GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GPAI Model Provider

stable gpai-model-provider · v1.1

A provider that places a general-purpose AI model on the market and carries the Chapter V duties that come with it: model documentation and downstream information, a copyright policy and rights reservation compliance, the public summary of training content and, once a model is designated as carrying systemic risk, a systemic risk framework and acceptance determination, evaluation under standardised protocols, protection of the model weights and infrastructure and serious incident reporting to the AI Office, with the Safety and Security Model Report recommended. The statement is seeded from saas-ai-provider because an organisation that trains and offers a model runs the same security, privacy and governance programme, and re-judged where the seat differs: the high-risk conformity rows are out of scope for a model as such and the Art.54 authorised representative arm is conditional on establishment outside the Union. A provider that also serves its model through a product holds the provider role and saas-ai-provider alongside this profile (ADR-046).

Roles
GPAI Model Provider
Deployment models
Cloud, multi-tenant SaaSCloud, single tenantOn premisesHybridEdgeOn deviceEmbeddedAir gapped
Risk classes
gpaigpai-systemic
Jurisdictions
EU
Frameworks
SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGPAI-COPGDPR

Applicability statement

201 controls Download CSV
required 178 controls In scope for this profile. The control has to be in place and evidenced.

GOV · Governance & Risk

The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.

AIG · AI Governance

The inventory holds each model with its designation status. The Art.52(1) notification to the Commission within two weeks of meeting the systemic-risk threshold is the threshold notification clause of this control.

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Art.5 binds every provider, whatever the risk class of its other systems.

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

The statement on customer data in training and the opt-out are the provider's to give.

Art.53(3) puts a cooperation duty on a general-purpose model provider: responding to information requests and taking part in an authority-led investigation. The request register here serves it; the mapping note records that the investigation half is not written into the control.

Art.53(1)(a) and (b): the model documentation and the downstream information, for every general-purpose model placed on the market. Art.53(2) relieves a free and open-source model without systemic risk of both; the relief is recorded against the inventory entry.

Art.53(1)(d): the public summary of training content, for every general-purpose model, with no open-source relief.

Art.53(1)(c): the copyright policy and rights reservation compliance, for every general-purpose model, with no open-source relief.

The training pipeline is the model providers own system.

Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).

conditional 17 controls In scope when the stated condition holds. Read the condition before deciding.

DAT · Data Protection

Condition: deployment_model in cloud-saas, cloud-single-tenant

Customer-held keys are a commitment of a hosted service. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

Location transparency is a commitment of a hosted service to its tenants. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

Export and portability are commitments of a hosted service to its tenants. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

Exit is executed by the provider on the customer's behalf, because the customer cannot run the transition on infrastructure it does not control. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

INF · Infrastructure & Cloud Security

Condition: deployment_model in cloud-saas, cloud-single-tenant

Tenant isolation exists because the product is cloud-hosted and shared. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

MON · Monitoring & Logging

Condition: deployment_model in cloud-saas, cloud-single-tenant

The service level objective and the status channel are commitments of a hosted service. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

VND · Vendor & Third-Party Risk

Condition: deployment_model in cloud-saas, cloud-single-tenant

The shared responsibility matrix exists because the customer's workload runs on the provider's service. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

Requests for customer data reach the provider because it hosts the tenant's data. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

A hosted service has customers whose data it holds, so the terms on which a customer leaves and the terms a regulation makes compulsory for that data are commitments of the service rather than internal practice. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

Condition: deployment_model in cloud-saas, cloud-single-tenant

The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).

AIG · AI Governance

Condition: ai_risk_class in gpai, gpai-systemic and the organisation is established outside the Union

Art.54 binds a general-purpose model provider established outside the Union to appoint an authorised representative before placing the model on the market; the Art.22 arm for high-risk systems belongs to the provider seat.

Condition: ai_risk_class in gpai-systemic

Art.55(1)(b) binds the provider of a model designated as carrying systemic risk.

Condition: ai_risk_class in gpai-systemic

Art.55(1)(a) binds the provider of a model designated as carrying systemic risk.

Condition: ai_risk_class in gpai-systemic

Art.55(1)(d) binds the provider of a model designated as carrying systemic risk.

Condition: ai_risk_class in gpai-systemic

Art.55(1)(c) binds the provider of a model designated as carrying systemic risk.

recommended 1 controls Good practice for this profile, not a duty it carries.

AIG · AI Governance

The Safety and Security Model Report is a Code of Practice measure and the Code is a voluntary route to demonstrating Art.55 compliance (ADR-038, ADR-046 decision 4). Recommended for a provider of a model designated as carrying systemic risk; a provider that does not adhere to the Code records how it demonstrates Art.55 compliance instead.

not-applicable 5 controls Out of scope for this profile. It is stated rather than omitted so the exclusion is auditable.

AIG · AI Governance

A general-purpose model is not a high-risk system; the conformity duties attach to the provider seat where the organisation also places a high-risk system on the market (saas-ai-provider, high-risk-provider-eu).

A general-purpose model is not a high-risk system; the conformity duties attach to the provider seat where the organisation also places a high-risk system on the market (saas-ai-provider, high-risk-provider-eu).

Deployer-seat duty (enterprise-ai-deployer).

Deployer-seat duty (enterprise-ai-deployer).

Deployer-seat duty (enterprise-ai-deployer).

Published 2026-09-15