Obligations live since 2 August 2025 · Enforcement LIVE since 2 August 2026
EU AI Act &
General Purpose AI
A comprehensive practitioner's guide to GPAI obligations, risk classification, agentic AI implications, and the compliance architecture banks and enterprises must build — right now.
Regulation (EU) 2024/1689
By Kishor Akshinthala
iPRODECISIONS × CryptoExponentials
August 2025
K
Kishor Akshinthala
Venture Studio Founder · Enterprise Deal Maker · Angel Investor
27 years across AI, Blockchain & Business Growth. Founder of AvArikA, CAIBots, CryptoExponentials & Path2Excel. This analysis draws on active advisory work with banks and fintechs navigating EU AI Act compliance across agentic AI deployments.
10²³
Training FLOPs Threshold
GPAI Threshold
Models trained with ≥10²³ floating-point operations generating language, image, audio or video across a wide task range are presumed GPAI — triggering full provider obligations under Art. 51.
Art. 3(63)Recital 98
→
10²⁵
Training FLOPs Threshold
Systemic Risk Tier
GPAI models with ≥10²⁵ FLOPs are classified as systemic risk — mandatory red-teaming, incident reporting, Commission notification within 2 weeks, and cybersecurity controls.
Art. 51(2)Art. 55
Legal Definition
Significant Generality
Must display "significant generality" — capable of competently performing a wide range of distinct tasks. Single-purpose models are NOT GPAI. Art. 3(63)
GPT-4 / 4oClaude 3+
Gemini UltraLlama 3 70B
Provider Role
GPAI Provider
Any entity that trains a GPAI model placed on the EU market — regardless of location. OpenAI, Anthropic, Google, Meta, Mistral. Carries the full Art. 53 documentation and transparency obligations. Art. 53
Deployer Role
GPAI Deployer
Entities building on top of GPAI models — banks, fintechs, enterprises. Fine-tuning and agents do not make you a provider unless deemed a "substantial modification." Risk obligations focus on use case, not compute. Art. 25
02
FLOPs in Context — Where Banks Actually Sit
Training Compute Scale → EU AI Act Classification
Frontier GPAI (GPT-4, Claude 3+, Gemini)
10²³–10²⁴
GPAI PROVIDER
Next-Gen Frontier (GPT-5 class)
10²⁵+
SYSTEMIC RISK
Open-Source Small (Llama 3 7B)
~10²²
NEAR THRESHOLD
Bank Fine-Tuning (70B model)
10¹⁸–10²⁰
DEPLOYER ONLY
Bank Agentic Orchestration Layer
~0
SOFTWARE ONLY
Key insight: Inference FLOPs do NOT count toward classification thresholds — only training compute matters. Banks fine-tuning on commercial models are deployers. But 70%+ of banking agentic use cases fall into high-risk by function, regardless of compute. Recital 98
03
GPAI Provider Obligations — Live from Aug 2, 2025
All GPAI Providers — ≥ 10²³ FLOPs Art. 53
Standard Obligations
01
Technical Documentation
Maintain and update detailed model documentation per Annex XI. Must be available to the AI Office on request. Art. 53(1)(a), Annex XI
02
Training Data Summary
Publicly publish a summary of training data. Mandatory Commission template issued July 24, 2025. Art. 53(1)(d)
03
Copyright Compliance Policy
Demonstrate adherence to EU Copyright Directive — including text and data mining opt-outs. Art. 53(1)(c), Dir. 2019/790
04
Downstream Transparency
Share capability, limitation, and risk information with all downstream integrators building on the model. Art. 53(1)(b)
Systemic Risk Only — ≥ 10²⁵ FLOPs Art. 55
Additional Systemic Obligations
▲
Notify the Commission
Must notify the EU AI Office within 2 weeks of reaching 10²⁵ FLOPs. Art. 52(1)
▲
Adversarial Testing (Red-Teaming)
Mandatory structured model evaluations including red-teaming before and after deployment. Art. 55(1)(a)
▲
Serious Incident Reporting
Report incidents causing harm, misuse at scale, or systemic failures to the EU AI Office. Art. 55(1)(c)
▲
Cybersecurity Protections
Model-level security controls against adversarial attacks, data poisoning, and model extraction. Art. 55(1)(d)
04
Voluntary Code of Practice
📜
Art. 56 · EU AI Office
Not Legally Binding — But Strategically Critical
The EU AI Office published a voluntary Code of Practice covering three chapters:
Transparency
Copyright Compliance
Safety & Security
Providers who do not join must demonstrate compliance via other means and explain to the AI Office how their alternative measures satisfy the law. Non-participation is not a safe harbour — it shifts the full burden of proof onto the provider. Art. 56(4)
05
Four-Tier Risk Classification
PROHIBITED
BANNED
Unacceptable Risk — Outright Prohibited Art. 5
Social scoring systems · Real-time biometric surveillance in public spaces · Subliminal or manipulative techniques · Exploiting vulnerable groups · Predictive policing based on personal characteristics
No Exceptions
Active from Feb 2025
€35M
or 7%
global turnover
whichever higher
Art. 99(3)
HIGH
RISK
High Risk — Strict Controls Required Art. 6, Annex III
Credit scoring · KYC / AML · Loan approvals · Fraud detection · Recruitment & HR · Law enforcement · Critical infrastructure · Education assessment · Border control
Conformity Assessment
Human Oversight
Audit Logs
Bias Testing
FRIA
EU DB Registration
€15M
or 3%
global turnover
whichever higher
Art. 99(4)
LIMITED
RISK
Limited Risk — Transparency Obligations Art. 50
Customer service chatbots · Deepfakes and synthetic media · Emotion recognition systems · AI-generated content. Must disclose AI nature — users must know they interact with AI.
