RankShield
RANKSHIELD NETWORK Get started

EU AI Act GPAI Rules: What US SaaS Companies Must Do by August 2

The EU AI Act’s enforcement powers over general-purpose AI go live on August 2, 2026. Here is which duties actually bind a US SaaS, which fall on your model vendor, and what to do about it.

August 2, 2026 · 12 min read · EU AI Act GPAI obligations for US SaaS
Share

As of today, August 2, 2026, the EU AI Act’s rules for general-purpose AI carry real teeth: the European Commission can now investigate the providers of general-purpose AI (GPAI) models and impose fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (EU Artificial Intelligence Act1). For most US SaaS companies, though, the honest answer to "do the EU AI Act GPAI obligations bind us" is narrower than the headlines suggest, and getting it right saves you from either ignoring a real duty or panicking over one that is not yours. The GPAI provider obligations fall on whoever places a general-purpose model on the EU market, which is usually your model vendor, not you, unless you train or substantially modify a model yourself. I build AI governance and verifiable-record tooling at RankShield, and the confusion I see most often is a founder assuming the whole Act lands on them because they call an API, when the parts that actually bind a typical SaaS are elsewhere. What most guidance leaves out is a plain reading of who is bound, by when, and what a small operator should actually do, rather than a dense recital of the whole regulation. That is what this covers. One honest note up front: this is general information, not legal advice, and how the Act applies turns on specifics only your counsel can confirm.

Does the EU AI Act’s GPAI regime actually bind your US SaaS?

For most US SaaS companies, the GPAI provider obligations do not bind you directly, because they attach to whoever places a general-purpose AI model on the EU market, and calling that model through an API does not make you its provider. If you build on OpenAI, Anthropic, Google, Meta, or Mistral through their APIs, those firms are the GPAI providers in the Act’s sense, and the Chapter V duties, along with the enforcement that started today, land on them regardless of where they are based. Your exposure runs through them, not around them.

Geography is not the deciding factor, which is the point most US founders get backwards. The Act reaches providers that place GPAI models on the EU market no matter where they are established, so "we are a US company" is not a shield for a model maker, and it is not the reason a typical SaaS is out of scope either. The reason a typical SaaS is out of scope for the GPAI provider duties is its role: it is a deployer or a downstream provider of an AI system, not the provider of the underlying general-purpose model (Latham & Watkins2).

Where it flips is modification. If you train your own general-purpose model, or you fine-tune or substantially modify someone else’s to the point that you are effectively placing a changed general-purpose model on the EU market, you can become a GPAI provider for that model, and the obligations attach to your version. Routine prompting, retrieval, and light fine-tuning for a narrow task generally do not cross that line, but the boundary is fact-specific, so if you are doing serious model work, this is the question to put to counsel first. Use the check below to see which side of the line you are on before you spend a day on paperwork that may not be yours.

GPAI APPLICABILITY CHECK

Do the EU AI Act GPAI provider duties bind you?

  1. How do you use the general-purpose model behind your product?
  2. Do you place a model (not just an app) on the EU market under your own name?
  3. Do you offer your AI product to users located in the EU?
  4. Does your use case involve chatbots, synthetic media, or AI-generated content shown to people?
  5. Could your use case fall under the Act’s high-risk categories (Annex III: hiring, credit, biometrics, essential services)?

What are the real EU AI Act deadlines?

The EU AI Act does not switch on all at once; it phases in, and three GPAI dates matter. GPAI provider obligations began applying on August 2, 2025. The Commission’s enforcement powers over GPAI providers, including the ability to impose fines, become active on August 2, 2026, which is today. Models already on the market before August 2, 2025, so-called legacy models, have until August 2, 2027, to be brought into compliance (EU Artificial Intelligence Act1).

