Manage systemic risk for high-impact general-purpose models
Under EU AI Act, Articles 51, 52 and 55
What does it require?
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Practical action
Track training compute against the threshold and prepare a safety and security framework before launch.
Who does it apply to?
Providers of general-purpose AI models meeting the systemic-risk criteria.
- Sectors
- Cross-sector / all sectors
- Use cases
- Generative AI and foundation models
Applies from:
Evidence examples
- Model evaluation and red-teaming reports (report)
- Commission notification record (record)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| NIST AI RMF 1.0 | MEASURE 2.x; NIST AI 600-1 | Evaluation and red-teaming practices. | medium |
Similar obligations in other instruments
- Large frontier developers must publish a frontier AI framework — California SB 53, California (United States)
- Measure and test trustworthiness characteristics (Measure) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.