Governed Foundation & GPAI Models Directory
What are the EU AI Act compliance obligations for Foundation & GPAI Models?
Under the EU AI Act (Articles 50, 51, 53, 55), General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policies, and provide transparency summaries. Models surpassing 10^25 FLOPs trigger systemic risk mitigation obligations.
Gemini 2.5 Pro
Tier 1 SystemicGemini 2.5 Pro surpasses the 10^25 FLOPs threshold, classifying it as a GPAI model with systemic risk under Article 51. Obligations include mandatory model evaluations, adversarial testing, systemic risk assessments, cybersecurity safeguards, and technical documentation for downstream deployers.
Gemini 2.5 Flash
Tier 2 GPAIGemini 2.5 Flash operates below the 10^25 FLOPs cumulative computation threshold, classifying as standard General Purpose AI (GPAI). It must maintain technical documentation, comply with EU copyright laws, and supply transparency summaries without systemic risk mitigation burdens.
Gemini 3.7 Flash
Tier 1 SystemicGemini 3.7 Flash includes native support for deterministic human-in-the-loop gating when orchestrated via MCP tool calling, allowing downstream providers to fulfill Article 14 oversight requirements in automated decision workflows.
Claude 3.7 Sonnet
Tier 1 SystemicAs a GPAI model exceeding 10^25 FLOPs, Claude 3.7 Sonnet requires Anthropic to perform continuous adversarial red-teaming, track serious incident reporting to the EU AI Office, implement cyber-resilience controls, and publish detailed training transparency dossiers.
Claude 3.5 Haiku
Tier 2 GPAINo. Claude 3.5 Haiku falls below the 10^25 FLOPs systemic threshold. It requires baseline GPAI compliance under Articles 50 and 53, including copyright compliance policies and downstream technical summaries.
Claude 3 Opus
Tier 1 SystemicClaude 3 Opus maintains comprehensive model cards, architecture summaries, training compute accounting, and data governance verification to satisfy Article 53 technical file requirements for EU market availability.
GPT-4o
Tier 1 SystemicDeployers of GPT-4o in high-risk domains must implement Article 14 human oversight, Article 50 transparency labels, maintain audit logs under Article 12, and verify that the foundation model maintains active systemic risk mitigations under Article 55.
GPT-4o-mini
Tier 2 GPAIGPT-4o-mini adheres to Article 53 GPAI data transparency requirements. It provides summary documentation on data filtering and copyright opt-out mechanisms for European market deployers.
OpenAI o1
Tier 1 SystemicOpenAI o1 incorporates deliberative chain-of-thought safety monitoring, pre-computation policy verification, and systemic risk evaluations designed to mitigate autonomous cyber and bio-hazard reasoning risks under Article 55.
OpenAI o3-mini
Tier 2 GPAIYes, provided the deployer wraps the model in Article 14 human oversight controls, logs outputs under Article 12, and performs post-market monitoring as mandated by EU AI Act Annex III standards.
LLaMA 3.3 70B
Tier 1 SystemicUnder Article 53(2), open-weight models with systemic risk must still publish detailed training data summaries, comply with EU copyright opt-outs, and provide documentation of architecture and safety evals to the EU AI Office.
LLaMA 3.1 405B
Tier 1 SystemicWith training compute significantly exceeding 10^25 FLOPs, LLaMA 3.1 405B triggers mandatory Article 55 systemic risk mitigations, including model evaluation benchmarks, adversarial testing dossiers, and incident notification pathways.
LLaMA 3.2 3B
Tier 3 SLMYes. As a lightweight edge model with under 3 billion parameters, LLaMA 3.2 3B is exempt from GPAI systemic obligations, requiring only standard Article 50 AI disclosure notice when generating user-facing content.
Mistral Large 2
Tier 1 SystemicMistral Large 2 is built by an EU-headquartered provider (Mistral AI, France) offering native European data residency, full GDPR alignment, and demonstrated alignment with European AI Office GPAI codes of practice.
Mistral Small
Tier 2 GPAIMistral Small provides complete European transparency files, clear watermarking indicators, and compliant copyright documentation according to Article 53 standards.
Codestral
Tier 2 GPAICodestral incorporates automated copyright filtering, open source license adherence tracking, and provides transparent technical dossiers satisfying Article 53 requirements for developer tooling.
DeepSeek V3
Tier 1 SystemicDeployers must ensure supplementary Chapter V GDPR transfer mechanisms (SCCs, TIA) alongside EU AI Act Article 53 technical files, as DeepSeek foundation infrastructure is hosted outside the EEA.
DeepSeek R1
Tier 1 SystemicDeepSeek R1 triggers Article 51 systemic classification due to frontier reasoning capabilities, requiring third-party adversarial benchmark audits, cyber vulnerability logging, and model transparency cards.
Qwen 2.5 72B
Tier 1 SystemicDeployers must provide Article 53 technical documentation, verify copyright opt-out compliance, and maintain Article 14 human oversight when integrating Qwen 2.5 into automated business processes.
Qwen 2.5 Coder 32B
Tier 2 GPAINo. Operating below 10^25 FLOPs, Qwen 2.5 Coder 32B is classified as a standard GPAI model requiring basic Article 50 transparency and Article 53 technical summaries.
Command R+
Tier 1 SystemicCommand R+ provides verifiable citation generation, private VPC deployment options in EU regions, and audited data governance files satisfying Article 10 and Article 53 standards.
DBRX
Tier 2 GPAIDBRX offers complete lineage tracking via Unity Catalog, auditable data provenance, and full compliance with EU AI Act Article 53 technical file requirements for enterprise data platforms.
Grok-2
Tier 1 SystemicReal-time social media training requires continuous Article 10 data bias scrubbing, strict Article 50 hallucination disclaimers, and Article 55 systemic adversarial safety reviews before EU distribution.
Phi-4
Tier 3 SLMPhi-4 is trained on curated synthetic data and filtered educational material, ensuring zero PII retention, minimal copyright liability, and streamlined Article 10 data quality verification.
Gemma 2 27B
Tier 2 GPAIGemma 2 27B provides open weights under responsible terms. It satisfies Article 53 open-source exemptions while maintaining safety cards and Article 50 transparency declarations.
Granite 3.0 8B
Tier 2 GPAIIBM provides full intellectual property indemnity and complete data governance disclosure for Granite 3.0, aligning directly with EU AI Act Article 53 copyright transparency guidelines.