{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 2,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/obligation.json",
  "self": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art55.json",
  "source": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "obligation": {
    "id": "AIGE-OBL-EUAIA-ART55",
    "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55",
    "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art55.json",
    "framework": "EU AI Act",
    "frameworkId": "eu-ai-act",
    "clause": "Art. 55",
    "obligation": "EU AI Act Art. 55 GPAI models with systemic risk",
    "requirement": "GPAI models with systemic risk: model evaluation incl. adversarial testing; Union-level risk assessment; serious-incident reporting; cybersecurity of the model",
    "artefact": "Eval and red-team suite; incident pipeline on the Commission serious-incident reporting template; weight-security controls; threat model",
    "layers": [
      3,
      4,
      5
    ],
    "dutyHolder": "GPAI provider (systemic risk)",
    "scope": null,
    "authority": "AI Office",
    "appliesFrom": "2025-08-02",
    "appliesStatus": "in-force",
    "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
    "milestones": [
      {
        "date": "2026-08-02",
        "systemClass": [],
        "note": "Commission enforcement powers apply"
      },
      {
        "date": "2027-08-02",
        "systemClass": [],
        "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
      }
    ],
    "systemClass": [
      "gpai-systemic"
    ],
    "patterns": [
      {
        "id": "pattern-eval-gate-in-ci",
        "title": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      },
      {
        "id": "pattern-adversarial-red-team-suite",
        "title": "Adversarial Red-Team Suite",
        "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
      },
      {
        "id": "pattern-incident-pipeline",
        "title": "Incident Pipeline",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
      },
      {
        "id": "pattern-ai-threat-model",
        "title": "AI Threat Model",
        "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
      },
      {
        "id": "pattern-model-artefact-integrity",
        "title": "Model Artefact Integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      }
    ],
    "crosswalkTopics": [
      "robustness-security-evals",
      "incident-monitoring",
      "gpai-foundation-models"
    ],
    "reviewed": "2026-09-24",
    "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
  }
}
