Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
Context fileUnder EU AI Act, Article 52(1)
What does it require?
A provider whose general-purpose AI model meets the Article 51(1)(a) high-impact capability condition, which is presumed once cumulative training compute exceeds 10^25 floating-point operations, must notify the Commission without delay and in any event within two weeks of the condition being met or of learning that it will be met. The notification may include arguments that the model nonetheless does not present systemic risk; the Commission decides and keeps a public list of designated models.
Practical action
Track cumulative training compute per model against the threshold and pre-draft the notification and any rebuttal arguments.
Who does it apply to?
Providers of general-purpose AI models approaching or exceeding the compute threshold, including during training.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesPolicyHead of AI safety · annualFrontier model safety and security framework
Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Compute tracking and threshold notification are part of the framework.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Training compute tracking record | register | |
| Notification to the Commission | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 4.2; Annex A.8.3 | Interested-party requirements and external reporting. | low |
| NIST AI RMF 1.0 | GOVERN 1.1, MAP 1.1 | Legal requirement tracking and system context. | medium |
Cite this record
AIPolicyTracker (2026). “Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-52-systemic-risk-notification (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.