Journal

· Amended · evidence

EU model provider records become enforceable

The August 2026 milestone gives the Commission consequences for missing, misleading, or inaccessible general-purpose model records.

A technical archive routes one stack of model records through a verdigris line into a precision inspection frame.

General-purpose model providers need records that can survive a Commission request, not a compliance narrative assembled after one arrives. The European Union Artificial Intelligence Act already set the duties. On August 2, 2026, its provider fine provision starts to apply, giving missing, misleading, or inaccessible evidence a defined financial consequence.

Three dates govern different events

The timeline is easy to flatten and costly to misread. Chapter V, which contains the duties for general-purpose model providers, applied from August 2, 2025, except for Article 101. Article 101 applies from August 2, 2026. That is the enforcement milestone, not the date when every provider first acquires its documentation duties.

There is a separate transition for older models. A provider whose general-purpose model was already on the market before August 2, 2025 has until August 2, 2027 to take the necessary compliance steps. That rule follows the model’s market date. It does not give every provider the same extra year.

Transparency duties arrive before the high-risk rules

Article 50 creates system transparency duties outside the provider record rules. From August 2, 2026, Article 50(1) requires providers to tell people when they interact directly with an Artificial Intelligence system, unless that interaction is obvious.

Article 50(2) requires providers to mark generated or manipulated audio, images, video, and text in a machine-readable format. A machine-readable mark is a technical signal that software can detect. A system already on the market before August 2, 2026 has until December 2, 2026 to meet this marking duty.

A deployer is the person or organization that uses a system under its authority for professional activity. Both deployer duties apply from August 2, 2026. Article 50(3) requires deployers to tell exposed people about emotion recognition or biometric categorization systems. Article 50(4) requires them to label deepfakes and generated or manipulated text published to inform the public on matters of public interest.

The public-interest text label does not apply when a person reviews the substance or exercises editorial control, and someone holds legal responsibility for publication.

The high-risk schedule moved later. On July 27, 2026, the Digital Omnibus entered into force. High-risk system rules now apply from December 2, 2027, while rules for systems embedded in products apply from August 2, 2028.

A request can reach the working record

Article 91 lets the Commission request the documentation required by Articles 53 and 55, plus additional information necessary to assess a provider’s compliance. In plain language, the authority can ask for the evidence behind the provider’s claims, not merely a polished summary. Its request must identify the legal basis and purpose, specify the information, set a response period, and warn of the fine exposure for incorrect, incomplete, or misleading information.

For a general-purpose model, Article 53 makes the core record concrete:

The first two duties have a limited exception for a non-systemic model released under a qualifying free licence with public parameters and model information. Article 53 still requires the copyright policy and training-content summary.

Providers of general-purpose models with systemic risk carry an additional record burden. In this Regulation, systemic risk means a risk specific to the high-impact capabilities of general-purpose models that has a significant effect on the Union market because of its reach or actual or reasonably foreseeable negative effects. Article 55 requires documented model evaluations and adversarial testing, assessment and mitigation of systemic risks, records and reports of serious incidents and corrective measures, and adequate cybersecurity protection.

Evaluation can go beyond the document set

If the requested information is insufficient, Article 92 allows the Office for Artificial Intelligence, after consulting the European Artificial Intelligence Board, to evaluate the model for compliance. It may also investigate Union level systemic risk for a model classified as presenting systemic risk. The Commission can request access through an API or another suitable technical route, including source code, and may appoint independent experts to conduct the evaluation.

Article 93 lets the Commission require appropriate compliance steps, mitigation of a serious and substantiated systemic risk, or restriction, withdrawal, or recall of a model. These are powers over the provider of the model concerned. The Regulation defines a provider by its development and market role, separately from a deployer that uses a system under its authority. An organization does not become the provider that owes these model records by virtue of use alone.

The maximum fine now has a live date

From the August 2, 2026 application date, Article 101 permits a maximum fine of 3% of the provider’s annual worldwide turnover in the preceding financial year or EUR 15 million, whichever is higher. That provision covers intentional or negligent infringement, failure to answer an Article 91 request or supplying incorrect, incomplete, or misleading information, failure to comply with an Article 93 measure, and failure to provide model access for an Article 92 evaluation. When setting the amount, the Commission must consider the infringement’s nature, gravity, and duration.

The operational test is therefore retrieval under pressure. A provider should be able to produce the current model record, show how it changed, identify who approved it, and connect each compliance assertion to training, testing, incident, and mitigation evidence. A folder of declarations without those links may be documentation in the everyday sense. It is a weak answer to an evaluation request.

This analysis relies on the public Regulation. The European Union institutions named in it are neither Muniment customers nor endorsers.

Sources

  1. EUR-Lex: Regulation (EU) 2024/1689: Artificial Intelligence Act eur-lex.europa.eu
  2. European Commission: Transparency obligations under Article 50 of the Artificial Intelligence Act digital-strategy.ec.europa.eu
  3. European Commission: Navigating the Artificial Intelligence Act digital-strategy.ec.europa.eu

Continue reading

All publications

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.