Passed last year, the AI Act will reach a key milestone tomorrow, 2 August 2025: from that date, suppliers of general-purpose AI (GPAI) models will have to apply new rules in all EU countries. These are general-purpose AI models capable of performing all kinds of tasks (e.g., writing text, coding or creating images) and which can serve as the basis for numerous downstream applications. Systems like OpenAI’s GPT-4 (which runs ChatGPT), Meta’s Llama 2, Anthropic’s Claude or models from the French startup Mistral AI typically fall into this category. Google has already announced that it will bend to these new rules, along with OpenAI and Mistral AI.
The European framework, the first of its kind in the world, aims to provide a framework for these extraordinarily capable tools in order to bring them into line with European values, without putting the brakes on innovation. In mid-July, moreover, the European Commission published guidelines to specify which companies and models are covered, as well as a standard public summary model for training data--in addition to a code of good practice drawn up with industry.
Unprecedented transparency obligations
Until now, the designers of these giant AIs have operated largely in secret. That’s about to change. From August 2025, every supplier of a general-purpose AI model will have to document its system from top to bottom: it will have to compile detailed technical documentation (including how the model has been trained, tested and evaluated) and keep it ready to be passed on to the competent European authorities in the event of an inspection.
The same information will also have to be shared with client companies that integrate the model into their own products, so that they fully understand its capabilities and limitations and can themselves comply with their legal obligations. In other words, a publisher using a generic AI model supplied by a third party will be entitled to much more comprehensive instructions for use than before.
On the business side, these obligations are also causing some tension. During the consultations carried out in 2024, several AI suppliers expressed concerns about the administrative burden represented by these new requirements. Some startups and open-source players felt that producing full documentation and a structured public summary could require significant resources--human, legal and technical--that they do not necessarily have at their disposal. The European Commission has listened to these concerns by proposing a standardised public summary model and a code of good conduct, but the transition remains a challenge, particularly for smaller structures.
Another major new feature is the transparency of the data used to train these AIs. Suppliers will have to publish a publicly accessible summary of the training data for each model, in sufficient detail to give a clear idea of the sources used. At the end of July, the European Commission presented a model for a harmonised public summary, which requires, for example, an indication of the main sources of ingested information (large datasets, names of dominant web domains, etc.) as well as information enabling stakeholders to assert their rights.
At the same time, AI designers will have to adopt an internal policy to respect copyright. Since the training of these models is often based on billions of texts, images or audio extracts gleaned from the internet--including protected works--this obligation responds to the concerns of creators and copyright holders. For example, it means preventing AI from reproducing an existing work verbatim without authorisation.
In practical terms, these rules will have a visible impact. If an AI model has been trained on a large corpus of protected books or press articles, its supplier will now have to reveal the main sources. Until now, the origin of the data remained confidential. A writer or photographer will therefore be able to find out--at least in part--whether his or her works were part of the training data for a model. Similarly, a user asking a chatbot to provide in extenso the lyrics of a song or a chapter from a novel could be refused: the model will have been configured not to infringe copyright, where it might previously have given in to the request.
OpenAI, Meta, Anthropic... first to be affected
These obligations directly target the players behind generalist models. American companies such as OpenAI, Meta, Google (with its Palm model behind Bard) and Anthropic, as well as European startups such as Mistral AI, will have to adapt their development and transparency practices. For example, OpenAI--which has come in for criticism for refusing to reveal the data used to train GPT-4, citing competition and security concerns--will have to play the openness card in Europe. The law will force it to disclose which copyrighted data was used to train its artificial intelligences. “These provisions are first and foremost about transparency, which guarantees that AI and the company developing it are trustworthy,” stresses Dragos Tudorache, Romanian MEP and co-rapporteur of the AI Act.
Other groups such as Meta (which runs Llama) or the French company Mistral, which rely more on open source, will also have to publish a minimum amount of information about their models--unless they are completely open and not commercialised, which may partially exempt them from these requirements. In any event, all suppliers wishing to deploy these AIs on the European market “will have to structure their documentation, clarify their processes, and demonstrate their compliance” with the regulations, sums up lawyer Alexandra Iteanu.
To help the industry apply these new rules, Brussels has brought together experts, companies and associations. The result is a GPAI Code of Practice, published on 10 July 2025, which sets out in detail how the obligations of transparency, security and respect for copyright can be met in practice. This voluntary code is divided into three chapters: transparency (description of the model, training methods, known limits, biases); copyright (information on protected content used and internal policies); and safety & security (tests, risk management, cybersecurity), the last of which concerns only a small number of models deemed to pose a systemic risk.
Model suppliers are strongly encouraged to adhere to this code, as it will make it easier for them to prove that they are complying with the AI Act. In practice, a signatory to the code benefits from a lighter administrative burden and greater legal certainty than a company that would have to demonstrate compliance without this support. The European Commission hopes that many suppliers will sign up quickly: this will help to recognise the voluntary “good performers” and encourage the rest of the sector to follow suit.
Implementation deadlines and penalties at stake
The new rules on generalist AI models formally come into force in August 2025, but with a phased implementation schedule. The legislator has provided for a transition period to give players time to comply. In concrete terms, while the transparency obligations will apply from 2025, official controls and potential sanctions will not begin until 2026 for new models placed on the market, and 2027 for models already in existence before the entry into force. This tolerance is intended to avoid putting a sudden brake on innovation, while sending out a clear message: after these deadlines, hefty fines could be levied in the event of non-compliance.
The European AI Office--the new authority responsible for overseeing the regulation, based partly in Brussels and partly in Luxembourg--will be able to impose penalties of up to €15m or 3% of the worldwide turnover of the company concerned. It’s all the more reason for the tech giants to take the law seriously. In fact, after threatening to withdraw ChatGPT from the European market in the face of these constraints, OpenAI has finally given assurances that it has “no plans to leave” and intends to abide by the rules of the game.
From the point of view of the general public, this regulatory change promises greater transparency and protection in the world of AI. In the future, it should be easier for Europeans to know when they are dealing with artificial intelligence and what it has been trained to do. It remains to be seen what use they will make of this new information...
This article was originally published in French.