Today’s date is the one that changes the risk calculus. Since August 2, 2025, GPAI providers have had duties on paper, but the Commission could not yet enforce them; from today it can investigate, request documentation, and levy penalties. That is why "the AI Act is a 2025 thing we already looked at" is a mistake worth correcting on your team: the obligation existed a year ago, but the consequence for ignoring it starts now (European Commission3).

The same August 2, 2026 milestone carries more than GPAI enforcement, which is why a US SaaS should not tune it out just because it is not a model maker. This is also the date the broader Act, including transparency obligations and the high-risk system regime, moves from published law to applied law. If any part of your product touches those areas, the calendar you care about is the same one the model makers are watching, so treat the timeline below as yours, not only theirs.

DOWNLOADABLE INFOGRAPHIC

The EU AI Act GPAI timeline

RANKSHIELD // EU AI ACT, GPAI TIMELINE Three dates that decide your exposure AUG 2, 2025 GPAI provider duties begin Obligations apply on paper. No enforcement power yet. AUG 2, 2026 ← TODAY Enforcement + fines go live Commission can investigate and fine up to EUR 15M or 3% of global turnover. Transparency + high-risk regime applies. AUG 2, 2027 Legacy models must comply Source: EU Artificial Intelligence Act, Chapter V enforcement; European Commission. General information, not legal advice.
The three GPAI dates that matter, and why August 2, 2026 is the one that changes your risk. Free to share with attribution.

What is the GPAI Code of Practice, and should you sign it?

The General-Purpose AI Code of Practice is a voluntary framework, developed with the European Commission and finalized in 2025, that GPAI providers can sign to show how they meet their Chapter V obligations on transparency, copyright, and safety. Signing is not mandatory, but adherence gives providers a presumption of conformity with the corresponding duties, which lowers their compliance and audit burden compared with demonstrating compliance from scratch (Latham & Watkins2).

For a typical US SaaS that only consumes a model, the Code is not something you sign; it is something you look for in your vendor. Whether your model provider has signed it, and which chapters they signed, is a useful signal of how they are handling the obligations you are relying on, and it is a fair question to raise in vendor due diligence and renewals. You inherit the benefit of their compliance, so their posture is part of your posture.

If you are in the narrower group that does become a GPAI provider, by training or substantially modifying a model, then the Code becomes a live decision for you, and the trade-off is real: signing commits you to specific documentation and transparency practices, while giving you the presumption of conformity that makes enforcement easier to withstand. That is a decision to make with counsel, weighed against how you actually build, rather than by default. The through-line for everyone is the same: know your role first, because it determines whether the Code is your obligation or your vendor’s.

What do GPAI providers actually have to file?

If you are a GPAI provider, the core obligations are documentation and transparency rather than a single filing: you must maintain up-to-date technical documentation of the model, provide information and documentation to downstream providers who build on it, put in place a policy to respect EU copyright law, and publish a sufficiently detailed public summary of the content used to train the model, using the template provided by the AI Office (Latham & Watkins2). Models classified as carrying systemic risk take on additional duties around evaluation and incident reporting.

Read that list against your own role before you act on it. For a SaaS that calls an API, none of these are yours to file; they are your vendor’s, and the practical value of the list is knowing what to expect from them, the training-data summary, the downstream documentation, the copyright policy, as artifacts you can ask to see. For the modification case, the obligations attach to the changes you made, not the entire base model, which is a meaningful narrowing but still real work.

The reason this matters even to out-of-scope SaaS is the downstream documentation duty. Your model provider owes you the information you need to understand and use the model responsibly, which is exactly the material you would lean on if you ever had to demonstrate your own oversight to a customer or a regulator. Keeping that vendor documentation on file, and knowing it exists, is a low-cost habit that pays off the moment anyone asks what your AI is built on. The table below sorts the obligations by who actually owns them.

