The emergence of ChatGPT highlighted the limitations of a use-based regulatory model underpinning the EU AI Act, prompting lawmakers to introduce new provisions specifically targeting general-purpose AI (GPAI) systems. This evolution demonstrates the Act’s capacity for adjustment rather than regulatory failure.
- EU AI Act shifted from application-based rules to include general-purpose AI model regulation
- Tiered obligations introduced for GPAI providers with stricter rules on higher-risk models
- Voluntary Code of Practice enables agile updates without changing primary law
What happened
The EU AI Act, originally designed to regulate AI based on usage risks rather than the underlying technology, encountered challenges as general-purpose AI models like ChatGPT gained prominence. These models power diverse applications simultaneously, making their risks harder to evaluate through the initial use-case framework alone.
In response, EU institutions expanded their approach between 2021 and 2023. Early warnings about these gaps surfaced during the 2021 public consultation. Subsequent political discussions culminated in a new layered regulatory regime for general-purpose AI, assigning baseline duties to all providers and enhanced obligations for those managing models deemed to carry systemic risks.
Why it matters
The adjustment of the AI Act highlights the importance of adaptive regulation in the rapidly evolving AI landscape. Instead of being frozen in place by new technological realities, the legislation has evolved to cover the unique challenges posed by multipurpose AI models that power a wide spectrum of services, ensuring that regulatory oversight remains relevant and effective.
Furthermore, this approach balances safety and innovation by differentiating between open-source providers and commercial model owners, applying proportionate safeguards while supporting transparency. The inclusion of a voluntary Code of Practice also provides a dynamic mechanism to update compliance measures without requiring legislative revisions, demonstrating a novel way to manage complex emerging technologies.
What to watch next
With the GPAI-specific obligations in force since August 2025, the upcoming period will reveal how well providers comply with documentation, transparency, and risk mitigation requirements. Regulators and stakeholders will closely monitor whether the layered regime effectively addresses systemic risks without unduly hindering innovation or access, especially for open-source models.
Attention will also focus on the voluntary Code of Practice established in mid-2025 as a flexible compliance tool. Its adoption and evolution will serve as a test case for how voluntary standards can complement primary legislation in overseeing complex AI systems, potentially influencing regulatory frameworks globally.