What it’s about: an additional tier of obligations for the largest GPAI models
Art. 55 AI Act (EU) 2024/1689 targets a small but particularly significant group: providers of general-purpose AI (GPAI) models classified as models “with systemic risk”. These obligations do not replace but come in addition to the general GPAI obligations under Art. 53 and Art. 54. The GPAI obligations as a whole – including Art. 55 – have already applied since 02.08.2025. Anyone providing such a model cannot rely on an ongoing transition period; the clock is running.
In practical terms: if you train a foundation model that is classified as posing systemic risk because of its capabilities (such as training compute) or has been designated as such by the Commission, four concrete sets of obligations apply from now on.
The four obligations in detail
Art. 55(1) requires:
- State-of-the-art model evaluation (point (a)): You must use standardised protocols and tools to identify and mitigate systemic risks. This expressly includes conducting and documenting adversarial testing of the model. A one-off internal quality check is not sufficient – what is required is a repeatable, documented procedure.
- Assessment and mitigation of union-wide systemic risks (point (b)): You must assess not only the risks of your own use, but also possible impacts that may arise from the development, placing on the market, or use of the model across the Union – including their sources.
- Incident management with a reporting duty (point (c)): Information on serious incidents and possible corrective measures must be recorded and documented. The AI Office and, where relevant, the competent national authorities must be informed without undue delay. “Without undue delay” means: no waiting for the next internal reporting cycle.
- Cybersecurity for the model and infrastructure (point (d)): An adequate level of cybersecurity protection is required not only for the model itself, but also for the physical infrastructure on which it is operated.
All four obligations presuppose robust, ongoing risk management – not a one-off conformity check before market launch.
Codes of practice and standards as a route to compliance
Art. 55(2) opens up a pragmatic route: as long as no harmonised European standard has been published, providers may rely on codes of practice under Art. 56 to demonstrate compliance with the obligations under paragraph 1. Compliance with a harmonised standard even gives rise to a presumption of conformity, insofar as it covers the relevant obligations. Anyone following neither a code of practice nor a standard must demonstrate alternative, adequate means of compliance to the Commission – the more burdensome, less predictable route.
In practice, this means it is worth checking early on whether, and which, codes of practice are relevant to your model, rather than developing your own procedures from scratch and having to justify them to the Commission later.
Confidentiality and typical gaps
Art. 55(3) refers to Art. 78: information and documentation obtained in the course of these obligations are subject to the confidentiality requirements set out there. This does not relieve providers of the reporting duty, but it does protect sensitive information from uncontrolled dissemination.
In practice, three gaps stand out in particular:
- Adversarial testing is missing or undocumented. Many providers carry out internal tests without logging them to the required level of detail – meaning due diligence cannot be demonstrated if it comes to the crunch.
- No process for serious incidents. There is often no clear internal escalation chain that would even enable reporting to the AI Office “without undue delay”.
- Cybersecurity is narrowed down to the model. The physical infrastructure – data centres, access management, supply chains – is often not assessed with the same rigour as the model itself.
Where you stand
If you provide a GPAI model, or work with a provider that does, you should clarify whether a classification as a model with systemic risk is a possibility – and if so, whether your processes for model evaluation, risk mitigation, incident management and cybersecurity already meet the requirements of Art. 55. You can get an initial, free overview of your classification and any open issues at /einstufung.