Direct answer
GPAI model exposure must be separated from deployment exposure.
General-purpose AI model questions are different from ordinary use-case readiness. A company should clarify whether it provides, modifies, integrates or merely uses a GPAI model before deciding which documentation and governance work matters.
For the next layer, compare provider vs deployer roles, review high-risk AI system signals, or start with an EU AI Act risk assessment.
Decision criteria
What changes the analysis
- The company provides or distributes a general-purpose AI model.
- The company modifies or fine-tunes a model in a way that changes responsibility.
- The model is embedded into an EU-facing product or workflow.
- Downstream users rely on the model in sensitive or regulated contexts.
First inspection
What to clarify first
- 01Model source and modification level.
- 02Provider, integrator and deployer roles.
- 03EU-facing product or workflow context.
- 04Documentation available from upstream providers.
This page provides operational information for AI governance readiness. It is not legal advice.