Providers of systemic-risk GPAI models must secure the model and its infrastructure
Context fileUnder EU AI Act, Article 55(1)(d)
What does it require?
Providers of general-purpose AI models with systemic risk must ensure an adequate level of cybersecurity protection for the model and for the physical infrastructure it runs on, which in practice covers protection of model weights, training and inference environments, and access controls against theft, tampering and unauthorised release. Codes of practice and harmonised standards may be used to show compliance.
Practical action
Apply a documented security standard to weight storage, training clusters and inference endpoints, with penetration tests and insider-risk controls.
Who does it apply to?
Providers of general-purpose AI models classified as having systemic risk under Article 51.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesTechnical measureQuality or testing lead · at launch and on material changeAccuracy, robustness, fairness and security testing
Serves 15 recorded duties · evidence: Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Security testing of the model and its serving infrastructure.
-
supportsPolicyHead of AI safety · annualFrontier model safety and security framework
Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Framework commits to the weight-security measures.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Model and infrastructure security assessment | report | |
| Weight access control records | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 27001:2022 | Clause 8.1; Annex A 5.15, A 8.24 | Access control and cryptography applied to model assets. | medium |
| NIST AI RMF 1.0 | MEASURE 2.7, MANAGE 2.2 | Security and resilience of the system. | medium |
| MITRE ATLAS | AML.M0005, AML.M0001 | Control access to models and limit artifact release. | medium |
Cite this record
AIPolicyTracker (2026). “Providers of systemic-risk GPAI models must secure the model and its infrastructure (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-cybersecurity (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Achieve appropriate accuracy, robustness and cybersecurity — EU AI Act, European Union
- Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool — NYC Local Law 144 (automated employment decision tools), New York (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.