self-assessment covering AI use cases, vendor risk, and where you sit against ISO 42001 and the EU AI Act. No sign-up gimmicks, delivered by email.
If you already know you need documentation in place, two products cover the ground this article raises:
- AI Acceptable Use Policy ($74) — the document procurement teams and boards ask for first. Ready to brand and issue to your team in under a day.
- AI Vendor Risk Assessment Questionnaire ($89) — a structured, repeatable way to vet the AI vendors in your own supply chain, aligned to ISO 42001 and Microsoft SSPA DPR v12 Section K.
Both are ready-to-deploy, editable Word documents — built to the standard a Big-4 advisor would produce, without the advisor’s invoice or timeline. If your business also has AU exposure, our related pieces cover the AU Privacy Act reform’s automated decision-making obligations and what an ISO 42001 toolkit actually needs to cover, clause by clause.
Frequently Asked Questions
When did EU AI Act GPAI obligations actually start?
Baseline transparency and copyright obligations for GPAI providers took effect in August 2025. What changes on 2 August 2026 is enforcement — this is when the EU AI Office and national authorities gain active enforcement powers.
Does the EU AI Act apply to my business if I’m not in the EU?
Directly, only if you provide or place a GPAI model on the EU market. Indirectly, most non-EU SMBs are affected through their AI vendors’ compliance obligations and through procurement teams increasingly expecting evidence of AI governance regardless of jurisdiction.
What’s the difference between a GPAI model and an AI system under the Act?
A GPAI model is a foundation model that can be used for many different tasks and gets built into other products. An AI system is the specific downstream application — like a hiring tool or credit-scoring tool — built using one or more GPAI models.
What should a non-EU business do to prepare?
Build a register of AI tools in use, put a written AI Acceptable Use Policy in place, ask key AI vendors what GPAI models underpin their product, and revisit the assessment quarterly as further deadlines land through 2027.
2 Responses