AI governance glossary
Systemic risk (general-purpose AI)
Definition
Under the EU AI Act, a general-purpose AI model has systemic risk when it has high-impact capabilities, which is presumed when the cumulative compute used to train it exceeds 10²⁵ floating-point operations, or when the Commission designates it. Such models carry extra duties: model evaluation including adversarial testing, assessing and mitigating systemic risks, reporting serious incidents, and cybersecurity protection.
Source: EU AI Act (Regulation (EU) 2024/1689). A plain-language explanation for orientation, not the legal text; follow the source for the binding wording.
Frontier model safety framework control →Red-team testing control →
Laws and policies on record that use it
- EU AI ActEuropean Union · Partially applicable
Duties that mention it
- Meet general-purpose AI model provider obligationsEU AI Act · European Union
- Manage systemic risk for high-impact general-purpose modelsEU AI Act · European Union
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk thresholdEU AI Act · European Union
- Providers of GPAI models must maintain technical documentation and inform downstream providersEU AI Act · European Union
- Non-EU providers of GPAI models must appoint an EU authorised representativeEU AI Act · European Union
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI OfficeEU AI Act · European Union
- Providers of systemic-risk GPAI models must secure the model and its infrastructureEU AI Act · European Union
Related terms
- General-purpose AI model (GPAI)An AI model, typically trained on a large amount of data with self-supervision at scale, that shows significan...
- Serious incidentAn incident or malfunction of an AI system that directly or indirectly leads to death or serious harm to a per...
- Red teaming (AI)Structured adversarial testing in which testers try to make an AI system fail: produce harmful output, leak da...
All glossary terms · Think a definition is off? Tell us; corrections are logged on the corrections page.
Frequently asked questions
What does "Systemic risk" mean?
Under the EU AI Act, a general-purpose AI model has systemic risk when it has high-impact capabilities, which is presumed when the cumulative compute used to train it exceeds 10²⁵ floating-point operations, or when the Commission designates it. Such models carry extra duties: model evaluation including adversarial testing, assessing and mitigating systemic risks, reporting serious incidents, and cybersecurity protection.
Where does the term Systemic risk come from?
This explanation follows EU AI Act (Regulation (EU) 2024/1689). It is a plain-language paraphrase for orientation; the source has the binding wording.
Which laws and policies use the term Systemic risk?
Among the records on this site: EU AI Act (EU).