TL;DR

For most of our clients the GPAI chapter is a documentation problem, not an engineering one. The engineering problem is downstream: proving you know which model version answered which user.

What the text asks

The obligations for providers of general-purpose AI models (Chapter V) boil down to technical documentation, a copyright policy, and a public summary of training content. Systemic-risk models get evaluation, incident reporting and cybersecurity duties on top.

What it changed for us

Nothing in the model code. Quite a lot in the delivery checklist: every deployment now carries a model card, a version pin and a log of which version served which request. That last one is the actual work.

What we are still unsure about

Fine-tuning thresholds. The guidance on when a fine-tune makes you a provider is workable but not crisp; we treat any training run above a modest compute budget as if it did.