Art. 55

Article 55: Systemic-Risk GPAI Obligations

Article 55 requires providers of GPAI models classified as posing systemic risk to evaluate their models including documented adversarial testing, assess and mitigate systemic risks at Union level, track and report serious incidents to the AI Office, and maintain adequate cybersecurity for the model and its infrastructure. Compliance can be demonstrated through Codes of Practice under Article 56 until harmonised standards exist.

gpai-provider gpai-systemic-risk
When it applies
What it requires
What you keep on file
Commonly misread

Systemic-risk duties under Article 55 are sometimes assumed to only start once the Commission issues a formal classification decision; they apply automatically once the compute threshold is met, unless the provider successfully rebuts the presumption.

Unsettled: The exact sub-paragraph (litera) breakdown within Article 55(1) was not returned with full precision by the primary source consulted in the underlying research; check the EUR-Lex text directly for citation in formal documents.

Recent activity

What regulators published on Art. 55

  1. Loading from the public feed…

Informational content only. Not legal advice and not a substitute for qualified counsel. Dates reflect Regulation (EU) 2026/1744 as of 04 Aug 2026.