New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to blog
Sector trends8 min read

The AI Reading Your Student Comments Is a General-Purpose Model. A New EU Regime Now Governs It.

If you use an LLM to theme open-text feedback, you are sitting downstream of a general-purpose AI model — and since August 2025 those models carry their own obligations under the EU AI Act. Most of the duties fall on the model provider, not on you. Here is what that actually means for how you procure and run an evaluation tool.

Koji Education Team

Product · August 9, 2026

Bottom line: The EU AI Act (Regulation (EU) 2024/1689) created a dedicated regime for general-purpose AI (GPAI) models — the large language models that sit underneath tools like ChatGPT, and underneath any evaluation platform that uses AI to summarise or theme open-text student feedback. Those obligations started applying on 2 August 2025. The important, slightly deflating truth is that most of them land on the model provider up the supply chain, not on your university as a deployer. But that does not make the regime irrelevant to evaluation teams — it changes what you can demand in procurement, and it clarifies a supply chain most quality offices have never mapped.

The layer you have been using without naming it

When a university runs student comments through an LLM to theme them at scale, it is standing on top of a general-purpose model it did not build and cannot see inside. Until recently that model was a regulatory black box. The AI Act's GPAI chapter changes that. It defines a GPAI model as one trained on a large amount of data using significant compute and capable of performing a wide range of distinct tasks — the Commission's guidelines use an indicative training-compute threshold in the region of 10^23 floating-point operations for classification. Providers of these models must now maintain detailed technical documentation, publish a summary of the content used for training, put in place a policy to comply with EU copyright law, and share information downstream so that deployers can understand and use the model responsibly.

A stricter tier applies to models with systemic risk — presumed above a training-compute threshold of 10^25 FLOPs — which face additional duties on model evaluation, adversarial testing, incident reporting and cybersecurity. To operationalise all this, the Commission published a voluntary GPAI Code of Practice on 10 July 2025; adherence is not mandatory, but providers can rely on it to demonstrate compliance. Enforcement powers against GPAI providers become available from 2 August 2026, with models already on the market before August 2025 given until August 2027 to comply. Fines for GPAI providers can reach €15 million or 3% of worldwide annual turnover, whichever is higher.

But universities aren't GPAI providers — so why should a quality office care?

This is the honest objection, and it is mostly right. Your university is a deployer, not a model provider, and the heavy GPAI documentation duties are not yours. Your own obligations under the Act come from elsewhere: the Article 4 AI-literacy duty on everyone who operates AI, the Article 50 transparency duty to tell people they are interacting with AI, and — if the use case qualifies — the high-risk regime for AI used in education. The GPAI chapter sits upstream of all of those.

So why care? Three reasons. First, procurement leverage: the regime gives you a right to expect that any AI vendor's underlying model comes with technical documentation, a training-data summary and a copyright-compliance policy — you can and should ask a course-evaluation vendor to evidence that the model beneath their tool sits on the right side of this. Second, supply-chain clarity: knowing that your feedback analysis rests on a GPAI model, governed by a named regime, lets you document the chain for your own DPIA and records — useful alongside your data-residency and hosting decisions. Third, and less comfortably, the deployer/provider line can blur: if your institution substantially fine-tunes or modifies a general-purpose model on your own data, you can inherit provider-style obligations for that modification. A quality office building its own bespoke LLM on years of evaluation text should get legal advice before assuming none of this applies.

What this does not do

It is worth being equally clear about the limits, because AI-Act commentary tends toward alarmism. The GPAI chapter does not ban using LLMs on student feedback. It does not, by itself, make your evaluation system "high-risk" — that classification turns on the use case under Annex III, not on the fact that a general-purpose model is involved. And it does not transfer the provider's documentation burden onto every downstream user. The regime's design is to fix responsibility at the point in the chain best placed to bear it — the model maker — and to give everyone below them enough information to act responsibly. For an evaluation team, the practical upshot is modest but real: ask better questions of your vendor, document the chain, and watch the fine-tuning line.

Where Koji fits

Koji is a downstream user of general-purpose models, and it is built to make that supply chain legible rather than opaque. Where a university would otherwise bolt an unaccountable LLM onto its raw feedback, Koji's AI moderation and automatic thematic analysis sit inside a system designed for the deployer duties that are yours: it discloses that students are interacting with an AI moderator (the Article 50 transparency point), it is designed for EU-appropriate, GDPR/AVG-compliant data handling, and it gives you a documented processing chain to reference in your own DPIA. That means a quality office can adopt AI-assisted analysis while keeping the procurement and transparency questions this regime rewards firmly answered. Teams doing wider user or stakeholder research can run the same governed engine on the main Koji platform.

To be precise about the claim: Koji does not assume your GPAI obligations, because as a deployer you have very few — and it does not make your use case low-risk if the underlying purpose is high-risk. It mitigates the governance gap by giving you a transparent, disclosable, EU-appropriate pipeline and the documentation trail to satisfy the duties that genuinely attach to you.

A short procurement checklist

The regime turns into something practical the moment you are choosing or renewing an AI-assisted evaluation tool. Four questions do most of the work. Ask the vendor whether the underlying general-purpose model carries the technical documentation and training-data summary the Act now expects, and whether the provider maintains an EU-copyright-compliance policy — you are entitled to expect a clean answer. Ask how, and how clearly, students are told they are interacting with an AI moderator, since that Article 50 transparency duty is genuinely yours. Ask where the data is processed and how the chain is documented, so the tool slots into your existing DPIA rather than opening a new gap. And ask whether anything you do — especially fine-tuning on your own feedback corpus — could reclassify you from deployer to provider, because that is the one move that pulls the heavy obligations onto your side of the line. None of these questions requires deep AI expertise; they require knowing the chain exists.

Frequently asked questions

What is a general-purpose AI model under the EU AI Act? A model trained on a large amount of data using significant compute that can perform a wide range of distinct tasks — the large language models underneath tools like ChatGPT. The Commission uses an indicative training-compute threshold around 10^23 FLOPs for classification, with a systemic-risk tier presumed above 10^25 FLOPs.

When did the GPAI obligations start applying? On 2 August 2025 for models placed on the market on or after that date. The Commission can enforce against GPAI providers from 2 August 2026, and models already on the market before August 2025 have until 2 August 2027 to comply.

Does my university have GPAI obligations if it uses an LLM to analyse feedback? Generally no. The GPAI duties fall on the model provider. As a deployer, your obligations come from the AI-literacy duty (Article 4), the transparency duty (Article 50), and the high-risk regime if your use case qualifies — not from the GPAI chapter itself.

Could we ever become a GPAI provider? Potentially, if you substantially fine-tune or modify a general-purpose model — for example, training a bespoke model on years of your own evaluation text. Substantial modification can bring provider-style obligations for that modification, so take legal advice before building one.

What should we ask a course-evaluation vendor about their AI? Ask whether the underlying model comes with technical documentation, a training-data summary and an EU-copyright-compliance policy; whether the vendor discloses AI interaction to students; and how the processing chain and data residency are documented for your DPIA.


Adopting AI-assisted feedback analysis without the governance headache? See how Koji for Education keeps the supply chain transparent and the deployer duties covered.