Disclose AI Nature
Label Synthetic Content
€7.5M
or 1%
global turnover
whichever higher
Art. 99(5)
MINIMAL
RISK
Minimal Risk — Voluntary Code Only Recital 48
Spam filters · AI in video games · Productivity assistants · Internal staff tools (e.g. Wells Fargo's 35,000-banker assistant). No mandatory obligations — voluntary Code of Practice encouraged.
No Mandatory Rules
Voluntary Good Practice
06
Penalty Structure — Enforcement from Aug 2, 2026
€35,000,000
— or —
7%
of global annual turnover
PROHIBITED PRACTICES
Whichever is higher Art. 99(3)
€15,000,000
— or —
3%
of global annual turnover
HIGH-RISK AI VIOLATIONS
Whichever is higher Art. 99(4)
€7,500,000
— or —
1%
of global annual turnover
FALSE INFORMATION
Whichever is higher Art. 99(5)
07
Agentic AI in Banking — Risk by Use Case
Use Case → Risk Classification
🏦Credit Scoring / Loan Approval AgentHIGH RISK
🔍KYC / AML Compliance AgentHIGH RISK
🚨Fraud Detection & Account FreezeHIGH RISK
📈Trading / Portfolio Rebalancing AgentHIGH RISK
💬Customer Service ChatbotLIMITED RISK
🖥️Internal Banker Productivity ToolMINIMAL RISK
GDPR Collision — Art. 22 GDPR
Mandatory Human Gate
Any automated decision with a "legal or significant effect" on a customer — credit approval, fraud freeze, KYC rejection — requires a mandatory human review step before execution. Agents cannot be the final decision-maker. GDPR Art. 22
Unresolved Grey Zone
Substantial Modification
Does fine-tuning a GPAI model make a bank a provider? Does wrapping it in an agentic framework count as substantial modification? No clean answer yet — legal interpretation actively evolving. Art. 25(1)(b)
AUG 2024
EU AI Act enters into force. 24-month main transition begins. Art. 113
FEB 2025
Prohibited practices rules activate. Social scoring and real-time biometric surveillance banned. Art. 5
⬤ AUG 2, 2025
GPAI obligations LIVE. Training data, documentation, copyright, downstream transparency all required now. Art. 53, 55
AUG 2026
Full enforcement powers. EU AI Office can issue fines. High-risk AI rules fully enforceable. Art. 99
AUG 2027
Pre-existing models (before Aug 2025) must comply fully. No legacy exemptions remain. Art. 111
09
Compliance Architecture — 5 Pillars
01
🏛️
Governance & Accountability
Rebuild Three Lines of Defence for AI. Appoint a Chief AI Risk Officer. Every agent must have a named human accountable owner. Maintain a living AI Register — inventory of all deployed agents with risk tier, oversight model, and review cycle.
AI RegisterCAIRO3LoD
02
👁️
Tiered Human Oversight
Tier 1 low-risk → full agent autonomy. Tier 2 moderate-risk → agent recommends, human approves. Tier 3 high-risk (credit, KYC, fraud) → agent analyses, human decides. GDPR Art. 22 gate on every legally significant output. Art. 14
HITLArt. 22 Gate
03
📋
Audit Trails & Explainability
Log every reasoning chain, tool call, and data source accessed — with timestamps. Build an AI Bill of Materials (AIBOM). Attach plain-language explanations to every output touching a customer decision. Immutable, tamper-proof storage. Art. 12
AIBOMReasoning Logs
04
🌍
Data Sovereignty & Tool Governance
Approved Tool Registry — agents may only invoke pre-vetted, GDPR-compliant APIs (no runtime tool discovery). EU data residency routing: EU customer data stays on EU-hosted services. Track the legal basis for every customer data access event. GDPR Art. 5, 6
Tool RegistryData Residency
05
⚖️
Pre-Deployment Risk Gate
Every agentic use case must pass a risk gate before go-live. Credit, fraud, KYC, or hiring → HIGH RISK: mandatory conformity assessment, bias testing, Fundamental Rights Impact Assessment (FRIA), named human owner, and EU database registration. Art. 9, 43
FRIAConformity Assessment
✦ iPRODECISIONS · AI ADVISORY
Ready to Navigate the
EU AI Act?
One precision session with Kishor Akshinthala gives you a clear, actionable EU AI Act compliance roadmap tailored to your agentic AI deployments and risk profile.
Risk Classification Audit
Compliance Architecture Blueprint
Agentic AI Governance Framework
Regulatory Timeline Mapping
100% Satisfaction Guarantee
📅 Schedule Your AI Strategy Session →
One hour. Precision answers. Actionable roadmap. · iprodecisions.com
REF
Regulatory Sources & Key References
📚 Primary Regulatory Sources
EU AI Act — Primary Legislation
GPAI Specific Articles
High-Risk AI & Governance Articles
GDPR & Related Legislation
EU AI Office & Official Guidance