Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
Context fileUnder EU AI Act, Article 55(1)(c)
What does it require?
Providers of general-purpose AI models with systemic risk must keep track of, document and report without undue delay to the AI Office and, where relevant, to national competent authorities the relevant information about serious incidents and the possible corrective measures to address them. The General-Purpose AI Code of Practice sets out timelines and content that providers may follow to demonstrate compliance.
Practical action
Define serious-incident criteria for the model, a tracking log and an AI Office notification template with owner and clock.
Who does it apply to?
Providers of general-purpose AI models classified as having systemic risk under Article 51.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesProcessIncident coordinator · continuousAI incident management and regulatory reporting
Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority
Model-level incident criteria, log and AI Office reporting.
-
supportsPolicyHead of AI safety · annualFrontier model safety and security framework
Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority
Framework defines the incident types and escalation.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Serious incident tracking log for the model | register | |
| AI Office incident notification | document |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 10.2; Annex A.8.4 | Corrective action and incident communication. | high |
| NIST AI RMF 1.0 | MANAGE 4.3, MEASURE 3.1 | Incident response and tracking of emergent risks. | high |
Cite this record
AIPolicyTracker (2026). “Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Report serious incidents to market surveillance authorities — EU AI Act, European Union
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI — EU AI Act, European Union
- Implement reasonable security safeguards and notify breaches — India DPDP Act, India
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States)
- Developers must notify the Attorney General and deployers of discovered algorithmic discrimination — Colorado AI Act, Colorado (United States)
- Deployers must notify the Attorney General of discovered algorithmic discrimination — Colorado AI Act, Colorado (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.