Article 55: Obligations for Providers of GPAI Models with Systemic Risk
provider · limited risk · Article 55
Article 55 adds four additional obligations on top of the [Article 53](/en/ai-act-guide/article-53) baseline for providers of GPAI models classified with systemic risk under [Article 51](/en/ai-act-guide/article-51): (a) perform model evaluation including adversarial testing; (b) assess and mitigate possible systemic risks; (c) track, document, and report serious incidents to the AI Office and national authorities; (d) ensure adequate cybersecurity protection. Compliance can be demonstrated through adherence to codes of practice under [Article 56](/en/ai-act-guide/article-56) or equivalent measures until harmonised standards are adopted.
How to satisfy it: Establish a model evaluation programme using standardised protocols (benchmarks, evaluations, stress tests) before each major release.
Article 55 on EUR-Lex · as of 2026-08-03 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744