By role · General-purpose AI model provider
AI regulation for general-purpose and foundation model providers
Providers of general-purpose AI models face a distinct set of duties: technical documentation for downstream integrators, a copyright policy and training-data summary, and for the most capable models, evaluation, adversarial testing, incident reporting and cybersecurity. These duties sit with the model provider even when the model is used inside someone else's system.
- Jurisdictions
- 4
- Evidence items
- 31
Model duties versus system duties
A model is not a system. The model provider documents the model and its training; the system provider who builds on it documents the system. Both chains of documentation have to exist and reference each other, which is why downstream documentation is a control of its own below.
Systemic-risk tiers
Where an instrument defines a higher tier by capability or compute, the duties step up to evaluation, red-teaming, incident reporting and security. The controls for those duties are listed with the risk areas they address, so the evaluation report and the incident record can be planned together.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| Frontier model safety and security framework Policy | 5 | 4 | Head of AI safety · annual |
| AI incident management and regulatory reporting Process | 3 | 3 | Incident coordinator · continuous |
| Technical documentation, model cards and instructions for use Process | 3 | 1 | Product or model owner · at launch and on material change |
| Contractual allocation of AI duties across the supply chain Contractual term | 2 | 0 | Legal counsel · once per ai system |
| Synthetic content labelling and provenance marking Technical measure | 2 | 0 | Engineering lead · continuous |
| Adversarial and red-team testing for generative AI Technical measure | 1 | 3 | AI security or safety lead · at launch and on material change |
| Accuracy, robustness, fairness and security testing Technical measure | 1 | 1 | Quality or testing lead · at launch and on material change |
| AI governance policy and accountability structure Policy | 1 | 0 | Executive sponsor for AI · annual |
| Training-data provenance and copyright register Process | 1 | 0 | Model development lead · at launch and on material change |
| Model release and change-management gate Process | 0 | 2 | Release manager · at launch and on material change |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
California (United States) 5 duties
-
Legal requirementCalifornia SB 53 · Labor Code Section 1107 (as added by SB 53)applies from 1 Jan 2026Frontier developers must protect employees who report catastrophic-risk concerns
-
Legal requirementCalifornia SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)applies from 1 Jan 2026Frontier developers must publish a transparency report before deploying a new frontier model
-
Legal requirementCalifornia SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)applies from 1 Jan 2026Large frontier developers must publish a frontier AI framework
-
Legal requirementCalifornia SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)applies from 1 Jan 2026Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
-
Legal requirementCalifornia SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)applies from 1 Jan 2026Report critical safety incidents to the Office of Emergency Services
European Union 8 duties
-
Legal requirementEU AI Act · Articles 51, 52 and 55applies from 2 Aug 2025Manage systemic risk for high-impact general-purpose models
-
Legal requirementEU AI Act · Article 53 and Annexes XI–XIIapplies from 2 Aug 2025Meet general-purpose AI model provider obligations
-
Legal requirementEU AI Act · Article 54applies from 2 Aug 2025Non-EU providers of GPAI models must appoint an EU authorised representative
-
Legal requirementEU AI Act · Article 53(1)(a) and 53(1)(b); Annexes XI and XIIapplies from 2 Aug 2025Providers of GPAI models must maintain technical documentation and inform downstream providers
-
Legal requirementEU AI Act · Article 52(1)applies from 2 Aug 2025Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
-
Legal requirementEU AI Act · Article 50(2)applies from 2 Aug 2026Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
-
Legal requirementEU AI Act · Article 55(1)(d)applies from 2 Aug 2025Providers of systemic-risk GPAI models must secure the model and its infrastructure
-
Legal requirementEU AI Act · Article 55(1)(c)applies from 2 Aug 2025Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
Singapore 1 duty
-
VoluntarySingapore Model AI Governance Framework · Generative AI framework, dimensions on incident reporting and content provenanceReport incidents and mark AI-generated content (generative AI framework)
South Korea 2 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 36applies from 22 Jan 2026Foreign AI business operators above the threshold must designate a domestic representative in Korea
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 32applies from 22 Jan 2026Operators of AI above the compute threshold must run lifecycle risk management and report safety results
What evidence would a reviewer expect?
- AI customer or deployer clause set Contract clause or supplier term
- AI governance forum minutes Governance meeting record
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI policy Policy document
- AI responsibility map Register entry
- AI supplier clause set Contract clause or supplier term
- Adversarial findings tracker Risk register
- Board or executive approval of the AI policy Approval or sign-off record
- Content labelling and provenance standard Procedure or standard operating process
- Contract clause index against the AI register Register entry
- Copyright and rights-reservation policy Policy document
- Dangerous-capability evaluation report Evaluation or test report
- Incident report to an authority Regulatory filing or notification
- Instructions for use Disclosure or notice
- Model card or deployer information pack Model documentation
- Pre-release test report Evaluation or test report
- Public summary of training content Disclosure or notice
- Published frontier safety framework Policy document
- Red-team exercise report Evaluation or test report
- Red-team rules of engagement and scenario library Procedure or standard operating process
- Release and change-classification procedure Procedure or standard operating process
- Release or change approval record Approval or sign-off record
- Release test sign-off Approval or sign-off record
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Threshold notification to an authority Regulatory filing or notification
- Training compute tracking record Register entry
- Training source register Register entry
- Visible AI-generated content label Disclosure or notice
- Watermark and provenance robustness test Evaluation or test report
Latest changes to these instruments
California SB 53 frontier-model transparency duties become operative
European Commission proposes Digital Omnibus adjustments to AI Act timelines
California enacts the Transparency in Frontier Artificial Intelligence Act (SB 53)
EU AI Act general-purpose AI, governance and penalty provisions start to apply
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Are open-weight models exempt?
- Partly, in some instruments: openly released models can be relieved of some documentation duties but not of copyright or, where it applies, systemic-risk duties. Check the exemption clause cited on the duty page.
- Which evidence matters most?
- The model documentation for downstream users, the training-data summary and copyright policy, and for higher tiers the evaluation and adversarial-testing reports and the incident log.