Praxikon
All obligations
Applicablev1.0.0

Article 55: GPAI models with systemic risk

Additional duties for the most capable general-purpose AI models, on top of Article 53.

The official source remains authoritative. This general interpretation is not legal advice.

Status
Applicable
Application date
2 August 2025
Version
1.0.0
Last reviewed
8 August 2026

Who this is relevant to

When this applies

  • Provider of a GPAI model

    A party that places a general-purpose AI model on the Union market.

  1. 1The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission.

What the official source establishes

Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.

Our interpretation

The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.

What you can do now

Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.

  1. 01

    Perform model evaluations and risk mitigation

    Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.

What to retain

Systemic-risk file

Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.

Control and reassessment

  • Compute threshold monitoring

    Monitor cumulative training compute and notify the Commission when the threshold is reached.

Public tools

Conditions and exceptions

  • The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 55(1)-(2) with Article 51 and Article 52

What changed in this

Moments when this obligation took effect, moved or received official guidance.

  • 2027-08-02 | upcoming

    Legacy GPAI models must comply

    Models placed on the market before 2 August 2025 have until 2 August 2027.

  • 2025-08-02 | applicable

    GPAI model obligations apply

    Since 2 August 2025 the obligations for providers of general-purpose AI models apply.

  • 2025-07-18 | guidance

    Guidelines on the scope of the GPAI obligations

    The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.

See the full timeline

What member states are doing with this

Dated signals from the enforcement tracker that refer to this obligation.

  • EU | 2026-08-02 | Europese Commissie / AI Office

    GPAI and Article 50 enforcement powers active

    Since 2 August 2026 the European Commission, through the AI Office, can enforce the GPAI obligations and national authorities are competent to enforce the Article 50 transparency obligations. Most other AI Act obligations also apply from this date.

    Europese Commissie (digital-strategy.ec.europa.eu)

  • EU | 2025-07-18 | Europese Commissie / AI Office

    Guidelines for providers of general-purpose AI models

    The Commission publishes guidelines clarifying who qualifies as a provider of a general-purpose AI model, when a model poses systemic risk and how the AI Office will apply the GPAI obligations, including exemptions for certain open-source models. Together with the GPAI Code of Practice, these guidelines form the enforcement framework the AI Office relies on since 2 August 2026.

    Europese Commissie (digital-strategy.ec.europa.eu)

  • EU | 2025-07-10 | Europese Commissie / AI Office

    GPAI Code of Practice published

    The AI Office publishes the final Code of Practice for providers of general-purpose AI models, with chapters on transparency, copyright and safety and security. The Commission and the AI Board subsequently assess the code as an adequate voluntary tool to demonstrate compliance with the GPAI obligations. 21 organisations sign the full code, including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI and Mistral AI; xAI signs only the safety and security chapter and must demonstrate compliance with the transparency and copyright obligations via alternative means. It is followed shortly by the guidelines on the scope of GPAI obligations (18 July 2025) and the training-data summary template (24 July 2025).

    Europese Commissie (digital-strategy.ec.europa.eu)

Open the enforcement tracker

Version history

  1. v1.0.0

    2 August 2025

    Article 55: GPAI models with systemic risk

    Additional duties for the most capable general-purpose AI models, on top of Article 53.

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.