Summary: The Act’s regime for general-purpose AI models (as distinct from systems): baseline obligations for all, plus four heavier obligations — including cybersecurity — for models classified as posing systemic risk above a 10²⁵ FLOP training-compute presumption.
Sources: raw/AI-regulations/Regulation - EU - 2024_1689.md (Articles 51–56); raw/Laws/Overview of Guidelines for GPAI Models...md; raw/Laws/Providers of General-Purpose AI Models...md; raw/Laws/Enforcement of Chapter V under the EU AI Act...md
Last updated: 2026-07-28
The systemic-risk threshold
Art 51(1) — a GPAI model is classified as having systemic risk if either:
- (a) “it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks”; or
- (b) the Commission decides so, ex officio or “following a qualified alert from the scientific panel,” using Annex XIII criteria.
Art 51(2) — the presumption: high impact capabilities are presumed “when the cumulative amount of computation used for its training measured in floating point operations is greater than 10²⁵” (source: Regulation - EU - 2024_1689.md).
The Commission may amend the thresholds by delegated act “in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency” (Art 51(3)) — an explicit acknowledgement that a fixed FLOP number decays as a proxy.
Procedure — the two-week clock
Art 52(1) — a provider meeting the 51(1)(a) condition “shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met.”
Note “or it becomes known that it will be met”: the clock can start before training completes. A provider that knows its planned run exceeds the threshold is already on notice.
Art 52(2)–(3) — a provider may argue it exceptionally does not present systemic risk despite meeting the threshold; if the Commission finds the arguments not sufficiently substantiated, it rejects them and the classification stands.
Art 52(5) — reassessment can be requested “at the earliest six months after the designation decision,” and again six months after any decision to maintain it.
Art 52(6) — the Commission publishes and maintains a public list of GPAI models with systemic risk.
Baseline obligations — Art 53 (all GPAI providers)
- (a) Technical documentation of the model including training, testing and evaluation results (Annex XI minimum), for the AI Office and national authorities on request.
- (b) Information and documentation for downstream providers integrating the model (Annex XII minimum), enough to “have a good understanding of the capabilities and limitations.”
- (c) A copyright policy, including identifying and complying with rights reservations under Art 4(3) of Directive (EU) 2019/790 “through state-of-the-art technologies.”
- (d) A “sufficiently detailed summary about the content used for training,” publicly available, on an AI Office template.
The open-source exemption and its limit
Art 53(2) — obligations (a) and (b) do not apply to models “released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available.”
“This exception shall not apply to general-purpose AI models with systemic risks.”
Copyright policy (c) and training-content summary (d) still apply to open-source models. The exemption is narrower than it is often described.
The Commission’s guidelines address when monetisation causes loss of open-source status (source: raw/Laws/Overview of Guidelines for GPAI Models...md).
Systemic-risk obligations — Art 55
In addition to Arts 53 and 54, providers of GPAI models with systemic risk shall (source: Regulation - EU - 2024_1689.md):
- (a) “perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks”;
- (b) “assess and mitigate possible systemic risks at Union level, including their sources”;
- (c) “keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures”;
- (d) “ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.”
Four lines. Article 55(1) is the entire binding cybersecurity and red-teaming requirement for frontier models in EU law. Everything operational lives in the Code of Practice, which is where “adequate level of cybersecurity protection” acquires meaning — see security mitigations.
Note 55(1)(d) covers physical infrastructure, not just the model. Datacentre physical access is in scope.
Codes of practice as the compliance route — Arts 55(2), 56
Providers “may rely on codes of practice… to demonstrate compliance… until a harmonised standard is published.” Compliance with European harmonised standards grants presumption of conformity. Providers who do neither “shall demonstrate alternative adequate means of compliance for assessment by the Commission” (Art 55(2)).
Art 56(9): codes of practice were to be ready “at the latest by 2 May 2025”; failing that by 2 August 2025, the Commission may set common rules by implementing act.
Art 56(7): providers of GPAI without systemic risk may limit adherence to the Art 53 obligations “unless they declare explicitly their interest to join the full code.”
Who counts as a provider
Determining the GPAI model provider — and when a downstream modifier becomes one — is the practical question. The Commission set “relatively high compute-based thresholds for what qualifies as substantial modifications of GPAI models, and currently expects only few modifiers to become GPAI model providers” (source: raw/Laws/Modifying AI Under the EU AI Act...md). See provider-vs-deployer.
Third-country providers must appoint an EU authorised representative by written mandate before placing a model on the Union market (Art 54(1)).
Enforcement asymmetry
Chapter V obligations have applied since 2 August 2025, but “the Commission’s supervision and enforcement powers against GPAI model providers will only come into force on 2 August 2026” (source: raw/Laws/Enforcement of Chapter V under the EU AI Act...md).
A one-year window of binding obligations without Commission enforcement powers. Other routes still operate in that window: national market surveillance authorities may request the Commission exercise its powers, downstream providers may lodge complaints, and the scientific panel may issue qualified alerts (same source). See enforcement-and-penalties and governance bodies.
Confidentiality
Art 53(7) and 55(3): information obtained under these articles, “including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.”
Related pages
- GPAI Code of Practice
- Systemic risk
- serious-incident-reporting
- Automated attack generation — how Art 55(1)(a) adversarial testing gets done