Most Turkish AI products are built on someone else’s model — GPT, Claude, Gemini, Llama. Founders often assume that puts the AI Act on the model maker’s desk, not theirs. Half right. The general-purpose AI (GPAI) regime has been in force since 2 August 2025, Commission enforcement begins 2 August 2026, and two of its mechanisms reach straight into your product: the provider/deployer boundary, and the information that must flow down the stack to you.
The boundary that matters: when do you become a “provider”?
Wrapping an API with your own prompts and UI keeps you a deployer (or a downstream system provider): your obligations are the transparency duties we covered for 2 August — disclosure, content marking — plus whatever risk class your use falls into.
But significantly modifying the model changes your status. Under the Commission’s July 2025 guidance and the training-content template, an entity that fine-tunes or otherwise substantially modifies a GPAI model becomes a provider for that modification — including the obligation to publish a training-content summary covering the data used for the fine-tune. If you fine-tuned an open-weight model on your proprietary dataset and shipped it to EU users, that summary obligation is yours, on the AI Office‘s own template, published 24 July 2025.
Practical rule of thumb: prompting and RAG keep you downstream; training moves you upstream. Where exactly the line sits is fact-specific — volume of compute, purpose change, capability change — and worth a legal look before your next model release, not after.
What must flow down to you — and what to do when it doesn’t
Article 53 obliges GPAI providers to prepare documentation for downstream providers: capabilities, limitations, integration information — alongside a copyright policy and the public training-content summary. The GPAI Code of Practice (10 July 2025) turned this into a Model Documentation Form that signatories — including the major labs — maintain and keep current.
Use that leverage. If you build on a model whose provider gives you nothing you can hand to your own enterprise customers or regulators, that is a red flag with a paper trail: the information duty exists precisely so the stack can comply.
The contract layer: six clauses for your AI vendor agreements
The AI Act’s stack logic lands in your contracts. When negotiating with model providers — or being negotiated with, as the AI feature vendor — these are the clauses we now consider baseline:
- Regulatory information flow. Provider delivers and updates the Art. 53 documentation, in a form you may share with customers and authorities.
- Marking tooling. Access to the provider’s content-marking/watermarking mechanisms, so your Article 50 marking duties are technically feasible.
- Copyright warranty and process. The provider maintains an EU-copyright-compliant training policy; you get cooperation if output triggers a third-party claim.
- Change notice. Advance notice of model deprecations and significant capability changes — a silent model swap can change your risk classification.
- Incident cooperation. A defined channel and timeline for serious-incident information, mirroring what the Act expects between stack layers.
- Compliance allocation. An explicit map of who owns which AI Act obligation — provider, you, your customer — instead of a generic “comply with applicable law” clause that helps no one.
If you sell AI features B2B, expect the same six demands from your customers, increasingly copy-pasted from EU procurement playbooks. Answering them well is a sales asset; see our SaaS & IT Contracts practice for how we structure the vendor-side answers.
This week’s homework
- Inventory which of your features rely on which models, and whether anything you did crosses from prompting into training.
- Pull the Model Documentation your providers publish; file the gaps.
- Diff your vendor agreements against the six clauses above.
- If you fine-tune: start the training-content summary now — retrofitting data provenance is far more painful than recording it.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call