WHO OWNS WHAT

GPAI obligations and who they fall on

ObligationModel vendor (GPAI provider)Typical US SaaS (API deployer)
Technical documentation of the modelRequiredNot yours; request from vendor
Documentation to downstream providersMust provide itYou are the recipient; keep it on file
EU copyright compliance policyRequiredNot yours (unless you modify a model)
Public training-data summary (AI Office template)Must publishNot yours; a signal to check
Signing the GPAI Code of PracticeOptional, gives presumption of conformityLook for it in vendor due diligence
Article 50 transparency to EU usersDepends on roleYours if you serve EU users AI content

General information, not legal advice. Which column you are in depends on your role, confirm with counsel.

What does non-compliance actually cost?

For GPAI providers, the Act lets the Commission impose fines of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher, and as of today those powers are active rather than theoretical (EU Artificial Intelligence Act1). Other breaches of the Act carry their own ceilings, with the most serious violations, such as prohibited practices, reaching higher still, so the GPAI figure is one band within a wider penalty structure, not the maximum.

The turnover basis is what makes these numbers serious for large model makers, because 3% of worldwide turnover can far exceed the flat 15 million euro figure, which is why the Act uses "whichever is higher." For a US SaaS that is not a GPAI provider, this specific penalty is not pointed at you; the exposure that is pointed at you comes from the transparency and high-risk duties, if they apply, and each of those carries its own consequences under the Act.

The takeaway is not to convert this into fear, because for most SaaS the honest risk on August 2 is modest and manageable. It is to right-size the response: confirm your role, verify your model vendor is carrying the GPAI duties you depend on, and check whether transparency or high-risk obligations reach your product. That is a focused afternoon of work for a typical team, not a compliance overhaul, and it is far cheaper than either ignoring a duty that is yours or burning a sprint on one that is not. If demonstrating oversight of your AI is part of that picture, being able to prove what your AI systems actually did is the evidence that makes it concrete, which is what a verifiable record gives you.

What should your US SaaS do about the EU AI Act today?

The August 2, 2026 deadline is real, enforcement is now live, and for most US SaaS the right response is precise rather than dramatic. Start by settling your role, because it decides everything else: if you call a third-party model through an API, the GPAI provider duties belong to your vendor, and your job is to verify their compliance in your contracts, ask for the downstream documentation and training-data summary they owe you, and note whether they signed the GPAI Code of Practice. If you train or substantially modify a general-purpose model, treat yourself as a possible GPAI provider and take that question to counsel first.

Then check the parts of the Act that can bind you directly regardless of GPAI status: Article 50 transparency if you show AI-generated content or chatbots to EU users, and the high-risk regime if your use case falls under Annex III. Map those honestly, and where a duty applies, the evidence that carries you through an audit is a demonstrable record of how your AI behaves and who authorized its consequential actions. That is exactly what RankShield’s verifiable-AI tooling is built to produce. This article is general information, not legal advice, and how the Act applies depends on facts only qualified counsel can confirm for your business; see how RankShield helps you prove your AI governance.

FREQUENTLY ASKED

Questions, answered.

Jamie Kloncz
Jamie KlonczCEO, RankShield · online

Does the EU AI Act apply to US companies?

Jamie Kloncz

Yes, but its reach depends on your role, not just your location. The Act applies to providers that place general-purpose AI models or AI systems on the EU market regardless of where they are established, so a US model maker is squarely in scope. It also reaches providers and deployers whose AI system output is used in the EU. What it does not do is automatically bind every US SaaS that calls an AI model. If you only consume a third-party model through an API, the general-purpose AI provider obligations sit with your vendor, not you, though other parts of the Act, such as transparency duties for AI-generated content shown to EU users, can still apply to you directly. The deciding question is whether you provide a model, deploy a system to EU users, or modify a model yourself. This is general information, not legal advice; confirm your specific position with counsel.

What is a GPAI provider under the EU AI Act?

