GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-047 General-Purpose Model Documentation and Downstream Information

Tier 2+AIGeneral-purpose modelGPAI Model Provider

Description

Model documentation exists for each general-purpose AI model before it is placed on the market and its current version corresponds to the version on the market. The documentation holds the elements the applicable regulation lists for authorities, at minimum the training process and methodology, the data used with how it was obtained, selected and cleaned, the compute and energy consumed in training, the evaluation methods and results and the model's capabilities and limitations, and the elements listed for downstream providers, at minimum what an integrator needs to understand the model's capabilities and limitations and to meet its own obligations. Previous versions are retained for the period the regulation sets. A published contact route lets the AI Office, national competent authorities and downstream providers request the documentation, each request and what was provided is recorded, and the documentation is under version and integrity control.

Rationale

The two audiences have different rights: an authority may ask for the full Annex XI file, a downstream provider is owed the Annex XII information and nothing that discloses trade secrets. Keeping one document with an audience marker per element, which is how the Code of Practice's Model Documentation Form is laid out, is simpler than two documents that drift. The compute and energy figures are the element most often missing because nobody owns them at training time; record them from the training run rather than reconstructing them later. Art.53(2) relieves a model released under a free and open-source licence of the documentation duties in Art.53(1)(a) and (b) unless the model carries systemic risk; where that relief is relied on the inventory entry (AIG-003) records it. Boundary with AIG-015: that control documents a system, this one documents a model, and a model served inside the organisation's own product carries both. Boundary with AIG-034: that control is what a customer deploying a system receives; a downstream provider building on the model receives the information here. gpai-provider seat (ADR-031).

Applicability (9 profiles)

SaaS AI Providerstablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

Enterprise AI Deployerstablenot-applicableout of scope

A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.

GPAI Model Providerstablerequiredrole duty

Art.53(1)(a) and (b): the model documentation and the downstream information, for every general-purpose model placed on the market. Art.53(2) relieves a free and open-source model without systemic risk of both; the relief is recorded against the inventory entry.

High-Risk Provider (EU)stablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

Public Body Deployer (EU)stablenot-applicableout of scope

A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.

Data Act Cloud Provider (EU)stablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

DORA ICT Provider (EU)stablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

HIPAA Business Associate (US)stablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

NIS2 Cloud Provider (EU)stablenot-applicableout of scope

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

Framework Mappings (7)

MDS-04Model Documentation Requirementsinformative
EU-AI-Art.53.1GPAI Model Obligations — Technical Documentationfull
EU-AI-Art.53.2GPAI Model Obligations — Downstream Provider Informationfull
COP-T-1Documentationfull
COP-T-1.1Drawing up and keeping up-to-date model documentationfull
COP-T-1.2Providing relevant informationfull
COP-T-1.3Ensuring quality, integrity, and security of informationfull

Evidence (2)

recorddocumentmanual

The model documentation for a named general-purpose model, with an audience marker on each element and a version that matches the model on the market.

Example: Model Documentation Form, Aurora-2 v2.3, revision 7 of 18 August 2026, audience markers per element, previous six revisions in the archive.

Test: Verify: (1) the documentation version corresponds to the model version on the market, checked against the model registry, (2) every element the regulation lists for authorities is present, including the training compute and energy figures with the run they were taken from, (3) every element listed for downstream providers is present and marked for that audience, (4) previous versions are retrievable for the period the regulation sets, (5) the document is under version control with an integrity check and a change record, (6) a sample element changed in the last release carries the update in the current version.

recorddocumentmanual

The published contact route and the register of documentation requests from the AI Office, national competent authorities and downstream providers, with what was provided to each.

Example: Documentation request register 2026, exported 1 September 2026, nine requests from four downstream providers and one from the AI Office.

Test: Verify: (1) the contact route is published where the model is offered and reaches a named owner, (2) each request in the register names the requester, its audience, the date received, the date answered and the elements provided, (3) a request from a downstream provider was answered with the downstream elements and nothing marked for authorities only, (4) a request from an authority was answered within the period the request set, (5) where no request arrived in the period, a record states that and a test of the route was performed and dated instead.

Questions (3)

boolean

Does documentation exist for each general-purpose model you place on the market, at the version that is on the market?

Answer for the model as such, not for a product built on it; the product's technical documentation is AIG-015. A model released under a free and open-source licence without systemic risk may rely on the Art.53(2) relief, in which case answer no and record the relief against the inventory entry.

multi

Which of the following does the model documentation hold?

Training process and methodologyThe data used, with how it was obtained, selected and cleanedCompute and energy consumed in trainingEvaluation methods and resultsCapabilities and limitationsThe elements a downstream provider needs, marked for that audiencePrevious versions retained for the period the regulation setsNone of the above

Options follow the order of the elements the regulation lists. Compute and energy is the one most often missing; it counts only when taken from the training run, not estimated afterwards.

select

How can the AI Office and downstream providers request the documentation?

A published contact route reaching a named owner, with every request and response recordedA published contact route, requests handled without a registerOn request through account or sales channelsNo route is published

Options run from the fullest arrangement to none. The register is what shows the route working; a route nobody has used is the second option until a test of it is recorded.