GPAI Systemic Risk
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic risk, which is a distinct regulatory category under the AI Act that requires dedicated coverage separate from general high-risk AI classification.
Overview
9 sources · Jul 23, 2026Legal Framework
The AI Act establishes a distinct regulatory category for general-purpose AI models presenting systemic risk, governed primarily by Article 55 and enforced under Article 88. Article 55 imposes specific obligations on providers of GPAI models classified as carrying systemic risk, separate from the general high-risk AI regime in Articles 6 and following.
A GPAI model is presumed to present systemic risk if the cumulative amount of compute used for its training exceeds 10^25 FLOPs. The European Commission retains the authority to designate additional models as carrying systemic risk based on criteria including the model's capabilities, its intended or foreseeable use, and the scale of its deployment. This dual-track classification—presumptive threshold plus discretionary designation—ensures that both compute-intensive frontier models and emerging models with demonstrable systemic impact fall within scope.
Article 55 requires providers to perform model evaluations, including conducting and documenting adversarial testing to identify and mitigate systemic risks. Providers must implement a serious incident reporting mechanism, track and document relevant information about the model's capabilities and limitations, and ensure adequate levels of cybersecurity protection. These obligations build on the baseline transparency requirements applicable to all GPAI providers under Article 53, adding a layer of risk management calibrated to models whose capabilities or deployment scale could generate broader societal harm.
Article 88 establishes the enforcement architecture, vesting the AI Office with primary responsibility for monitoring and enforcing compliance with GPAI obligations. Member State authorities are precluded from separately enforcing these provisions, centralizing oversight to avoid fragmentation.
Key Developments
The AI Act's GPAI systemic risk provisions entered into force on August 1, 2024, with the relevant obligations becoming applicable on August 2, 2025. The Commission has been developing implementing acts to operationalize the GPAI Code of Practice, which providers may rely on to demonstrate compliance. The Code functions as a presumptive compliance mechanism: adherence creates a presumption of conformity with Article 55 obligations, though providers retain the alternative of demonstrating compliance through other means.
The Commission's designation power under the systemic risk criteria remains untested, but the 10^25 FLOPs threshold provides a bright-line presumptive trigger. Providers whose models approach this threshold should anticipate classification and prepare compliance documentation in advance. The AI Office's enforcement discretion under Article 88 will likely focus initially on frontier model developers, with graduated enforcement reflecting the novelty of the regime.
Practical Guidance
Calculate and document cumulative training compute for every GPAI model you develop. Maintain auditable records demonstrating whether the 10^25 FLOPs threshold is approached or exceeded, as this determination triggers Article 55 obligations automatically.
Establish a model evaluation and adversarial testing protocol before placing any GPAI model on the market. Article 55 requires documented evaluations identifying systemic risks, with mitigation measures proportionate to identified vulnerabilities.
Implement a serious incident reporting pipeline capable of detecting, documenting, and notifying the AI Office of incidents involving your GPAI model. This must be operational before deployment, not retrofitted after an incident occurs.
Adopt the GPAI Code of Practice once finalized, as adherence creates a presumption of conformity with Article 55. If relying on alternative compliance measures, ensure your documentation independently addresses each Article 55 obligation with equivalent rigor.
Centralize compliance oversight within a designated function reporting to the AI Office, as Article 88 concentrates enforcement at the EU level. Coordinate technical documentation, incident response, and Commission liaison through a single accountable structure to avoid fragmented reporting.