Skip to main content
v2026.11,858 entries · CC-BY 4.0

GPAI Systemic Risk: The EU AI Act Term Explained

What systemic risk means under the EU AI Act, the Article 51 classification test and 10^25 FLOPs presumption, and the Article 55 obligations it triggers once a model is classified.

Written and maintained by CASRAI Editorial Board

Last updated

Under the EU AI Act, most general-purpose AI (GPAI) models owe only a baseline set of obligations — transparency documentation and a copyright policy, both under Article 53. A smaller set of models owe a heavier set of obligations because they’ve been classified as carrying systemic risk. This guide defines that term precisely, explains the compute threshold that triggers it, and covers what changes once a model is classified.

For the baseline obligations and the voluntary Code of Practice that most providers use to demonstrate compliance with them, see The EU AI Act GPAI Code of Practice: What It Is and Who Signed It. This page is narrower: it’s about the systemic-risk classification specifically, which is a distinct, additional layer on top of that baseline.

What “systemic risk” means in the Act

The AI Act defines the term in Article 3(65), as part of its general definitions section. A systemic risk is:

“a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain”

That’s a definition of the risk concept, not a classification test on its own. The actual test — when a specific model gets classified as carrying that risk — is set out separately, in Article 51.

The classification test: Article 51

A general-purpose AI model is classified as a general-purpose AI model with systemic risk if either of two conditions is met:

  • (a) High-impact capabilities — evaluated using appropriate technical tools and methodologies, including indicators and benchmarks; or
  • (b) A Commission determination — made ex officio or following a qualified alert from the scientific panel of independent experts, that the model has capabilities or impact equivalent to (a), assessed against the criteria in Annex XIII.

Article 51 also sets a presumption for (a): a model’s high-impact capabilities are presumed when the cumulative amount of compute used for its training, measured in floating point operations (FLOPs), is greater than 1025. This is the figure most often cited as “the” systemic-risk threshold, but it’s precisely a rebuttable presumption tied to condition (a) — not the only route to classification, and not, on its own, an automatic finding that a given model is unsafe. It’s an administrative trigger for closer scrutiny.

The Commission can adjust this threshold and add further benchmarks by delegated act as the state of the art moves — the Act anticipates that a fixed FLOPs number will need revisiting as algorithmic efficiency improves and less compute produces equivalent capability.

What a provider has to do when the threshold is met

Article 52 sets the notification procedure. A provider whose model meets the compute presumption has to notify the Commission without delay, and in any event within two weeks of the requirement being met. The provider can accompany that notification with substantiated arguments that, despite meeting the compute presumption, the model doesn’t in fact present systemic risks; if the Commission finds those arguments insufficient, it rejects them and the model is treated as a systemic-risk model regardless.

The Commission isn’t limited to waiting on providers to self-report. It can designate a model as carrying systemic risk on its own initiative, or following an alert from the scientific panel, whether or not the compute threshold was met. Once a designation is made, a provider can request reassessment, but only starting six months after the decision and only on the basis of new, objective, and detailed reasons.

What changes once a model is classified: Article 55

Classification isn’t just a label — it adds four obligations under Article 55, on top of the Article 53 baseline every GPAI provider already owes:

  • Model evaluation — perform evaluation against standardised protocols and state-of-the-art tools, including documented adversarial testing.
  • Risk assessment and mitigation — assess and mitigate possible systemic risks at Union level, including their sources, across the model’s development, market placement, and use.
  • Incident tracking and reporting — track, document, and report serious incidents and possible corrective measures to the AI Office without undue delay.
  • Cybersecurity — maintain an adequate level of cybersecurity protection for the model itself and for the physical infrastructure it runs on.

These map directly to Chapter 3 (Safety and Security) of the GPAI Code of Practice, which is the chapter that only systemic-risk signatories need to sign — see the Code of Practice guide for how the other two chapters work and who has signed. A provider can demonstrate compliance with Article 55 by adhering to an approved code of practice, by following a harmonised standard once one exists, or by showing the Commission alternative adequate means.

Has the 2026 AI omnibus changed any of this?

A “Digital Omnibus on AI” package amending the AI Act was adopted in June 2026 and entered into force on 27 July 2026, with most substantive changes applying from 2 August 2026. It’s a real amendment to the Act, so it’s worth checking specifically whether it touched systemic-risk classification. As of this writing, it doesn’t: the amending text’s changes are concentrated elsewhere — simplifying high-risk system requirements, adjusting Article 5 prohibitions, conformity assessment, and related provisions — and don’t modify Article 51, Article 52, Article 55, or the 1025 FLOPs presumption. Treat this as a snapshot rather than a permanent guarantee: the Commission retains the delegated-act power described above to adjust the compute threshold on its own timeline, separate from omnibus legislation.

How CASRAI’s NIKOLAI tracks this

Article 51’s structure — a specific, testable point (the 1025 FLOPs presumption) at which a model crosses into a category requiring additional obligations — is the same conceptual shape CASRAI catalogs independently as the Capability Threshold element in NIKOLAI’s Thresholds and Checkpoints track (N3), alongside how Anthropic, OpenAI, Google DeepMind, and other labs define the thresholds in their own scaling policies. CASRAI tracks the EU AI Act’s compute presumption via NIKOLAI as one more example of that pattern, not as an implementation or interpretation of the Act itself — NIKOLAI is CASRAI’s own, unendorsed reference project, not an EU institution’s or any lab’s endorsed framework. See NIKOLAI’s Thresholds and Checkpoints track.

FAQ

Is 10^25 FLOPs a hard legal line?

No. It’s a rebuttable presumption tied to one of two classification routes (high-impact capabilities). Meeting it triggers a mandatory notification to the Commission, but a provider can argue the model doesn’t actually present systemic risk, and the Commission can also classify a model that falls under the threshold through its own determination.

How is this different from the GPAI Code of Practice?

The Code of Practice is a voluntary compliance instrument; systemic-risk classification is a statutory determination under Article 51 that triggers mandatory Article 55 obligations regardless of whether a provider signs anything. A classified provider typically signs the Code’s Safety and Security chapter as the lowest-friction way to demonstrate Article 55 compliance, but the classification and the obligations exist independent of the Code.

What has to happen once a model is classified?

The provider owes four additional obligations under Article 55: standardised model evaluation with adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting to the AI Office, and adequate cybersecurity for the model and its infrastructure.

Can a provider dispute a systemic-risk classification?

Yes, in two ways: at notification, by submitting substantiated arguments that the model doesn’t present systemic risk despite meeting the compute presumption; or after a Commission designation, by requesting reassessment starting six months later with new, objective, detailed reasons.

Does the 2026 AI omnibus change the compute threshold?

No. The Digital Omnibus on AI package, in force from 27 July 2026 with most provisions applying from 2 August 2026, does not amend Article 51, Article 52, Article 55, or the 1025 FLOPs presumption. Its changes are concentrated in other parts of the Act.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about GPAI Systemic Risk: The EU AI Act Term Explained

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →