Legal requirement Safety testing and evaluation European Union Partially applicable

Manage systemic risk for high-impact general-purpose models

Under EU AI Act, Articles 51, 52 and 55

Source-linked Open official source

What does it require?

A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.

Practical action

Track training compute against the threshold and prepare a safety and security framework before launch.

Who does it apply to?

Providers of general-purpose AI models meeting the systemic-risk criteria.

Applies from:

Evidence examples

  • Model evaluation and red-teaming reports (report)
  • Commission notification record (record)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
NIST AI RMF 1.0MEASURE 2.x; NIST AI 600-1Evaluation and red-teaming practices.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.