General-Purpose AI Model Provider Compliance Kit
In brief
The General-Purpose AI Model Provider Compliance Kit is a free XLSX and DOCX kit for EU AI Act. For providers of general-purpose AI models: every recorded GPAI provider duty as a checklist, the information pack for downstream providers, a training-content summary worksheet and the systemic-risk sections. It is written for general-purpose ai model provider and provider / developer.
- Format
- XLSX and DOCX · Kit
- Version
- v2, built 6 Oct 2026
- Duties cited
- 10 from 5 instruments
- Rows from the records
- 42
- Frameworks
- EU AI Act
- Written for
- General-purpose AI model provider, Provider / developer
- Price and licence
- Free · CC BY 4.0
What's inside
- Provider checklist: every recorded duty of GPAI model providers, with status and evidence
- Downstream information sheet: ten items downstream providers need
- Training content summary worksheet
- Document: copyright policy, systemic-risk assessment and incident sections
Preview
The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Provider checklist
| Duty | Instrument | Reference | Systemic-risk models only ▾ | Status ▾ | Owner | Evidence link | Record |
|---|---|---|---|---|---|---|---|
| Large frontier developers must publish a frontier AI framework | California SB 53 | Business and Professions Code, Chapter 25.1 (as added by SB 53) | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | ||||
| Report critical safety incidents to the Office of Emergency Services | California SB 53 | Business and Professions Code, Chapter 25.1 (as added by SB 53) | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | ||||
| Frontier developers must publish a transparency report before deploying a new frontier model | California SB 53 | Business and Professions Code Section 22757.12 (as added by SB 53) | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report | ||||
| Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state | California SB 53 | Business and Professions Code Section 22757.12 (as added by SB 53) | https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries | ||||
| Frontier developers must protect employees who report catastrophic-risk concerns | California SB 53 | Labor Code Section 1107 (as added by SB 53) | https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections | ||||
| Meet general-purpose AI model provider obligations | EU AI Act | Article 53 and Annexes XI–XII | https://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations |
Every recorded duty of general-purpose AI model providers. Mark the ones that apply only to models with systemic risk from each record.
Sheet: Downstream information
| Information item | What we provide | Where downstream providers find it | Last updated |
|---|---|---|---|
| Model name, version and release date | |||
| Tasks the model is intended for, and uses it should not be put to | |||
| Acceptable use policy | |||
| Architecture and number of parameters | |||
| Input and output modalities and formats | |||
| Licence |
What downstream providers building on the model need in order to understand it and meet their own duties. Keep it current with each release.
Sheet: Training content summary
| Data source or category | Kind ▾ | Collection period | Approximate share | Rights reservations respected and how | Notes |
|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||
A working sheet for the public summary of training content and for the copyright policy. Use the official template where an authority publishes one.
Sheet: GPAI provider duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Large frontier developers must publish a frontier AI framework | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, | Published frontier AI framework | GOVERN 1.x; NIST AI 600-1 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | |
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Frontier developers must publish a transparency report before deploying a new frontier model | Transparency and disclosure | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websi | Published model transparency report; Redaction justification log | Annex A.8.2, A.8.3 | GOVERN 4.2, MAP 5.1, MEASURE 2.6 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report |
| Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment | Internal-use catastrophic risk assessment summary sent to the Office of Emergency Services | Clause 9.1; Annex A.8.3 | MEASURE 2.6, MANAGE 1.2, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries |
| Frontier developers must protect employees who report catastrophic-risk concerns | Governance and accountability | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Labor Code Section 1107 (as added by SB 53) | 2026-01-01 | A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal | Whistleblower policy and employee notice; Anonymous reporting channel records | Clause 5.1, 7.4; Annex A.3.2 | GOVERN 4.1, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections |
| Meet general-purpose AI model provider obligations | Copyright and training-data transparency | EU AI Act | European Union | General-purpose AI model provider | Legal requirement | Article 53 and Annexes XI–XII | 2025-08-02 | Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XI | Public summary of training content; Copyright compliance policy | Annex A controls on data provenance and documentation | NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations |
Document outline (DOCX)
- General-purpose AI model provider compliance kit
- Copyright policy
- Systemic-risk assessment
- Serious incidents
- Duties on record
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Frontier developers must publish a transparency report before deploying a new frontier model
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Frontier developers must protect employees who report catastrophic-risk concerns
- Meet general-purpose AI model provider obligations
- Manage systemic risk for high-impact general-purpose models
- Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Providers of GPAI models must maintain technical documentation and inform downstream providers
- Non-EU providers of GPAI models must appoint an EU authorised representative
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Providers of systemic-risk GPAI models must secure the model and its infrastructure
- Report incidents and mark AI-generated content (generative AI framework)
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Foreign AI business operators above the threshold must designate a domestic representative in Korea
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Downstream information" and "Training content summary" sheets for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Provider checklist", "Downstream information" and "GPAI provider duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (General-purpose AI model provider compliance kit, Duties on record) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (10)
Each is cited in the file with its source reference and a link back to the record.
- Large frontier developers must publish a frontier AI framework
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Developers must supply deployers with documentation of the technology
- Draw up technical documentation before placing a high-risk system on the market
- Meet general-purpose AI model provider obligations
- Manage systemic risk for high-impact general-purpose models
- Providers must document and register a conclusion that an Annex III system is not high-risk
- Providers of GPAI models must maintain technical documentation and inform downstream providers
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results
- Measure and test trustworthiness characteristics (Measure)
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v2 | 9710140e23e4 | Dataset c6967b988bb5 → 9710140e23e4. | |
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the General-Purpose AI Model Provider Compliance Kit?
Provider checklist: every recorded duty of GPAI model providers, with status and evidence. Downstream information sheet: ten items downstream providers need. Training content summary worksheet. Document: copyright policy, systemic-risk assessment and incident sections.
Which duties does it cite?
10 recorded duties from California SB 53, Colorado ADMT law (SB 26-189), EU AI Act and Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, including Business and Professions Code, Chapter 25.1 (as added by SB 53), Business and Professions Code Section 22757.12 (as added by SB 53), Article 11 and Annex IV, Article 53 and Annexes XI–XII, Articles 51, 52 and 55 and Article 6(4); Article 49(2). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on general-purpose ai model provider and provider / developer. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.