Skip to content

GPAI Technical Documentation: What Article 53 Actually Requires

10 min read · updated August 11, 2026

Article 53 is usually summarised as “GPAI providers must keep technical documentation”. It requires two separate documents with different contents, different audiences and different confidentiality positions, and the split is the most practically important thing in the article.

One article, two documentation packs

Article 53(1) of Regulation (EU) 2024/1689 imposes four obligations on providers of general-purpose AI models. The first two are both documentation, and they are not the same document:

  • 53(1)(a) — draw up and keep up to date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at a minimum the information in Annex XI, for the purpose of providing it on request to the AI Office and to national competent authorities.
  • 53(1)(b) — draw up, keep up to date and make available information and documentation to providers of AI systems who intend to integrate the model into their systems, containing at a minimum the elements in Annex XII.
  • 53(1)(c) — put in place a policy to comply with Union copyright law, in particular to identify and comply with a reservation of rights expressed under Article 4(3) of Directive (EU) 2019/790.
  • 53(1)(d) — draw up and make publicly available a sufficiently detailed summary about the content used for training, according to a template provided by the AI Office.

Note the different verbs. The Annex XI pack is held and produced on request; the Annex XII pack is actively made available to integrators; the training content summary is published. Three different disclosure postures in one paragraph. See the copyright policy obligation and the training content summary.

Not legal advice, and the practical content of these obligations is still settling: Article 53(4) lets providers rely on codes of practice to demonstrate compliance until a harmonised standard is published, and the Commission published a General-Purpose AI Code of Practice in July 2025 with a model documentation form. Check the current version of that code and of the AI Office template before building to any list, including this one.

Annex XI: what the AI Office can ask for

Annex XI Section 1 applies to all GPAI providers. It asks first for a general description of the model: the tasks it is intended to perform and the type and nature of AI systems it can be integrated into; the acceptable use policies; the date of release and methods of distribution; the architecture and number of parameters; the modality and format of inputs and outputs; and the licence.

Section 1 point 2 is where it becomes demanding. It requires a detailed description of the elements above and of the development process, including:

  • the technical means required for the model to be integrated into AI systems;
  • the design specifications of the model and the training process, including training methodologies and techniques, the key design choices with their rationale and assumptions, and what the model is designed to optimise for;
  • information on the data used for training, testing and validation — type and provenance, curation methodologies such as cleaning and filtering, the number of data points, their scope and main characteristics, how the data was obtained and selected, and the measures used to detect unsuitable data sources and identifiable biases;
  • the computational resources used to train the model, for example the number of floating point operations, the training time and other relevant details;
  • the known or estimated energy consumption of the model — which, where unknown, may be based on information about the computational resources used.

Annex XI Section 2 adds further items for models classified as presenting systemic risk under Article 51 — evaluation strategies and results, including adversarial testing, and details of the system architecture and risk assessment. Article 51(2) sets a presumption of systemic risk where the cumulative compute used for training, measured in floating point operations, is greater than 1025. See the systemic risk obligations.

Annex XII: what a downstream provider gets

Annex XII is the integrator’s pack, and Article 53(1)(b) states its purpose directly: the information must enable providers of AI systems to have a good understanding of the capabilities and limitations of the model and to comply with their own obligations under the Regulation. It is expressly without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets.

Its general description overlaps with Annex XI — intended tasks, acceptable use policies, release date and distribution methods, architecture and number of parameters, modality and format of inputs and outputs, licence — and adds two items Annex XI does not have: how the model interacts, or can be used to interact, with hardware or software that is not part of the model itself, and the versions of relevant software related to its use.

Its second section requires the technical means needed to integrate the model, the modality and format of inputs and outputs and their maximum size — the context window, named in an annex to a regulation — and information on the data used for training, testing and validation including type, provenance and curation methodologies.

The difference, item by item

Reading the two annexes against each other is the fastest way to understand the policy. What the AI Office can obtain and the downstream provider cannot:

  • Training compute. The number of floating point operations and the training time appear in Annex XI and nowhere in Annex XII. This is the figure that determines systemic risk classification, and it is not owed to customers.
  • Energy consumption. Known or estimated, in Annex XI only.
  • Design rationale. The key design choices, their rationale and assumptions, and what the model optimises for are Annex XI items; Annex XII asks what the model does, not why it was built that way.
  • Data at depth. Both annexes ask about training data, but Annex XI adds the number of data points, their scope and main characteristics, how the data was obtained and selected, and the measures taken to detect unsuitable sources and identifiable biases.

And what the downstream provider gets that the annex to the AI Office does not list: the maximum input and output size, software versions, and the model’s interaction with external hardware and software. These are integration facts, useless to a regulator assessing model-level risk and essential to somebody building a product.

The design principle is legible once you see it. The AI Office pack answers “what is this model and what did it cost to make”; the downstream pack answers “what can I build with it and where will it fail”. Article 53(7) closes the loop by requiring that information obtained under the article, including trade secrets, be treated in accordance with the confidentiality obligations in Article 78.

The open-source exemption and the dates

Article 53(2) disapplies the obligations in points (a) and (b) — both documentation packs — for providers of AI models released under a free and open-source licence that allows access, usage, modification and distribution, and whose parameters, including the weights, the information on the model architecture and the information on model usage are made publicly available.

Two limits define it. The exemption does not touch points (c) and (d): the copyright policy and the public training content summary are owed by open-source providers too. And it does not apply at all to general-purpose AI models with systemic risk. A widely used open-weights model above the Article 51 threshold carries the full documentation obligation. See the open-source exemption in detail.

On timing: Chapter V, which contains Article 53, has applied since 2 August 2025 under Article 113(b). Article 111(2) gives providers of GPAI models placed on the market before that date until 2 August 2027 to take the necessary steps to comply. Commission fines for GPAI providers under Article 101 — up to 3% of annual total worldwide turnover or €15,000,000, whichever is higher — sit outside the Article 113(b) advance and become applicable with the general body of the Regulation on 2 August 2026.

The AI Act has since been amended, and GPAI providers should be clear about what did and did not move. The digital omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 — the first substantive amendment since the Act was adopted in 2024. It moves the stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and high-risk systems embedded in Annex I regulated products to 2 August 2028. Those are high-risk dates: the Chapter V GPAI obligations described on this page have applied since 2 August 2025 and this page does not attribute any change to them, or any other change, to the amending Regulation. Its text has not been read for this page. Verify the applicable dates and any further amendment against the consolidated AI Act on EUR-Lex before relying on them.

The Regulation is on EUR-Lex; the General-Purpose AI Code of Practice and the AI Office documentation template are published by the European Commission on its GPAI code of practice page. For the broader obligation set, see GPAI obligations and the code of practice.