Training-Data Transparency: What the GPAI Public Summary Template Requires

Alongside the Code of Practice enforcement I’ve written about separately, 2 August 2026 activates something else: the AI Office’s supervisory power over a mandatory public disclosure every GPAI provider was already required to publish a year earlier. If a provider’s training-data summary doesn’t exist, or exists but doesn’t follow the actual template, that gap becomes actively checkable in eleven days, not just theoretically required.

The European Commission’s AI Office published the Explanatory Notice and Template for the Public Summary of Training Content on 24 July 2025, implementing Article 53(1)(d) of the AI Act. The obligation itself took effect 2 August 2025 for any GPAI model newly placed on the market; models already on the market before that date have a longer runway, until 2 August 2027. What changes on 2 August 2026 is supervision — the AI Office gains the power to actually check compliance and act on it, the same enforcement date as the Code of Practice I’ve written about separately.

What the template actually requires

Providers must disclose training-content categories — publicly available datasets, private or licensed datasets, data obtained through crawling or scraping, user data, synthetic data, and a catch-all “other data” category — with data size disclosed by selecting ranges rather than exact figures, a deliberate balance the Commission struck between genuine transparency and protecting trade secrets. The Explanatory Notice is explicit that the summary should be “generally comprehensive in scope” rather than technically granular, aimed at giving copyright holders and the public a real, if high-level, picture of what went into a model without forcing disclosure of the underlying raw data or proprietary training methodology.

Free · 4 minutes

When two of your systems disagree, do you know which one to believe?

Fourteen questions on ownership, lineage, and quality — the difference between a number on a dashboard and a number you could defend. Banded finding on screen, full sheet by email.

Critically, this isn’t a one-time filing. Providers must update the summary at least every six months, or whenever a material change occurs — fine-tuning, additional training — connecting directly to the fine-tuning provider-obligation threshold I’ve written about separately. A summary published once at initial release and never revisited, despite the underlying model having been meaningfully fine-tuned since, is itself a compliance gap once the AI Office’s supervisory power activates.

Why this matters to deployers, not just providers

This connects directly to the model-provenance diligence I’ve written about generally — a provider’s training-data summary, once published, becomes a genuine, checkable artefact a deployer can actually review as part of vendor due diligence, rather than relying entirely on a provider’s own marketing claims about how a model was trained. A provider with no published summary, or a summary that’s obviously stale against a model that’s clearly been updated since, is a concrete, checkable red flag rather than an abstract concern — precisely the kind of specific, verifiable fact the general provenance-diligence discipline calls for.

The template’s own acknowledged ambiguities — how exactly to measure “size of content scraped,” for instance — mean early compliance won’t be perfectly uniform across providers, and a genuinely careful reviewer should expect some legitimate variation in interpretation rather than treating every inconsistency as a red flag. But the presence or absence of a genuine, current summary at all is a clean, binary signal worth checking directly.

What checking this actually found

A firm reviewing its three core AI vendors ahead of the 2 August enforcement date found one provider’s training-data summary hadn’t been updated in over a year, despite the provider’s own public release notes describing two significant model updates in that window — a clear, checkable gap between the six-monthly update requirement and actual practice. Raising it directly with the vendor produced a prompt, specific response and an updated summary within days, precisely the kind of quick correction a vendor genuinely investing in compliance can make once the gap is pointed out clearly.

Checking a specific AI provider’s training-data summary against the actual template requirements — as part of genuine vendor due diligence ahead of the AI Office’s now-active supervisory power — is exactly the kind of vendor diligence a technology control assessment is built to perform.

This is worth checking across every material AI vendor relationship in the next eleven days specifically, not on the next scheduled review cycle — the supervisory power activates on a fixed date, and gaps found before that date are considerably easier conversations than gaps discovered after.

Whether a provider carries the Act’s heaviest obligations at all comes down to a single number — see the 10^25 FLOP systemic-risk threshold.

Vendors that treat the disclosure obligation seriously tend to also treat the underlying data-governance question seriously — the summary itself is a useful, low-cost proxy for a provider’s broader compliance culture.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming