A foundation model is a large AI model trained on broad, often unlabelled data at scale -- typically using self-supervised learning -- that can be adapted to a wide range of downstream tasks through fine-tuning, prompting, or further training, rather than being built for one purpose from scratch. The term was coined by Stanford's Center for Research on Foundation Models (CRFM) in its August 2021 report and now describes the base layer beneath nearly all frontier AI: large language models like GPT, Claude, and Gemini; image and video generators; and multimodal systems. Foundation models matter for governance because their generality is also their risk: a single model's flaws, biases, or vulnerabilities propagate into every downstream product built on it, and their scale of training compute can produce capabilities not fully anticipated by their own developers. The EU AI Act formalizes this concern by regulating foundation models as "general-purpose AI models" (GPAI models) under Articles 51-56, with a tiered system of obligations that escalates sharply once a model crosses a defined training-compute threshold. Organizations building on, fine-tuning, or deploying foundation models increasingly need to track both the underlying model provider's compliance posture and their own downstream obligations under this framework.
Run the free AI Health CheckFoundation Model, a large AI model trained on broad data at scale and adaptable to a wide range of downstream tasks, typically through fine-tuning or prompting rather than purpose-specific training.
Foundation models are the basis of most modern frontier AI, including all large language models, image generators, and multimodal systems from OpenAI, Anthropic, Google DeepMind, Meta, Mistral, and others. Under the EU AI Act, foundation models are regulated as General-Purpose AI (GPAI) models: provider obligations under Article 53 formally apply from 2 August 2025, though providers of GPAI models already on the market before that date have until 2 August 2027 to bring their technical documentation into compliance, and the Commission's power to investigate and fine providers (Articles 88 and 101) only becomes applicable from 2 August 2026. Models meeting "systemic risk" thresholds (currently 10^25 FLOPs of training compute) face additional Article 55 obligations. The EU's June 2026 "Digital Omnibus on AI" amendments delayed high-risk AI system obligations but left this GPAI/foundation-model framework (Articles 51-56) untouched, so the dates above still stand.
Source: EU AI Act, Articles 51-55, 88, 101; Digital Omnibus on AI (June 2026); Stanford CRFM
Before foundation models, most AI systems were built narrowly: a model trained on labelled data for one task (say, classifying spam email) that could not be repurposed for anything else. Foundation models invert this. They are trained once, on broad and often internet-scale data, using self-supervised objectives that don't require task-specific labels -- and the resulting model can then be adapted to many different downstream tasks through fine-tuning, retrieval augmentation, or simply prompting, without retraining from scratch.
This shift has two governance-relevant consequences. First, it concentrates capability and risk: a handful of labs (OpenAI, Anthropic, Google DeepMind, Meta, Mistral, and a small number of others) train the foundation models that thousands of downstream products then build on, creating single points of failure and dependency. Second, it decouples the entity that trains a model from the entities that deploy it -- a foundation model provider may have no visibility into the hundreds of applications built on their API, which is precisely the structural problem the EU AI Act's provider/deployer split is designed to address.
Baseline obligations (Article 53) -- all providers
Every provider of a general-purpose AI model placed on the EU market must: maintain up-to-date technical documentation of training and testing (Annex XI); provide downstream integrators with information on the model's capabilities and limitations (Annex XII); adopt a policy to comply with EU copyright law, including honouring text-and-data-mining opt-outs; and publish a sufficiently detailed public summary of training content using the AI Office's template. These obligations apply from 2 August 2025.
Systemic-risk threshold (Article 51) -- the 10^25 FLOPs test
A model is rebuttably presumed to have 'systemic risk' if cumulative training compute exceeds 10^25 floating-point operations. The Commission can also designate a model as systemic-risk below that line based on Annex XIII criteria, and can revise the threshold itself by delegated act as hardware and algorithmic efficiency improve. Providers must notify the Commission within two weeks of a model meeting the threshold (Article 52).
Systemic-risk obligations (Article 55) -- the highest tier
Providers of systemic-risk models face additional duties: standardised model evaluation and adversarial (red-team) testing, assessment and mitigation of systemic risks at EU level, tracking and reporting serious incidents to the AI Office, and ensuring adequate cybersecurity protection for the model and its infrastructure.
Open-source exemption -- and its limit
Providers releasing a model under a free and open-source licence, with publicly available weights, architecture details, and permission for use/modification/distribution, are exempt from the Article 53 documentation and downstream-information duties. This carve-out disappears entirely once a model is classified as systemic-risk -- open weights do not exempt a frontier-scale model from Article 55.
Enforcement and penalties
The Commission can fine GPAI providers up to 3% of global annual turnover or EUR 15 million, whichever is higher, for infringements, false/incomplete information, or refusing model access for evaluation. Crucially, this enforcement power only becomes applicable from 2 August 2026 -- a full year after the underlying obligations started applying on 2 August 2025. Models already on the market before 2 August 2025 have until 2 August 2027 for full documentation compliance.
