Article 53

EU AI Act Article 53 — General-Purpose AI Model Provider Obligations

Article 53 of Regulation (EU) 2024/1689 sets obligations on providers of general-purpose AI (GPAI) models: technical documentation per Annex XI, downstream provider information, training-data summary, copyright policy.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 53 actually requires

Article 53 of Regulation (EU) 2024/1689 sets obligations on providers of general-purpose AI (GPAI) models — models trained with large amounts of data using self-supervision at scale that display significant generality and are capable of competently performing a wide range of distinct tasks.

GPAI providers must:

  • (a) Draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, with at minimum the elements set out in Annex XI, to be provided on request to the AI Office and national competent authorities.
  • (b) Draw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the GPAI model into their AI systems, with at minimum the elements in Annex XII.
  • (c) Put in place a policy to comply with Union law on copyright and related rights, including identifying and complying with reservations of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790.
  • (d) Draw up and make publicly available a sufficiently detailed summary about the content used for training of the GPAI model, according to a template provided by the AI Office.

Open-source carve-out — Article 53(2)

Article 53(2) provides that obligations (a) and (b) do not apply to providers of AI models released under a free and open-source licence that allows access, use, modification and distribution of the model, and whose parameters, including weights, model architecture and information on model usage, are made publicly available — unless the model is a systemic-risk GPAI under Article 55.

Obligations (c) and (d) — copyright policy and training-data summary — apply regardless of open-source status.

Who is covered

Providers of GPAI models, defined in Article 3(63) — the entity that develops a GPAI model or has it developed and places it on the market under its own name or trademark. Downstream AI system providers integrating GPAI models keep their full Article 11 obligations.

What to do

  • For closed GPAI models: produce the Annex XI documentation and the Annex XII downstream-provider documentation. The AI Office is publishing templates.
  • For open-source GPAI models with publicly-available weights: Article 53(2) carve-out applies for (a)+(b); (c)+(d) still apply.
  • Set a copyright-compliance policy that handles Article 4(3) Directive (EU) 2019/790 opt-outs at the data-acquisition stage.
  • Publish the training-data summary using the AI Office template (when published).

Inline crosswalk

  • ISO/IEC 42001:2023 Annex A.6.2 — Lifecycle documentation (mirrors Annex XI).
  • NIST AI RMF MAP 4.1 — Documentation includes purpose, intended use, users, limitations.
  • NIST AI RMF GOVERN 6.1 — Policies for third-party software and data.

Common mistakes

  • Treating open-source as a blanket exemption. Article 53(2) carve-out is partial.
  • Skipping the training-data summary because "we use a lot of public data." Article 53(1)(d) is mandatory.
  • Article 4(3) Dir (EU) 2019/790 opt-outs unhandled — reservations of rights must be respected.

Penalties

Article 101 sets fines for GPAI providers up to €15 million or 3% of worldwide annual turnover, whichever is higher.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Article 11 · Starter tier · critical

    Document training data sources and quality controls

    Article 10 data governance must be traceable in the technical file. Where did the data come from, who vetted it, what validation ran.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
art11-training-dataISO/IEC 42001:2023 Annex A.7.4 — Quality of data for AI systemsArticle 10 training-data documentation directly evidences the data-quality control objective in Annex A.7.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
art11-training-dataNIST AI RMF MAP 2.3 — Scientific integrity and TEVV considerations are identified and documented, including data and modeling approachDocumenting training-data sources, quality controls and TEVV is the substance of MAP 2.3.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.