Systemic-Risk Obligations for General-Purpose AI Models
9 min read · updated August 11, 2026
Article 53 applies to every general-purpose AI model. Article 55 applies only to the subset classified as presenting systemic risk, and it is a different kind of obligation: not documentation, but evaluation, mitigation, incident reporting and security, owed continuously.
Where the systemic-risk line sits
Article 51 of Regulation (EU) 2024/1689 gives two routes into the classification. A model is classified as having systemic risk if it has high-impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or if the Commission decides — on its own initiative or following a qualified alert from the scientific panel — that it has capabilities or impact equivalent to those.
Article 51(2) supplies the presumption everyone quotes: a model is presumed to have high-impact capabilities when the cumulative amount of computation used for its training, measured in floating point operations, is greater than 1025. Article 51(3) lets the Commission amend that threshold by delegated act, and Annex XIII lists the criteria — parameter count, dataset quality and size, modality, benchmark performance, reach, number of registered end users — that feed the qualitative assessment.
Two things follow from the word presumed. A provider above the threshold may argue that its model exceptionally does not present systemic risk, and Article 52(2) allows that argument to be put to the Commission with substantiated reasons; if the Commission is not convinced, the classification stands. And a model below the threshold is not safe: the Commission can designate it under Article 51(1)(b) on the Annex XIII criteria. The FLOP figure is a trigger, not a boundary.
The two-week notification duty
Article 52(1) requires a provider to notify the Commission without delay, and in any event within two weeks, after the requirement in Article 51(1)(a) is met or it becomes known that it will be met. That second limb is the one that catches people: the clock can start before the training run finishes, at the point the provider knows the planned run will cross the threshold. A provider that waits for release has already missed it.
The Commission maintains a public list of general-purpose AI models with systemic risk under Article 52(6). Being on that list is what turns Article 55 on.
The four duties Article 55 adds
Article 55(1) is a short list with a large surface area. These sit on top of the Article 53 obligations, which continue to apply — the systemic-risk provider still owes technical documentation, downstream information, a copyright policy and a training content summary.
- Model evaluation, including adversarial testing. Article 55(1)(a) requires evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing with a view to identifying and mitigating systemic risks. “Documenting” is the operative word: red-teaming that leaves no record does not evidence the duty.
- Assessing and mitigating systemic risks at Union level. Article 55(1)(b) covers risks arising from development, placing on the market or use, including their sources. This is the duty with the least determinate content and the most weight, because it is where the provider has to say what risks it thinks its model creates.
- Tracking, documenting and reporting serious incidents. Article 55(1)(c) requires keeping track of relevant information about serious incidents and possible corrective measures, and reporting them without undue delay to the AI Office and, as appropriate, to national competent authorities.
- Adequate cybersecurity protection. Article 55(1)(d) covers both the model and its physical infrastructure. The concern is model weight exfiltration and unauthorised access, not only ordinary IT security — a stolen frontier checkpoint is a systemic risk that no downstream control can recover from.
Article 55(2) then adds the compliance route: providers may rely on codes of practice to demonstrate compliance until a harmonised standard is published, and adherence carries a presumption of conformity. That mechanism is described on the GPAI Code of Practice page. Article 55(3) requires providers not adhering to a code to demonstrate compliance by alternative adequate means for the Commission's assessment.
What counts as a serious incident
The definition is in Article 3(49) and it is shared with the high-risk incident regime, which is why the serious incident reporting page is worth reading alongside this one. It covers an incident or malfunctioning that directly or indirectly leads to death or serious harm to health, a serious and irreversible disruption of the management or operation of critical infrastructure, infringement of Union law obligations intended to protect fundamental rights, or serious harm to property or the environment.
Note the fourth limb. “Serious harm to property or the environment” is broad, and the fundamental-rights limb is broader still: it makes an incident reportable by reference to a legal consequence rather than a physical one. Article 55(1)(c) does not restate the graduated deadlines that Article 73 imposes for high-risk systems; it says without undue delay, which is a standard rather than a clock.
What is still unresolved
It is worth being explicit about how much of this is not settled, because the confident summaries are the ones to distrust.
- What counts as adequate evaluation. Article 55(1)(a) defers to “standardised protocols and tools reflecting the state of the art”. Those protocols are still being written; the harmonised standards work at CEN-CENELEC JTC 21 had not produced a published standard covering this at the time of writing.
- Where fine-tuning creates a new provider. Recital 109 addresses downstream modification, but the point at which a party that fine-tunes a systemic-risk model becomes a provider of a systemic-risk model in its own right is not crisply defined, and the answer determines who owes Article 55 at all.
- Whether the 1025 threshold survives. It is amendable by delegated act under Article 51(3), and it was chosen as a proxy for capability rather than as a measurement of it. Training efficiency improvements pull in the direction of it being too high; nothing about the mechanism guarantees it moves.