# GPAI Systemic Risk — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/general-purpose-ai-models-systemic-risk
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses the classification and identification of general-purpose AI models that present systemic risk, which is a distinct regulatory category under the AI Act that requires dedicated coverage separate from general high-risk AI classification.

## Overview

## Legal Framework

The AI Act establishes a distinct regulatory category for general-purpose AI models presenting systemic risk, governed primarily by Article 55 and enforced under Article 88. Article 55 imposes specific obligations on providers of GPAI models classified as carrying systemic risk, separate from the general high-risk AI regime in Articles 6 and following.

A GPAI model is presumed to present systemic risk if the cumulative amount of compute used for its training exceeds 10^25 FLOPs. The European Commission retains the authority to designate additional models as carrying systemic risk based on criteria including the model's capabilities, its intended or foreseeable use, and the scale of its deployment. This dual-track classification—presumptive threshold plus discretionary designation—ensures that both compute-intensive frontier models and emerging models with demonstrable systemic impact fall within scope.

Article 55 requires providers to perform model evaluations, including conducting and documenting adversarial testing to identify and mitigate systemic risks. Providers must implement a serious incident reporting mechanism, track and document relevant information about the model's capabilities and limitations, and ensure adequate levels of cybersecurity protection. These obligations build on the baseline transparency requirements applicable to all GPAI providers under Article 53, adding a layer of risk management calibrated to models whose capabilities or deployment scale could generate broader societal harm.

Article 88 establishes the enforcement architecture, vesting the AI Office with primary responsibility for monitoring and enforcing compliance with GPAI obligations. Member State authorities are precluded from separately enforcing these provisions, centralizing oversight to avoid fragmentation.

## Key Developments

The AI Act's GPAI systemic risk provisions entered into force on August 1, 2024, with the relevant obligations becoming applicable on August 2, 2025. The Commission has been developing implementing acts to operationalize the GPAI Code of Practice, which providers may rely on to demonstrate compliance. The Code functions as a presumptive compliance mechanism: adherence creates a presumption of conformity with Article 55 obligations, though providers retain the alternative of demonstrating compliance through other means.

The Commission's designation power under the systemic risk criteria remains untested, but the 10^25 FLOPs threshold provides a bright-line presumptive trigger. Providers whose models approach this threshold should anticipate classification and prepare compliance documentation in advance. The AI Office's enforcement discretion under Article 88 will likely focus initially on frontier model developers, with graduated enforcement reflecting the novelty of the regime.

## Practical Guidance

- **Calculate and document cumulative training compute** for every GPAI model you develop. Maintain auditable records demonstrating whether the 10^25 FLOPs threshold is approached or exceeded, as this determination triggers Article 55 obligations automatically.

- **Establish a model evaluation and adversarial testing protocol** before placing any GPAI model on the market. Article 55 requires documented evaluations identifying systemic risks, with mitigation measures proportionate to identified vulnerabilities.

- **Implement a serious incident reporting pipeline** capable of detecting, documenting, and notifying the AI Office of incidents involving your GPAI model. This must be operational before deployment, not retrofitted after an incident occurs.

- **Adopt the GPAI Code of Practice** once finalized, as adherence creates a presumption of conformity with Article 55. If relying on alternative compliance measures, ensure your documentation independently addresses each Article 55 obligation with equivalent rigor.

- **Centralize compliance oversight** within a designated function reporting to the AI Office, as Article 88 concentrates enforcement at the EU level. Coordinate technical documentation, incident response, and Commission liaison through a single accountable structure to avoid fragmented reporting.

