Pflichten für GPAI-Modelle
Sie bauen auf dem Modell eines anderen auf. Die Pflichten erreichen Sie immer noch.
Was ist Pflichten für GPAI-Modelle?
Learn about the EU AI Act's framework for General-Purpose AI (GPAI) models. Understand provider obligations for technical documentation and training data transparency, systemic risk classification criteria, and the downstream responsibilities that flow through the AI value chain to downstream providers building products on third-party models.
Was Sie lernen in Pflichten für GPAI-Modelle
- Die beiden Auslöser für die Einstufung als GPAI mit systemischem Risiko erkennen (Rechenleistungs-Schwelle und Einstufung durch das KI-Büro)
- Grundpflichten für GPAI (für alle Modelle) von zusätzlichen Pflichten bei systemischem Risiko unterscheiden
- Erklären, warum Geschäftsgeheimnisse GPAI-Anbieter nicht von der Trainingsdaten-Transparenz befreien
- Understand downstream provider responsibilities when building products on GPAI models
- Urheberrechtliche Pflichten erkennen, die sich entlang der KI-Wertschöpfungskette weitergeben
Pflichten für GPAI-Modelle — Trainingsschritte
-
Artikel 51 bis 56: KI-Modelle mit allgemeinem Verwendungszweck
The EU AI Act introduces a dedicated framework for General-Purpose AI (GPAI) models under Articles 51-56. GPAI models are AI models trained on broad data that can perform a wide range of tasks - large language models are the primary example. All GPAI providers must supply technical documentation (including the model's energy consumption), comply with EU copyright law, and publish a sufficiently detailed summary of their training data. Systemic risk GPAI - models trained with compute exceeding 10^25 FLOPs, or designated by the AI Office - have additional obligations including adversarial testing (red-teaming), systemic risk assessment and mitigation, incident reporting, and cybersecurity measures. These obligations apply to the model provider. But downstream companies building products on GPAI models inherit their own set of responsibilities.
-
Prüfung der Modellauswahl
Eine E-Mail von Raj Patel, dem CTO von NovaMind Labs, trifft ein. Zwei GPAI-Modelle stehen für die Kundensupport-Plattform zur Auswahl, und Alice soll die Compliance-Dokumentation beider Modelle prüfen.
-
Prüfung der Modellkarten
Alice öffnet über den Link in Rajs E-Mail die Seite zur Modellbewertung. Dort werden beide Kandidaten nebeneinander angezeigt — mit ihrem Rechenaufwand, Dokumentationsstatus, Trainingsdaten und Bewertungsergebnissen.
-
Wissenscheck: Trainingsdaten-Transparenz
-
Bewertung des systemischen Risikos
Die Checkliste zum systemischen Risiko beschreibt beide regulatorischen Wege zu Artikel 55 (Rechenschwelle und Einstufung durch das KI-Büro) sowie die zusätzlichen Pflichten, die sie gegenüber Standard-GPAI auslösen.
-
Nachgelagerte Pflichten und Urheberrecht
When NovaMind builds a customer support platform on a GPAI model, the resulting system may be classified independently under the EU AI Act's risk framework. A general customer FAQ bot is likely limited risk (transparency only). But if the system makes decisions affecting customer access to services, credit, or insurance, it could be high-risk -- triggering conformity assessment, human oversight, and incident reporting. NovaMind must assess this independently; the GPAI provider's obligations do not cover the downstream provider's risk classification. Copyright compliance also flows through the value chain. GPAI providers must comply with EU copyright law, including the text and data mining opt-out (Article 4, DSM Directive). If a GPAI model generates content resembling copyrighted material and NovaMind serves it to customers, both the provider and NovaMind may face liability . Before building on any GPAI model, verify the provider's copyright compliance documentation and consider content filtering safeguards.
-
Bewertung einreichen
Alice hat jetzt den vollständigen Überblick: Dokumentationslücken, Einstufung als systemisches Risiko und die nachgelagerten Pflichten, für die NovaMind verantwortlich sein wird. Nun antwortet sie Raj mit einer strukturierten Bewertung — nach Modell aufgeschlüsselte Feststellungen mit Zuordnung zu konkreten Artikeln sowie einer klaren Empfehlung.
-
Warum jeder Teil des Berichts wichtig ist
Eine gute GPAI-Bewertung ist kein Urteil, sondern ein Prüfpfad. Jeder Abschnitt von Alices Antwort erfüllt eine konkrete Funktion für Raj und die Beschaffungsunterlagen.
-
Abschluss: GPAI in der Wertschöpfungskette
Alice has completed the GPAI model evaluation and filed her recommendation. Here are the key takeaways from Articles 51-56: Layered obligations GPAI obligations flow through the value chain: the model provider has baseline duties, and the downstream provider inherits additional responsibilities based on how the model is used. Baseline provider duties All GPAI providers must supply technical documentation, including energy consumption, and a sufficiently detailed training data summary. Trade secrets do not override this requirement. Systemic risk threshold GPAI models trained with compute exceeding 10^25 FLOPs, or designated by the AI Office, are classified as systemic risk. This triggers additional obligations: adversarial testing, systemic risk assessment and mitigation, incident reporting, and cybersecurity measures. Independent risk assessment Downstream providers must independently assess the risk classification of the product they build on a GPAI model. The model provider's compliance does not cover the product. Copyright runs through the chain Copyright compliance is not just the provider's problem. If a GPAI model generates copyrighted content and the downstream provider serves it, both parties may face liability.
Abdeckung der Sicherheits-Frameworks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 53 Obligations for providers of general-purpose AI models
- Art. 55 Obligations for providers of GPAI models with systemic risk