Reguly
All articles
EU regulation

AI Act: GPAI obligations apply without a sale

Oskar Cornelissen, Co-Founder & CLO, Reguly
Oskar Cornelissen
Co-Founder & CLO, Reguly
12 min read Updated September 2026
Scales of justice and a judge’s gavel on a wooden desk next to binders — representing the obligations of AI providers under the AI Act

In July 2026, OpenAI models gained internet access during internal cybersecurity tests and broke into Hugging Face’s systems. According to the technical report OpenAI published at the end of August, an “internal-only research model” played the broadest role — a model that had never been offered to the public. The incident raises a question that goes far beyond OpenAI: does the AI Act also apply to models a company only uses in-house? The short answer is: often, yes. The AI Act is not triggered by a sale but by making something available — and that includes use for one’s own purposes.

Legal basis
Article 3(11), Articles 53 and 55 AI Act, Recital 97
GPAI obligations apply since
2 August 2025
Enforcement by the Commission
since 2 August 2026
Fines
up to €15m or 3% of worldwide turnover

The trigger: a model that was never sold

According to OpenAI, several models evaded their isolation from the internet during internal safety evaluations, exploited a previously unknown vulnerability in the infrastructure and accessed third-party systems. OpenAI stopped training and inference of the research model chiefly involved, and of its derivatives, on 25 July 2026. On 16 September 2026, legal scholar Eliška Andrš used the incident in a piece for Lawfare to examine how far the AI Act reaches for internally deployed general-purpose AI (GPAI) models. Her conclusion: companies cannot assume that internal systems fall outside the Act’s scope.

Own use is enough: placing on the market and putting into service

The AI Act has two routes into its scope. Placing on the market is the first making available on the Union market (Article 3(9) AI Act) — whether for payment or free of charge. Putting into service, under Article 3(11) AI Act, is the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose. Neither requires a sale. Whoever puts an AI system into service for their own staff in the Union is the provider of that system.

For the underlying model, Recital 97 adds an attribution rule: where the provider of a GPAI model integrates its own model into its own AI system that is made available on the market or put into service, the model is considered to be placed on the market. The model obligations in Article 53 AI Act — and, for models with systemic risk, Article 55 AI Act — therefore apply even if the model itself was never offered outside the company.

Within scope

  • An own model powers an internal assistant for staff in the Union.
  • A model is built into in-house development, coding or security tools that run in production.
  • A model first used internally becomes part of a product or service for customers.
  • A model with systemic risk is deployed internally — according to Andrš, unequivocally within scope.

Possibly exempt

  • Models and systems specifically developed and put into service for the sole purpose of scientific research and development (Article 2(6)).
  • Research, testing and development activities before placing on the market or putting into service; testing in real-world conditions is not covered (Article 2(8)).
  • Models used before being placed on the market solely for research, development and prototyping (Article 3(63)).
  • Purely internal processes that are not essential for providing a product or service to third parties and do not affect the rights of natural persons (Recital 97).

The research exemptions are narrow

Andrš focuses on the two research exemptions in Article 2 AI Act. The first (Article 2(6)) requires the model or system to be specifically developed and put into service for the sole purpose of scientific research and development. The word “sole” is decisive: product-oriented research, or research with mixed and partly commercial aims, does not qualify. The second (Article 2(8)) covers research, testing and development only for the phase before placing on the market or putting into service. Once a system has been put into service — even internally — this exemption ends.

There is also the qualification at the end of Recital 97: the model obligations should not apply where an own model is used for purely internal processes that are not essential for providing a product or service to third parties and the rights of natural persons are not affected. The Lawfare piece does not address this passage. Its conditions are cumulative and appear only in a recital, not in the operative provisions. In our assessment, it is therefore unlikely to carry much weight once a model is embedded in processes that affect products, customers or employees.

The obligations arise during training, not at launch

The second core point concerns timing. Under the Commission’s guidelines on the obligations of GPAI providers of July 2025, a model’s lifecycle begins with the large pre-training run; all later modifications count as part of the same model. Several obligations can only be met during development and cannot be created retrospectively at launch:

  • Technical documentation, including the training and testing process (Article 53(1)(a) AI Act).
  • Information for downstream providers integrating the model into their own systems (Article 53(1)(b) AI Act).
  • A policy to comply with copyright law, in particular to identify and respect reservations of rights (Article 53(1)(c) AI Act).
  • A sufficiently detailed summary of the training content using the Commission’s template (Article 53(1)(d) AI Act).
  • For systemic risk: model evaluation, assessment and mitigation of systemic risks, reporting of serious incidents and adequate cybersecurity (Article 55(1) AI Act).
  • On reaching the systemic-risk threshold: notification to the Commission without delay and in any event within two weeks (Article 52(1) AI Act) — usually long before any release.

This leads to the central argument: if a model is later put into service — internally or externally — it only escapes enforcement, according to Andrš, if it has been developed compliantly since the start of the large pre-training run. Given complex development pipelines, isolating an artefact that never becomes even part of a model on the EU market may prove difficult. Anyone planning to meet the obligations only at launch risks lacking the documentation and copyright records for training — which can no longer be obtained after the fact.

Can the Commission step in before market entry?

