HAGAHA Farsamada

GPAI Models with Systemic Risk Under the EU AI Act

The EU AI Act treats a general-purpose AI model as systemic-risk when it has high-impact capabilities or the Commission designates it for equivalent capabilities or impact.

  • 3 daqiiqo akhri
  • Markii u dambaysay ee la cusbooneysiiyay
Boggaan3 daqiiqo akhri
  1. Dulmar
  2. quusid qoto dheer
  3. Saamaynta Istiraatijiyadeed
  4. The Future of GPAI Models with Systemic Risk Under the EU AI Act
  5. Dhaqangelinta Adduunka-dhabta ah
  6. Khatarta & Dariiqyada Ilaalada
  7. Qorshe Hawleedka Dhaqangelinta
  8. Sii wad Sahaminta
  9. Su'aalaha soo noqnoqda

Dulmar

More than 10^25 training FLOP creates a presumption of high-impact capability, not an unchallengeable classification; systemic-risk providers have extra evaluation, risk-management, incident-reporting, and cybersecurity duties.

quusid qoto dheer

The AI Act’s systemic-risk category is a subset of general-purpose AI models. Article 51 provides two routes: a model has high-impact capabilities assessed with appropriate tools, indicators, and benchmarks; or the Commission designates it because capabilities or impact are equivalent, using Annex XIII criteria. Training compute above 10^25 floating-point operations creates a presumption of high-impact capability. The number is a threshold in the law and is subject to delegated adjustment; it is not the only way to qualify. Article 52 requires a provider whose model meets the compute condition to notify the Commission without delay, and no later than two weeks after the condition is met or it becomes known that it will be met. The provider may submit substantiated arguments that the model does not, due to its specific characteristics, present systemic risks. The Commission can reject that case or designate a model on its own initiative or following a qualified scientific-panel alert. Commission guidelines describe its interpretation and enforcement approach but are not binding law. Article 55 adds four duties beyond the general GPAI requirements: standardized model evaluation, including documented adversarial testing; assessment and mitigation of possible systemic risks at Union level; documentation and reporting of serious incidents and corrective measures; and adequate cybersecurity for both model and physical infrastructure. These duties are not waived just because a model is distributed under a free and open-source license. Providers can rely on an approved code or harmonised standards while available, or demonstrate alternative adequate means for Commission assessment. GPAI obligations began applying on August 2, 2025. The Commission’s guidance states that its enforcement powers apply from August 2, 2026, and qualifying models already on the market before August 2, 2025 have a compliance transition until August 2, 2027. Providers should track training-compute evidence, expected threshold timing, notification, and any designation decision. This is an overview, not a legal opinion on an individual model.

Saamaynta Istiraatijiyadeed

Qiimaha iyo miisaaniyada

Go'aamada qaab-dhismeedku waxay horseedaan waxqabadka iyo kharashka hawlgalka sannadaha.

Go'aamo cad

Waxbarashada farsamada waxay ka caawisaa kooxaha inay doortaan xidhmo sax ah, ma aha oo kaliya kan ugu cusub.

Xakamaynta tayada

Doorashooyinka injineernimada ee wanaagsan waxay yareeyaan shilalka la isku halleyn karo ee wax soo saarka.

The Future of GPAI Models with Systemic Risk Under the EU AI Act

The Act empowers the Commission to revise compute thresholds and benchmarks as capabilities and hardware efficiency evolve. A provider should not assume today’s FLOP threshold will remain fixed or that falling below it resolves designation risk. Monitor official Commission guidelines and any delegated acts, and review status when a model’s training run, capabilities, distribution, or deployment context changes. Track delegated updates to Annex XIII and any official changes to the compute presumption. Document threshold calculations consistently across training runs. Review changes before each release.

Dhaqangelinta Adduunka-dhabta ah

A provider forecasts training compute above 10^25 FLOP and prepares the Article 52 notification before the threshold is reached.

A provider crossing the threshold submits evidence with its notification explaining why the model’s specific capabilities do not create systemic risk.

A safety team documents adversarial testing, EU-level risk assessments, incident response, and infrastructure security for a designated model.

A company with an open-source systemic-risk model checks Article 55 duties rather than assuming Article 53’s limited exception covers it.

Khatarta & Dariiqyada Ilaalada

  • Hagaajinta hal bartilmaameed waxay qarin kartaa daciifnimada nidaamka ballaaran.

  • Kaabayaasha dhaqaalaha iyo dayactirka inta badan waa la dhayalsadaa.

  • Nabadgelyada iyo daldaloolada u fiirsashada ayaa kori kara marka nidaamyadu noqdaan kuwo aad u adag.

Qorshe Hawleedka Dhaqangelinta

  1. Qeex daahida, tayada, iyo bartilmaameedyada qiimaha ka hor inta aan la hirgelin.

  2. Benchmark marka la eego culeyska dhabta ah iyo xaaladaha xogta.

  3. La socodka qalabka khaladaadka, leexashada, iyo saamaynta isticmaalaha.

  4. U diyaari dib-u-noqoshada iyo dariiqyada jawaab-celinta dhacdada ka hor inta aanad miisaan.

Sii wad Sahaminta

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the GPAI Models with Systemic Risk Under the EU AI Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bilow kedis

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Su'aalaha soo noqnoqda

What is GPAI Models with Systemic Risk Under the EU AI Act?

The EU AI Act treats a general-purpose AI model as systemic-risk when it has high-impact capabilities or the Commission designates it for equivalent capabilities or impact. More than 10^25 training FLOP creates a presumption of high-impact capability, not an unchallengeable classification; systemic-risk providers have extra evaluation, risk-management, incident-reporting, and cybersecurity duties.

What does training compute above 10^25 FLOP do under Article 51?

Article 51(2) presumes high-impact capabilities above the compute threshold, while Article 51 and 52 allow other evidence and procedures.

Which second route can lead to systemic-risk designation besides the compute presumption?

Article 51(1)(b) and Article 52(4) allow Commission designation based on equivalent capabilities or impact using Annex XIII criteria.

When must a provider notify the Commission after a model meets or is expected to meet the compute condition?

Article 52(1) requires notice without delay and no later than two weeks after the condition is met or known to be expected.

Which item is an Article 55 duty for a systemic-risk GPAI provider?

Article 55(1)(a) requires model evaluation under state-of-the-art protocols, including documented adversarial testing.

What does Article 55 require about serious incidents?

Article 55(1)(c) requires tracking, documenting, and reporting serious-incident information and possible corrective measures.