Article 55
EU AI Act Article 55 — GPAI Models with Systemic Risk
Article 55 of Regulation (EU) 2024/1689 sets additional obligations for general-purpose AI models with systemic risk. Model evaluation, adversarial testing, incident tracking, and the 10^25 FLOP designation threshold.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 55 actually requires
Article 55 of Regulation (EU) 2024/1689 sets additional obligations on providers of GPAI models classified as carrying systemic risk under Article 51.
A GPAI model has systemic risk when it has high-impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks. The Regulation sets a default presumption of systemic risk when the cumulative amount of computation used for training, measured in floating-point operations, is greater than 10^25 FLOPs (Article 51(2)).
The Commission may designate models as systemic-risk based on capabilities, the number of parameters, the quality or size of the dataset, the input/output modality, the degree of autonomy, the impact on the internal market, the number of registered end users, etc.
The four additional obligations
Providers of systemic-risk GPAI models must, in addition to Article 53 duties:
- (a) Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.
- (b) Assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of GPAI models with systemic risk.
- (c) Keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them.
- (d) Ensure an adequate level of cybersecurity protection for the GPAI model with systemic risk and the physical infrastructure of the model.
Who is covered
Initially, frontier-lab providers (OpenAI, Anthropic, Google DeepMind, Meta, Mistral, etc.) whose state-of-the-art models exceed the 10^25 FLOP presumption threshold or are otherwise designated by the Commission.
What to do
- If your training run exceeds 10^25 FLOPs, notify the Commission without delay (Article 52(1)).
- Build a model-evaluation programme aligned with state-of-the-art protocols. The AI Office is publishing reference protocols.
- Run adversarial-testing campaigns on the model itself (red-teaming) and document outcomes.
- Maintain a serious-incident register tied to the Article 73 / 79 reporting flow.
- Cybersecurity-harden the model: weights protection, supply-chain integrity, physical security of the training infrastructure.
The AI Office is developing codes of practice under Article 56 to operationalise Article 55. Adherence to an approved code of practice creates a presumption of compliance.
Inline crosswalk
- ISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systems.
- NIST AI RMF MEASURE 2.7 — Security and resilience evaluated and documented.
- NIST AI RMF MANAGE 4.3 — Incidents and errors communicated to relevant AI Actors.
Penalties
Article 101 fines for GPAI obligations — up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Annex IV · Pro tier · high
Adversarial-testing results against common attack vectors
Annex IV(2)(g) requires documentation of cybersecurity measures. Cover data poisoning, model extraction, evasion, and prompt injection with real test results.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
annexiv-cybersecurity | ISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systems | Adversarial-testing results against poisoning, extraction, evasion and prompt injection evidence the AI-security control of Annex A.6.2.5. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
annexiv-cybersecurity | NIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documented | Adversarial-testing results across attack vectors are the documented security/resilience evaluation MEASURE 2.7 calls for. |
Related
Article 53
EU AI Act Article 53 — General-Purpose AI Model Provider Obligations
Articles 51 / 53 / 55
GPAI Compliance — Obligations for General-Purpose AI Model Providers
Article 79
EU AI Act Article 79 — Procedure for AI Systems Presenting a Risk
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.