Skip to main content
Praxikon
All obligations
Applicablev1.0.0

Article 55: GPAI models with systemic risk

Additional duties for the most capable general-purpose AI models, on top of Article 53.

Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure.

Praxikon tracks Article 55: GPAI models with systemic risk under the EU AI Act, checked against the official source on 8 August 2026, citing the source for every statement.

Status
Applicable
Application date
2 August 2025
Version
1.0.0
Last reviewed
8 August 2026

Review status: placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Applicable · 2 August 2025

For whom

Provider of a GPAI model

What you do

Perform model evaluations and risk mitigation

What you record

Systemic-risk file

Who this is relevant to

When this applies

  • Provider of a GPAI model

    A party that places a general-purpose AI model on the Union market.

  1. 1The GPAI model has high-impact capabilities, presumed above 10^25 FLOPs of cumulative training compute, or is designated by the Commission.

What the official source establishes

Article 55 obliges providers of GPAI models with systemic risk to perform model evaluations including adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents, and ensure adequate cybersecurity of model and infrastructure. The duties apply since 2 August 2025; AI Office enforcement is active since 2 August 2026.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

The 10^25 FLOPs threshold is a presumption, not a shield: the Commission can also designate models on capabilities, and fine-tuning on top of an existing model can in some circumstances trigger a qualification of its own.

What you can do now

Model providers near the threshold: set up compute monitoring now and join the Code of Practice to carry the burden of proof.

  1. 01

    Perform model evaluations and risk mitigation

    Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.

What to retain

Systemic-risk file

Evaluation results, risk assessments, mitigations, incident reports and security measures per model version.

Control and reassessment

  • Compute threshold monitoring

    Monitor cumulative training compute and notify the Commission when the threshold is reached.

Public tools

Conditions and exceptions

  • The GPAI Code of Practice can, following the adequacy assessment, serve as a means to demonstrate compliance.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 55(1)-(2) with Article 51 and Article 52

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 55: GPAI models with systemic risk",
praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2025-08-02T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589,
https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-55-gpai-systemic-risk&effective_at=2025-08-02&known_at=2026-08-08&lang=en, accessed 2026-09-07)

Short form

praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk@1.0.0 (sha256 112ee626)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-55-gpai-systemic-risk-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 55: GPAI models with systemic risk},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2025-08-02T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589},
  url          = {https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk},
  urldate      = {2026-09-07},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk@1.0.0",
    "type": "dataset",
    "title": "Article 55: GPAI models with systemic risk",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-55-gpai-systemic-risk",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-55-gpai-systemic-risk",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          7
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2025-08-02T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 112ee62609020ed4f49362f4910ee0bdb9155a472914dad7870a887141a5f589; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-55-gpai-systemic-risk&effective_at=2025-08-02&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

What changed in this

Moments when this obligation took effect, moved or received official guidance.

  • 2027-08-02 | upcoming

    Legacy GPAI models must comply

    Models placed on the market before 2 August 2025 have until 2 August 2027.

  • 2025-08-02 | applicable

    GPAI model obligations apply

    Since 2 August 2025 the obligations for providers of general-purpose AI models apply.

  • 2025-07-18 | guidance

    Guidelines on the scope of the GPAI obligations

    The Commission explains when someone becomes the provider of a GPAI model, including through fine-tuning.

See the full timeline

What member states are doing with this

Dated signals from the enforcement tracker that refer to this obligation.

  • EU | 2026-08-02 | Europese Commissie / AI Office

    GPAI and Article 50 enforcement powers active

    Since 2 August 2026 the European Commission, through the AI Office, can enforce the GPAI obligations and national authorities are competent to enforce the Article 50 transparency obligations. Most other AI Act obligations also apply from this date.

    Europese Commissie (digital-strategy.ec.europa.eu)

  • EU | 2025-07-18 | Europese Commissie / AI Office

    Guidelines for providers of general-purpose AI models

    The Commission publishes guidelines clarifying who qualifies as a provider of a general-purpose AI model, when a model poses systemic risk and how the AI Office will apply the GPAI obligations, including exemptions for certain open-source models. Together with the GPAI Code of Practice, these guidelines form the enforcement framework the AI Office relies on since 2 August 2026.

    Europese Commissie (digital-strategy.ec.europa.eu)

  • EU | 2025-07-10 | Europese Commissie / AI Office

    GPAI Code of Practice published

    The AI Office publishes the final Code of Practice for providers of general-purpose AI models, with chapters on transparency, copyright and safety and security. The Commission and the AI Board subsequently assess the code as an adequate voluntary tool to demonstrate compliance with the GPAI obligations. 21 organisations sign the full code, including Amazon, Anthropic, Google, IBM, Microsoft, OpenAI and Mistral AI; xAI signs only the safety and security chapter and must demonstrate compliance with the transparency and copyright obligations via alternative means. It is followed shortly by the guidelines on the scope of GPAI obligations (18 July 2025) and the training-data summary template (24 July 2025).

    Europese Commissie (digital-strategy.ec.europa.eu)

Open the enforcement tracker

Version history

  1. v1.0.0

    2 August 2025

    Article 55: GPAI models with systemic risk

    Additional duties for the most capable general-purpose AI models, on top of Article 53.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.