GPAI model with systemic risk
The most powerful general-purpose AI models, those large enough or capable enough to potentially affect critical systems across society, which face the strictest rules under the EU AI Act.
The Simple Version
The most powerful general-purpose AI models, those large enough or capable enough to potentially affect critical systems across society, which face the strictest rules under the EU AI Act.
Detailed Explanation
Article 51 establishes systemic-risk classification for GPAI models. Once designated, providers must perform adversarial testing ('red teaming'), report serious incidents to the European AI Office, implement cybersecurity protections, and report on energy consumption. The 10²⁵ FLOP threshold aligns with guidance from the AI Safety Summit. Designation can also occur based on qualitative capability criteria, such as if a model can generate chemical or biological weapon instructions. The European AI Office maintains the list of designated models and may update the compute threshold via delegated act.
Key Characteristics
- Compute threshold of 10²⁵ FLOPs used for training as primary trigger
- Qualitative capability-based designation available to the European AI Office
- Mandatory adversarial testing, incident reporting, and cybersecurity obligations
- Subject to oversight by the European AI Office rather than national authorities
Why It Matters
Frontier model labs and major cloud providers releasing very large models must track training compute, engage in adversarial testing programmes, and maintain incident-reporting channels with EU authorities.
Real-World Analogy
Like how nuclear power plants face a separate, more rigorous regulatory regime than conventional power stations due to the magnitude of potential impact, GPAI models with systemic risk are subject to obligations beyond those applied to standard AI systems.
Common Misconceptions
- Only proprietary models can be classified as systemic-risk, open-source models meeting the compute threshold are also within scope, though some obligations are modulated.
- The compute threshold is the only route to systemic-risk designation, the Commission can designate a model based on capability or impact assessment regardless of training compute.