As EU lawmakers worked to shape their negotiating position on the AI Act, generative AI had become a central question: how could rules cover models that serve many purposes and involve multiple companies along the way? The approach under discussion divided obligations into three layers, from the relationships between providers and downstream users to specific transparency duties for generative systems.
Rules across the AI value chain
One proposed layer would apply broadly to general purpose AI, whether the model was large or small, foundational or non foundational. It would clarify what one entity owes another when it puts a model on the market and another company uses it for a particular purpose.
That downstream purpose could make the resulting application high risk. In that case, the company using the model may need information from its provider to meet the AI Act’s requirements. The proposals described in the article include explaining how a model was trained and providing information about its data sets, including their accuracy and possible biases.
The issue is access to information as well as responsibility. A company building an application on top of a model may not have the underlying training data or other details needed to assess it. Lawmakers were therefore considering how duties should be shared, so that obligations do not fall only on the company deploying a specific application.
Additional duties for foundational models
A second layer would apply to providers of foundational models. MEP Dragos Tudorache, the AI Act’s co-rapporteur, said lawmakers believed these providers should have specific responsibilities because of the models’ power, training and versatility.
The proposed duties would cover the model’s development and its life after release. The areas discussed included transparency, how the model is trained, and how it is tested before entering the market. The broader question is what level of care developers should owe when they make foundational models available.
This would add requirements at the model-provider level, alongside the broader rules about relationships between companies. It reflects a concern that the AI value chain can involve many organizations in development, customization and deployment, making it difficult to assign responsibility clearly.
Generative AI and transparency about training material
The third layer would target generative AI, including large language models and systems that generate art or music. The lawmakers’ proposal would address risks connected to what these tools produce, including disinformation and defamation, as well as the use of copyrighted material in training.
The idea described was not to create a new copyright regime. Instead, developers would document and disclose material used to train models. Rights holders could then examine whether their protected material had been used and consider their rights under existing copyright laws.
That approach would bring information about training material into the AI Act while leaving copyright questions to existing law. It also addresses a practical challenge for generative systems: their outputs can vary widely, and a model may not have one fixed use. The same kind of tool could support research or writing, while also being used in ways that raise concerns about accuracy, creative work or rights.
A proposal still to be negotiated
The three layers were part of the European Parliament’s developing position, not a final rule. The Council’s position, adopted in December, favored leaving generative AI to additional implementing legislation, while MEPs were looking at adding requirements to the Act itself. The article reported that technology companies, including Google and Microsoft, had argued for generative AI to receive a carve out.
The Commission’s draft took a risk-based approach. It proposed prohibiting some uses, applying stronger requirements to high risk applications, and setting transparency requirements for certain other technologies, such as chatbots and deepfakes. Because that draft had been developed before generative AI became a mainstream focus, lawmakers had an opportunity to amend it as negotiations continued.
At the time of the report, lawmakers were working toward votes on Parliament’s negotiating mandate, followed by discussions with the Council. Tudorache said an agreement might be reached by the end of the year, while acknowledging that disagreements and the timeline remained uncertain. The AI Act was not expected to be in force before 2025, or potentially later, depending in part on how much preparation time companies and enforcement authorities received.
The proposed structure aimed to connect duties to the different roles in AI development and use: providers of general purpose systems, developers of foundational models, and makers of generative tools. Whether those layers would appear in the final law depended on negotiations between the Parliament and Member States.