Article 55 — GPAI Systemic-Risk Obligations
GPAI models above the 10^25 FLOP training-compute threshold carry additional systemic-risk obligations including evaluations, adversarial testing, incident reporting and cybersecurity.
What the Article requires
Article 55 adds obligations on top of Article 53 for GPAI models with systemic risk — defined as models trained on >= 10^25 FLOPs of compute, or otherwise designated by the AI Office. Obligations: state-of-the-art model evaluations including adversarial testing, assessment and mitigation of systemic risks at Union level, serious-incident tracking and reporting, and adequate cybersecurity protection for the model and its physical infrastructure.
In engineering terms
Article 55 affects very few enterprises directly — the threshold catches frontier-model providers like OpenAI, Anthropic, Google, Mistral. For enterprise integrators the question is which downstream evidence each frontier vendor provides under Article 55 — adversarial-test reports, systemic-risk assessments, incident logs. The vendor disclosures cascade into customer-side Articles 9-15 evidence.
Compliance checklist
- ✓Confirm whether your GPAI provider crosses the 10^25 FLOP threshold
- ✓Obtain vendor Article 55 disclosure pack
- ✓Cascade vendor Article 55 evidence into customer Article 11 documentation
- ✓Adversarial-test review (vendor-provided)
- ✓Incident-tracking integration if vendor-managed
Terms used here
All Articles in the reference · The EU AI Act compliance architecture
Need audit-survivable evidence for Article 55?
MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.