Governance

General-Purpose AI Model with Systemic Risk

A general-purpose AI model legally designated as carrying risks that can affect the EU market or society at scale, subject to heightened obligations under the EU AI Act.

Definition

Official/legal definition: Under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), a general-purpose AI model with systemic risk is a general-purpose AI model that meets either (a) it has high-impact capabilities as evaluated by appropriate technical tools, indicators and benchmarks, or (b) the model is designated by the Commission (ex officio or following a qualified alert from the scientific panel) as having equivalent capabilities or impact, having regard to the criteria set out in Annex XIII. This classification rule and related procedures are set out in Article 51 (classification), Article 52 (procedure) and the Annex XIII criteria of the Regulation. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Context and scope: The term builds on the Act's definitions of general-purpose AI model (an AI model that displays significant generality and can competently perform a wide range of distinct tasks) and of systemic risk at Union level (risks that, because of reach or scale, may have significant impact on the internal market or cause actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights or society as a whole). The Act presumes that a model has "high-impact capabilities" (and therefore qualifies as systemic) when the cumulative compute used for its training, measured in floating-point operations (FLOPs), exceeds 10^25, while also empowering the Commission to use alternative or supplementary benchmarks and to update thresholds by delegated act. The criteria the Commission may consider when deciding designation are listed in Annex XIII (for example: number of parameters, data quality/size, compute used, input/output modalities, benchmark results, market reach and numbers of users). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Practical implications for businesses and providers: If a provider's general-purpose AI model is classified as a model with systemic risk, the provider becomes subject to a set of enhanced, substantive obligations under the Act beyond the baseline GPAI transparency duties. Those obligations include, inter alia: timely notification to the Commission when the threshold/condition is met (see Article 52 — notification within two weeks after the requirement is met or is reasonably foreseen); conducting standardized model evaluation and documented adversarial testing; assessing and mitigating systemic risks that could arise at Union level; prompt reporting of serious incidents and corrective measures to the AI Office and competent authorities; and ensuring adequate cybersecurity and protection of the model's physical infrastructure. Providers may rely on approved codes of practice or harmonised standards where available; otherwise they must demonstrate alternative adequate means of compliance. These obligations effectively require larger governance, monitoring, testing and incident-response programmes for affected providers. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Key requirements / criteria (summary):

  • A model meets the systemic-risk classification if it has high-impact capabilities as evaluated using technical tools and benchmarks, or if the Commission designates it as having equivalent capabilities (Article 51). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Presumption threshold: cumulative training compute > 10^25 FLOPs creates a presumption of high-impact capability (Article 51(2)); the Commission may amend thresholds by delegated act. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Annex XIII criteria (non-exhaustive) that the Commission may use include: number of parameters; dataset quality/size; compute used; modalities; benchmark and evaluation results; market reach (e.g., made available to at least 10,000 registered EU business users); and number of registered end-users. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Procedural duty: providers meeting the technical condition must notify the Commission without delay and within two weeks; the provider may submit evidence to rebut systemic-risk classification but the Commission decides following the procedure (Article 52). ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Examples and cross-references: Typical examples discussed in commentary and enforcement guidance include large-scale foundation models / large multimodal models (e.g., advanced large language or multimodal models) whose training compute, capability breadth, and market reach make them candidates for systemic designation. Businesses should cross-reference the definitions and obligations for general-purpose AI model (Article 3(63)), high-impact capabilities (Article 3(64)), and systemic risk (Article 3(65)), and consult the Act's Annex XIII and Articles 52–55 for procedure and provider obligations. In addition to meeting the Regulation's requirements, developers and deployers are advised to apply technical risk-management frameworks and profiles (e.g., NIST AI RMF / Generative AI Profile) and relevant ISO guidance on AI risk management to operationalize testing, evaluation and incident response. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Sources

  • EU AI Act Article 51
  • EU AI Act Article 55