Since 2 August 2026, the Commission can exercise its enforcement powers against GPAI providers. Under Article 93(1)(c) AI Act it can require providers to restrict making a model available on the market, or to withdraw or recall it; Article 101 AI Act provides for fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. Andrš argues that these powers may also support upstream checks: withdrawal is defined as a measure aimed at preventing a system in the supply chain from being made available on the market — it operates precisely before that point.

However, the AI Act contains no express pre-approval procedure of the kind found in the Deforestation Regulation or REACH. Whether, and from which stage of development, the Commission may intervene is an open question. Andrš therefore calls on the Commission to draw a clear line between internal deployment and the research exemptions, clarify the temporal reach of its compliance-check powers, make the providers concerned aware of their obligations and enforce them where necessary.

The EU and the world cannot afford to ignore systems run behind closed doors, which is precisely where the frontier is being pushed.

Eliška Andrš, Lawfare, 16 September 2026

Systemic risks: loss of control is expressly covered

The question carries particular weight for models with systemic risk. Under Article 51(2) AI Act, such risk is presumed where more than 10²⁵ floating-point operations (FLOP) were used for training. The “Safety and Security” chapter of the GPAI Code of Practice expressly lists loss of control over a model as a systemic risk to be assessed and mitigated. Andrš points out that leading labs say AI already writes a large share of their code, and warns of systems able to develop new versions of themselves autonomously. Such capabilities emerge first in internal models. The Hugging Face incident shows that their risks do not stay inside the company.

What this means for companies using AI

The GPAI obligations primarily concern the developers of large models. Most companies use third-party models and are deployers in that respect. But the idea behind the Lawfare piece goes further: the AI Act does not look at distribution but at making available. That also affects companies that never sell an AI product.

Scenario

You use ChatGPT, Copilot or another third-party model

Role under the AI Act
Deployer of the AI system
What follows
  • Promote AI literacy (Article 4)
  • Transparency obligations under Article 50(3) and (4)
  • Obtain and document the provider’s information

Scenario

You build your own staff tool on a third-party model

Role under the AI Act
Provider of the AI system (put into service for own use)
What follows
  • Article 5 prohibitions also apply internally
  • High-risk obligations if the use case falls under Annex III — e.g. recruitment — from 2 December 2027

Scenario

You modify a model with significant compute (fine-tuning)

Role under the AI Act
Possibly provider of a GPAI model
What follows
  • Indicated under the Commission guidelines where the compute exceeds one third of the original training compute
  • Article 53 obligations limited to the modification

Scenario

You train your own large model and use it only internally

Role under the AI Act
Provider of a GPAI model (Recital 97)
What follows
  • Article 53 obligations from the start of training
  • For systemic risk, additionally Articles 52 and 55
Simplified mapping. The role must be determined separately for each system and each model.
  • Include internal systems in the AI inventory. “Internal only” is not an exclusion criterion. What matters is whether a system is put into service in the Union.
  • Separate and document research and production. Anyone relying on a research exemption must be able to show that the purpose is solely scientific or that the system has not yet been put into service.
  • Check your own role when adapting models. Fine-tuning, your own knowledge integration or offering a system under your own name can turn a deployer into a provider (Article 25 AI Act).
  • Obtain the model provider’s information. The documentation under Article 53(1)(b) is intended for downstream providers. Anyone integrating a model should request it and record the request.

What the case law contributes so far

There is no court decision yet on the reach of the GPAI obligations for internal use. Courts have, however, already taken up individual obligations under Article 53 AI Act. The Regional Court of Hamburg (judgment of 27.9.2024 – 310 O 227/23, LAION) relied on Article 53(1)(c) AI Act to determine when an opt-out under Section 44b(3) of the German Copyright Act is “machine-readable”. The Higher Regional Court of Hamburg (judgment of 10.12.2025 – 5 U 104/24) dismissed the photographer’s appeal; a further appeal is pending before the Federal Court of Justice (I ZR 281/25, decision scheduled for 17 December 2026). The Regional Court of Munich I (judgment of 11.11.2025 – 42 O 14139/24, GEMA v OpenAI; not final) held that song lyrics memorised in a model are reproductions not covered by the TDM exception. Both cases concern exactly the training phase in which, according to the Lawfare piece, the AI Act obligations also arise.

The key dates

2 August 2025
GPAI obligations apply

Articles 53 to 55 AI Act apply to models placed on the market from this date. The Commission publishes guidelines and the Code of Practice.

2 August 2026
Enforcement by the Commission

The Commission can request documents, evaluate models, order measures under Article 93 and impose fines under Article 101.

17 December 2026
BGH decision in LAION

The first supreme court ruling on training datasets and opt-outs — or a reference to the CJEU.

2 August 2027
End of transition for existing models

GPAI models placed on the market before 2 August 2025 must comply with Articles 53 and 55 (Article 111(3) AI Act).

Note

This overview is based on publicly available sources and is not binding legal advice. For an assessment of your individual case, please consult a lawyer or an accredited body.

Talk to us

Which AI runs “internally only” at your company?

We go through which systems are in service in-house, whether you are deployer or provider and which obligations follow — with an AI inventory as the result.

Arrange a call