## Legislation (full text of key provisions)

### Obligations for providers of general-purpose AI models

*Source: AI Act, aiact-art-53-en, 2024-06-12 — https://overview.legal/posts/92790*

### Authorised representatives of providers of general-purpose AI models

*Source: AI Act, aiact-art-54-en, 2024-06-12 — https://overview.legal/posts/92812*

### Obligations of providers of general-purpose AI models with systemic risk

*Source: AI Act, aiact-art-55-en, 2024-06-12 — https://overview.legal/posts/92830*

### Enforcement of the obligations of providers of general-purpose AI models

*Source: AI Act, aiact-art-88-en, 2024-06-12 — https://overview.legal/posts/93401*

### Procedural rights of economic operators of the general-purpose AI model

*Source: AI Act, aiact-art-94-en, 2024-06-12 — https://overview.legal/posts/93470*

Article 18 of Regulation (EU) 2019/1020 shall apply mutatis mutandis to the providers of the general-purpose AI model, without prejudice to more specific procedural rights provided for in this Regulation.

### Fines for providers of general-purpose AI models

*Source: AI Act, aiact-art-101-en, 2024-06-12 — https://overview.legal/posts/93587*

### AI systems already placed on the market or put into service and general-purpose AI models already placed on the marked

*Source: AI Act, aiact-art-111-en, 2024-06-12 — https://overview.legal/posts/93631*

### Classification of general-purpose AI models as general-purpose AI models with systemic risk

*Source: AI Act, aiact-art-51-en, 2024-06-12 — https://overview.legal/posts/92764*

### Mutual assistance, market surveillance and control of general-purpose AI systems

*Source: AI Act, aiact-art-75-en, 2024-06-12 — https://overview.legal/posts/93253*

### Recital 112 — general-purpose AI systemic risk classification procedure

*Source: AI Act, aiact-rec-112-en, 2024-06-12 — https://overview.legal/posts/93906*

It is also necessary to clarify a procedure for the classification of a general-purpose AI model with systemic risks. A general-purpose AI model that meets the applicable threshold for high-impact capabilities should be presumed to be a general-purpose AI models with systemic risk. The provider should notify the AI Office at the latest two weeks after the requirements are met or it becomes known that a general-purpose AI model will meet the requirements that lead to the presumption. This is especially relevant in relation to the threshold of floating point operations because training of general-purpose AI models takes considerable planning which includes the upfront allocation of compute resources and, therefore, providers of general-purpose AI models are able to know if their model would meet the threshold before the training is completed. In the context of that notification, the provider should be able to demonstrate that, because of its specific characteristics, a general-purpose AI model exceptionally does not present systemic risks, and that it thus should not be classified as a general-purpose AI model with systemic risks. That information is valuable for the AI Office to anticipate the placing on the market of general-purpose AI models with systemic risks and the providers can start to engage with the AI Office early on. That information is especially important with regard to general-purpose AI models that are planned to be released as open-source, given that, after the open-source model release, necessary measures to ensure compliance with the obligations under this Regulation may be more difficult to implement.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

### Artificial intelligence: the action plan of the CNIL

*Source: CNIL, 2023-05-16 — https://overview.legal/posts/6206 — original: https://www.cnil.fr/en/artificial-intelligence-action-plan-cnil#entry-5218*

The main thing is:

The CNIL has been undertaking work for several years to anticipate and respond to the issues raised by AI.
In 2023, it will extend its action on augmented cameras and wishes to expand its work to generative AIs, large language models and derived applications (especially chatbots).
Its action plan is structured around four strands:

to understand the functioning of AI systems and their impact on people;
enabling and guiding the development of privacy-friendly AI;
federate and

## Related topics

- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **AI Office Establishment and Role** — https://overview.legal/topics/ai-office-establishment-role
  The AI Office is a new institutional body created by the AI Act with specific establishment procedures, roles, responsibilities, and governance structures that 
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Authority Cooperation** — https://overview.legal/topics/cooperation-with-authorities-ai
  This new topic is needed because the AI Act establishes specific cooperation and coordination mechanisms between AI providers/deployers and competent authoritie

---
Generated by overview.legal · https://overview.legal/topics/general-purpose-ai-models-systemic-risk · 2026-08-22
