Home · EU AI Act · Articles · Article 55
EU AI Act · Engineering reference

Article 55 — GPAI Systemic-Risk Obligations

GPAI models above the 10^25 FLOP training-compute threshold carry additional systemic-risk obligations including evaluations, adversarial testing, incident reporting and cybersecurity.

Audit-survivable
18%
of 50 EU-exposed enterprises in MindMap's 2026 readiness benchmark

What the Article requires

Article 55 adds obligations on top of Article 53 for GPAI models with systemic risk — defined as models trained on >= 10^25 FLOPs of compute, or otherwise designated by the AI Office. Obligations: state-of-the-art model evaluations including adversarial testing, assessment and mitigation of systemic risks at Union level, serious-incident tracking and reporting, and adequate cybersecurity protection for the model and its physical infrastructure.

In engineering terms

Article 55 affects very few enterprises directly — the threshold catches frontier-model providers like OpenAI, Anthropic, Google, Mistral. For enterprise integrators the question is which downstream evidence each frontier vendor provides under Article 55 — adversarial-test reports, systemic-risk assessments, incident logs. The vendor disclosures cascade into customer-side Articles 9-15 evidence.

Compliance checklist

  • ✓Confirm whether your GPAI provider crosses the 10^25 FLOP threshold
  • ✓Obtain vendor Article 55 disclosure pack
  • ✓Cascade vendor Article 55 evidence into customer Article 11 documentation
  • ✓Adversarial-test review (vendor-provided)
  • ✓Incident-tracking integration if vendor-managed

Terms used here

GPAI (General-Purpose AI)EU AI ActAnnex III high-risk AI

All Articles in the reference · The EU AI Act compliance architecture

Need audit-survivable evidence for Article 55?

MindMap runs a 90-day path from standing start to audit-survivable evidence. Talk to the engineering team.

Download the whitepaper →Check your tier →Book a scoping call →