EU AI Act Art. 55: GPAI models with systemic risk
GPAI models with systemic risk: model evaluation incl. adversarial testing; Union-level risk assessment; serious-incident reporting; cybersecurity of the model
AIGE-OBL-EUAIA-ART55. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 55.
- Duty holder: GPAI provider.
- Applies from: 2025-08-02, In force.
- Artefact: Eval and red-team suite.
- Layers: Layer 03, Layer 04, Layer 05.
- Evidence record: Eval result, +1 more.
- Record schemas: Eval result , AI incident record .
- The same topic in 20 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART55- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 55
- Duty holder
- GPAI provider (systemic risk)
- Authority
- AI Office
- Applies from
- In force · Obligations from 2025-08-02; enforcement from 2026-08-02
- Later dates
-
- Commission enforcement powers apply
- GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))
- System class
- GPAI model with systemic risk
The artefact that evidences it
Eval and red-team suite; incident pipeline on the Commission serious-incident reporting template; weight-security controls; threat model.
- L3 Evals & Red Teaming as Evidence
- L4 Runtime Controls & Observability
- L5 Assurance & Continuous Compliance
Patterns that build it
- Eval Gate in CI (layer 3)
- Adversarial Red-Team Suite (layer 3)
- Incident Pipeline (layer 5)
- AI Threat Model (layer 1 and 3)
- Model Artefact Integrity (layer 2 and 4)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored (core)
- TC260 Framework 3.0 TC260 5.3.7 Real-time risk monitoring (core)
- TC260 Framework 3.0 TC260 5.3.18 Incident reporting (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- EU AI Act Art. 26(5) Deployer monitoring, informing the provider and suspending use (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- NIST AI RMF MANAGE 4.3 MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- GAO AI Accountability 4.1 Planning: develop plans for continuous or routine monitoring of the AI system (core)
- GAO AI Accountability 4.2 Drift: establish the range of data and model drift that is acceptable (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
GPAI and foundation models
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework (core)
- Korea AI Act Art. 32 Safety duties for AI above the compute threshold (core)
- EU AI Act Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk
- EU AI Act Art. 56 Codes of practice
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations
- GPAI Code Safety C7 Commitment 7: Safety and Security Model Reports
- CSA AICM MDS-12 Open Model Risk Assessment
- CSA AICM MDS-03 Model Documentation
- Singapore GenAI GenAI 8 Safety and Alignment R&D
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing
- China GenAI Measures GenAI Art. 7 Lawful data and foundation-model sources
Cases that cite this article
- OpenAI agents and Hugging Face: an evaluation environment that was not isolated (2026)
- An agent in training reached a public chatbot through the sandbox DNS resolver (2026)
- An internally deployed model published a researcher's GitHub token in a public repository (2026)
- Agents in training shared a file through a public file-hosting service (2026)
- Training samples exchanged messages through a shared package repository (2026)
- Claude models reached real systems from a misconfigured third-party cyber evaluation (2026)
- Agents in a cyber range with open internet took unsanctioned actions against real people (2026)
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-EVAL-009Evaluation Validity Checks (Evaluation environment profile) -
AIGE-CTL-ASSURE-002Release Blocked Below the Eval Threshold (Assurance and evidence profile) -
AIGE-CTL-ASSURE-010Model Artefacts Signed at Build and Verified Before Load (Assurance and evidence profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art55.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 55: GPAI models with systemic risk (AIGE-OBL-EUAIA-ART55). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 55: GPAI models with systemic risk (AIGE-OBL-EUAIA-ART55)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55},
note = {Version 0.5.0}
}