Jamie Kloncz

A GPAI provider is whoever develops a general-purpose AI model and places it on the EU market under their own name or brand, or has it placed on the market on their behalf. In practice that means the firms that build foundation models, such as OpenAI, Anthropic, Google, Meta, and Mistral, are the GPAI providers, and the Chapter V obligations attach to them regardless of where they are headquartered. A company that builds an application on top of one of those models through an API is generally a deployer or a downstream provider of an AI system, not a GPAI provider. The important exception is modification: if you train your own general-purpose model, or fine-tune or substantially modify an existing one to the point that you are effectively placing a changed general-purpose model on the market, you can become a GPAI provider for that model, and the obligations attach to your version.

What are the EU AI Act GPAI deadlines?

Jamie Kloncz

There are three dates that matter for general-purpose AI. GPAI provider obligations began applying on August 2, 2025. The European Commission’s enforcement powers over GPAI providers, including the ability to impose fines, became active on August 2, 2026. Models that were already on the market before August 2, 2025, known as legacy models, have until August 2, 2027, to be brought into full compliance. The August 2, 2026 date is the one that changes the risk calculus, because the obligations existed on paper from 2025 but could not be enforced until now. That same date also marks when the broader Act, including transparency obligations and the high-risk system regime, moves from published law to applied law, so it matters to more companies than just model makers.

Do I need to sign the GPAI Code of Practice?

Jamie Kloncz

Only if you are a GPAI provider, and even then it is voluntary. The General-Purpose AI Code of Practice is a framework developed with the European Commission that GPAI providers can sign to demonstrate how they meet their obligations on transparency, copyright, and safety. Signing is not required, but it gives a provider a presumption of conformity with the corresponding duties, which reduces the burden of proving compliance from scratch. For a typical US SaaS that only consumes a third-party model, the Code is not something you sign; it is something to look for in your model vendor, because whether they signed it, and which chapters, tells you how they are handling the obligations you rely on. If you do become a GPAI provider through modification, whether to sign becomes a real decision to weigh with counsel against how you build.

What are the penalties under the EU AI Act for GPAI providers?

Jamie Kloncz

For general-purpose AI providers, the Act allows the European Commission to impose fines of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. As of August 2, 2026, those enforcement powers are active rather than theoretical. The turnover basis is what makes the figure significant for large model makers, since 3% of global turnover can exceed the flat 15 million euro amount. This particular penalty is aimed at GPAI providers, so a US SaaS that is not a provider is not the target of it. The exposure that does reach a typical SaaS comes instead from the transparency and high-risk obligations, if they apply, and those carry their own consequences under the Act. The most serious violations of all, such as engaging in prohibited practices, sit in a higher penalty band.

I only use OpenAI or Anthropic through their API. Do the GPAI rules bind me?

Jamie Kloncz

Generally no, not the GPAI provider obligations. When you build on OpenAI, Anthropic, or a similar model through their API, those firms are the GPAI providers in the Act’s sense, and the Chapter V duties, along with the enforcement that is now live, land on them. You are a deployer of their model. That does not mean the Act is irrelevant to you: if you serve users in the EU and show them AI-generated content or chatbots, Article 50 transparency duties can apply to you directly, and if your use case falls into a high-risk category under Annex III, those obligations can apply too. Your practical task is therefore to verify your vendor is carrying the GPAI duties you depend on, keep the documentation they owe you on file, and separately check whether transparency or high-risk duties reach your own product. Confirm the specifics with qualified counsel.

Try one of the suggested questions above.

References

  1. EU Artificial Intelligence Act. Enforcement of Chapter V (GPAI provider obligations; enforcement and fines up to EUR 15M or 3% of global turnover from August 2, 2026; legacy models by August 2, 2027).
  2. Latham & Watkins. EU AI Act GPAI model obligations in force and final GPAI Code of Practice in place (who is a GPAI provider; provider duties; Code of Practice presumption of conformity).
  3. European Commission. The AI Act (official policy overview, phased application, and the AI Office).
Jamie Kloncz
WRITTEN BY

Jamie Kloncz

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.

Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.