AIPolicyTracker
KitFree · sent to your work emailEU AI Act

General-Purpose AI Model Provider Compliance Kit

Formats: XLSX and DOCX · Version v2 · Built from dataset 9710140e23e4 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The General-Purpose AI Model Provider Compliance Kit is a free XLSX and DOCX kit for EU AI Act. For providers of general-purpose AI models: every recorded GPAI provider duty as a checklist, the information pack for downstream providers, a training-content summary worksheet and the systemic-risk sections. It is written for general-purpose ai model provider and provider / developer.

Format
XLSX and DOCX · Kit
Version
v2, built 6 Oct 2026
Duties cited
10 from 5 instruments
Rows from the records
42
Frameworks
EU AI Act
Written for
General-purpose AI model provider, Provider / developer
Price and licence
Free · CC BY 4.0

What's inside

  • Provider checklist: every recorded duty of GPAI model providers, with status and evidence
  • Downstream information sheet: ten items downstream providers need
  • Training content summary worksheet
  • Document: copyright policy, systemic-risk assessment and incident sections

Preview

The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Provider checklist · 8 columns · 16 rows from the records
First rows of the Provider checklist sheet
DutyInstrumentReferenceSystemic-risk models only ▾Status ▾OwnerEvidence linkRecord
Large frontier developers must publish a frontier AI frameworkCalifornia SB 53Business and Professions Code, Chapter 25.1 (as added by SB 53)https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
Report critical safety incidents to the Office of Emergency ServicesCalifornia SB 53Business and Professions Code, Chapter 25.1 (as added by SB 53)https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Frontier developers must publish a transparency report before deploying a new frontier modelCalifornia SB 53Business and Professions Code Section 22757.12 (as added by SB 53)https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the stateCalifornia SB 53Business and Professions Code Section 22757.12 (as added by SB 53)https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries
Frontier developers must protect employees who report catastrophic-risk concernsCalifornia SB 53Labor Code Section 1107 (as added by SB 53)https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
Meet general-purpose AI model provider obligationsEU AI ActArticle 53 and Annexes XI–XIIhttps://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations

Every recorded duty of general-purpose AI model providers. Mark the ones that apply only to models with systemic risk from each record.

Sheet: Downstream information · 4 columns · 10 rows from the records
First rows of the Downstream information sheet
Information itemWhat we provideWhere downstream providers find itLast updated
Model name, version and release date
Tasks the model is intended for, and uses it should not be put to
Acceptable use policy
Architecture and number of parameters
Input and output modalities and formats
Licence

What downstream providers building on the model need in order to understand it and meet their own duties. Keep it current with each release.

Sheet: Training content summary · 6 columns · blank, 40 rows ready to fill
First rows of the Training content summary sheet
Data source or categoryKind ▾Collection periodApproximate shareRights reservations respected and howNotes
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

A working sheet for the public summary of training content and for the copyright policy. Use the official template where an authority publishes one.

Sheet: GPAI provider duties · 14 columns · 16 rows from the records
First rows of the GPAI provider duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Large frontier developers must publish a frontier AI frameworkSafety testing and evaluationCalifornia SB 53California (United States)General-purpose AI model providerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, Published frontier AI frameworkGOVERN 1.x; NIST AI 600-1Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
Report critical safety incidents to the Office of Emergency ServicesIncident reporting and handlingCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and thIncident classification and reporting procedureMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Frontier developers must publish a transparency report before deploying a new frontier modelTransparency and disclosureCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websiPublished model transparency report; Redaction justification logAnnex A.8.2, A.8.3GOVERN 4.2, MAP 5.1, MEASURE 2.6Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report
Large frontier developers must send periodic summaries of catastrophic-risk assessments to the stateSafety testing and evaluationCalifornia SB 53California (United States)General-purpose AI model providerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment Internal-use catastrophic risk assessment summary sent to the Office of Emergency ServicesClause 9.1; Annex A.8.3MEASURE 2.6, MANAGE 1.2, GOVERN 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries
Frontier developers must protect employees who report catastrophic-risk concernsGovernance and accountabilityCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementLabor Code Section 1107 (as added by SB 53)2026-01-01A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal Whistleblower policy and employee notice; Anonymous reporting channel recordsClause 5.1, 7.4; Annex A.3.2GOVERN 4.1, GOVERN 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
Meet general-purpose AI model provider obligationsCopyright and training-data transparencyEU AI ActEuropean UnionGeneral-purpose AI model providerLegal requirementArticle 53 and Annexes XI–XII2025-08-02Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XIPublic summary of training content; Copyright compliance policyAnnex A controls on data provenance and documentationNIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risksSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations

Document outline (DOCX)

  1. General-purpose AI model provider compliance kit
  2. Copyright policy
  3. Systemic-risk assessment
  4. Serious incidents
  5. Duties on record
  6. Large frontier developers must publish a frontier AI framework
  7. Report critical safety incidents to the Office of Emergency Services
  8. Frontier developers must publish a transparency report before deploying a new frontier model
  9. Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
  10. Frontier developers must protect employees who report catastrophic-risk concerns
  11. Meet general-purpose AI model provider obligations
  12. Manage systemic risk for high-impact general-purpose models
  13. Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
  14. Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
  15. Providers of GPAI models must maintain technical documentation and inform downstream providers
  16. Non-EU providers of GPAI models must appoint an EU authorised representative
  17. Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
  18. Providers of systemic-risk GPAI models must secure the model and its infrastructure
  19. Report incidents and mark AI-generated content (generative AI framework)
  20. Operators of AI above the compute threshold must run lifecycle risk management and report safety results
  21. Foreign AI business operators above the threshold must designate a domestic representative in Korea

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Downstream information" and "Training content summary" sheets for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Provider checklist", "Downstream information" and "GPAI provider duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (General-purpose AI model provider compliance kit, Duties on record) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (10)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of General-Purpose AI Model Provider Compliance Kit
VersionBuiltDatasetWhat changed
v29710140e23e4Dataset c6967b988bb5 → 9710140e23e4.
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the General-Purpose AI Model Provider Compliance Kit?

Provider checklist: every recorded duty of GPAI model providers, with status and evidence. Downstream information sheet: ten items downstream providers need. Training content summary worksheet. Document: copyright policy, systemic-risk assessment and incident sections.

Which duties does it cite?

10 recorded duties from California SB 53, Colorado ADMT law (SB 26-189), EU AI Act and Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, including Business and Professions Code, Chapter 25.1 (as added by SB 53), Business and Professions Code Section 22757.12 (as added by SB 53), Article 11 and Annex IV, Article 53 and Annexes XI–XII, Articles 51, 52 and 55 and Article 6(4); Article 49(2). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on general-purpose ai model provider and provider / developer. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.