Downstream propagation of flaws
A bias, security vulnerability, or hallucination pattern baked into a foundation model surfaces in every product fine-tuned or built on top of it, often invisibly to the deployer.
Capability opacity
Because foundation models are adapted to tasks the original trainers never tested for, emergent capabilities (and failure modes) can appear only after wide deployment, well after initial evaluation.
Market concentration
The capital and compute required to train frontier-scale foundation models limits the field to a small number of providers, creating systemic dependency and single points of failure across the economy.
Training data and copyright exposure
Broad-data training raises unresolved copyright, consent, and provenance questions -- the EU AI Act's Article 53 copyright-policy and training-summary requirements are a direct regulatory response to this.
Compute-threshold gaming
Because systemic-risk status turns partly on a bright-line FLOPs number, providers have an incentive to structure training runs just under the threshold, which is part of why the Act also allows Commission designation independent of the compute test.
The EU AI Act is currently the only binding, comprehensive legal framework specifically tiering obligations by foundation-model scale. The United States has no equivalent federal statute; after the Biden-era executive order on AI was rescinded in January 2025, federal policy shifted toward a lighter-touch, sector-by-sector approach, leaving foundation-model-specific rules mainly to a patchwork of state legislation and voluntary frameworks such as the NIST AI Risk Management Framework.
The UK has so far relied on existing regulators acting within their current remits rather than new foundation-model legislation, though the government has signalled intent to introduce binding frontier-AI rules. China takes a more vertical, content- and security-focused approach -- for example mandating labelling of AI-generated content -- rather than a compute-threshold model resembling the EU's. This divergence means a foundation model provider operating globally may need to satisfy EU-style tiered technical obligations while facing a materially different (and often less prescriptive) set of rules elsewhere.
Is a foundation model the same thing as a large language model (LLM)?
No -- LLMs are one type of foundation model. Foundation model is the broader category coined by Stanford's Center for Research on Foundation Models (CRFM) in its 2021 report 'On the Opportunities and Risks of Foundation Models': any model trained on broad data at scale that can be adapted to many downstream tasks. LLMs (GPT, Claude, Gemini, Llama) are text-based foundation models, but the category also includes image generators (Stable Diffusion, Midjourney), multimodal models, and some biology/protein models.
Does the EU AI Act use the term 'foundation model'?
No. The AI Act's legal text uses 'general-purpose AI model' (GPAI model), defined in Article 3(63). Stanford CRFM's own analysis of the Act notes the definitions closely track the original 2021 foundation-model definition, and Recital 97 treats the two as describing the same underlying category -- so 'foundation model' and 'GPAI model' are used interchangeably in practice, but only the latter is the operative legal term.
What is the 10^25 FLOPs threshold and what does it trigger?
It is the compute threshold in Article 51 of the EU AI Act above which a general-purpose AI model is presumed (rebuttably) to pose 'systemic risk.' Models over this threshold face additional obligations under Article 55 -- model evaluation and adversarial testing, systemic risk assessment and mitigation, incident tracking and reporting to the AI Office, and cybersecurity protections -- on top of the baseline Article 53 obligations every GPAI provider must meet. The Commission can also designate a model as systemic-risk below this threshold, and can amend the threshold itself by delegated act as compute efficiency improves.
When do EU AI Act obligations for foundation models actually apply and get enforced?
The Article 53/55 obligations started applying on 2 August 2025 for new models. Providers of GPAI models already on the market before that date have until 2 August 2027 to bring documentation into full compliance. Separately, the Commission's power to investigate, request information, and fine providers only becomes applicable from 2 August 2026 -- so there is a one-year gap between the obligations taking effect and enforcement teeth arriving. Fines for GPAI non-compliance can reach 3% of global annual turnover or EUR 15 million, whichever is higher.
Did the 2026 EU 'Digital Omnibus' delay foundation model rules?
No. The Digital Omnibus on AI, approved by the European Parliament on 16 June 2026 and given final Council sign-off on 29 June 2026, delayed obligations for high-risk AI systems (standalone systems under Annex III pushed to 2 December 2027; product-embedded systems to 2 August 2028). It left the general-purpose AI model framework in Articles 51-56 -- including the 2 August 2025 start date and 2 August 2026 enforcement date -- unchanged.
Are open-source foundation models exempt from EU AI Act obligations?
Partially. Article 53(2) exempts providers of models released under a free and open-source licence (with publicly available weights, architecture information, and permission for access, use, modification and distribution) from the technical-documentation and downstream-information obligations. This exemption does not apply once a model is classified as posing systemic risk -- those providers must meet the full Article 55 obligations regardless of licence.
Last reviewed July 2026