EU AI Act Art. 55: GPAI models with systemic risk

GPAI models with systemic risk: model evaluation incl. adversarial testing; Union-level risk assessment; serious-incident reporting; cybersecurity of the model

From clause to evidenceThe chain from EU AI Act Art. 55 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI ActArt. 55Duty holderGPAI providerApplies from2025-08-02In forceArtefactEval andred-team suiteLayersLayer 03Layer 04Layer 05Evidence recordEval result+1 moreSame topic in 20 frameworks (73 clauses): EU AI Act, ISO 42001, NIST AI RMF, TC260 Framework 3.0, China Deep Synthesis,GB/T 45654, GPAI Code and 13 moreAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from EU AI Act Art. 55 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI Act · Art. 55Duty holderGPAI providerApplies from2025-08-02 · In forceArtefactEval and red-team suiteLayersLayer 03Layer 04Layer 05Evidence recordEval result · +1 moreSame topic in 20 frameworks (73 clauses): EUAI Act, ISO 42001, NIST AI RMF, TC260Framework 3.0, China Deep Synthesis and 15…As of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-EUAIA-ART55. Drawn from chapter 08.
Text alternative
  • Clause: EU AI Act, Art. 55.
  • Duty holder: GPAI provider.
  • Applies from: 2025-08-02, In force.
  • Artefact: Eval and red-team suite.
  • Layers: Layer 03, Layer 04, Layer 05.
  • Evidence record: Eval result, +1 more.
  • Record schemas: Eval result , AI incident record .
  • The same topic in 20 other frameworks; the crosswalk section below links each clause.
Id
AIGE-OBL-EUAIA-ART55
Instrument
EU AI Act (post-Omnibus) law
Compared side by side
ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
Clause
Art. 55
Duty holder
GPAI provider (systemic risk)
Authority
AI Office
Applies from
In force · Obligations from 2025-08-02; enforcement from 2026-08-02
Later dates
  • Commission enforcement powers apply
  • GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))
System class
GPAI model with systemic risk

The artefact that evidences it

Eval and red-team suite; incident pipeline on the Commission serious-incident reporting template; weight-security controls; threat model.

Patterns that build it

The same topic in other frameworks

From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.

Robustness, security and evaluations

Incident response and monitoring

Cases that cite this article

Open controls that evidence it

Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.

Source

Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). EU AI Act Art. 55: GPAI models with systemic risk (AIGE-OBL-EUAIA-ART55). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{EU AI Act Art. 55: GPAI models with systemic risk (AIGE-OBL-EUAIA-ART55)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55},
  note         = {Version 0.5.0}
}