Article 55

EU AI Act Article 55 — GPAI Models with Systemic Risk

Article 55 of Regulation (EU) 2024/1689 sets additional obligations for general-purpose AI models with systemic risk. Model evaluation, adversarial testing, incident tracking, and the 10^25 FLOP designation threshold.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 55 actually requires

Article 55 of Regulation (EU) 2024/1689 sets additional obligations on providers of GPAI models classified as carrying systemic risk under Article 51.

A GPAI model has systemic risk when it has high-impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks. The Regulation sets a default presumption of systemic risk when the cumulative amount of computation used for training, measured in floating-point operations, is greater than 10^25 FLOPs (Article 51(2)).

The Commission may designate models as systemic-risk based on capabilities, the number of parameters, the quality or size of the dataset, the input/output modality, the degree of autonomy, the impact on the internal market, the number of registered end users, etc.

The four additional obligations

Providers of systemic-risk GPAI models must, in addition to Article 53 duties:

  • (a) Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.
  • (b) Assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of GPAI models with systemic risk.
  • (c) Keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them.
  • (d) Ensure an adequate level of cybersecurity protection for the GPAI model with systemic risk and the physical infrastructure of the model.

Who is covered

Initially, frontier-lab providers (OpenAI, Anthropic, Google DeepMind, Meta, Mistral, etc.) whose state-of-the-art models exceed the 10^25 FLOP presumption threshold or are otherwise designated by the Commission.

What to do

  • If your training run exceeds 10^25 FLOPs, notify the Commission without delay (Article 52(1)).
  • Build a model-evaluation programme aligned with state-of-the-art protocols. The AI Office is publishing reference protocols.
  • Run adversarial-testing campaigns on the model itself (red-teaming) and document outcomes.
  • Maintain a serious-incident register tied to the Article 73 / 79 reporting flow.
  • Cybersecurity-harden the model: weights protection, supply-chain integrity, physical security of the training infrastructure.

The AI Office is developing codes of practice under Article 56 to operationalise Article 55. Adherence to an approved code of practice creates a presumption of compliance.

Inline crosswalk

  • ISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systems.
  • NIST AI RMF MEASURE 2.7 — Security and resilience evaluated and documented.
  • NIST AI RMF MANAGE 4.3 — Incidents and errors communicated to relevant AI Actors.

Penalties

Article 101 fines for GPAI obligations — up to €15 million or 3% of worldwide annual turnover, whichever is higher.


Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Annex IV · Pro tier · high

    Adversarial-testing results against common attack vectors

    Annex IV(2)(g) requires documentation of cybersecurity measures. Cover data poisoning, model extraction, evasion, and prompt injection with real test results.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
annexiv-cybersecurityISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systemsAdversarial-testing results against poisoning, extraction, evasion and prompt injection evidence the AI-security control of Annex A.6.2.5.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
annexiv-cybersecurityNIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documentedAdversarial-testing results across attack vectors are the documented security/resilience evaluation MEASURE 2.7 calls for.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.