EU AI Act · Article 55

Obligations for Providers of GPAI Models with Systemic Risk

Applies to
provider
Risk tier
limited
Applies from
Evidence
process

Article 55: Obligations for Providers of GPAI Models with Systemic Risk

provider · limited risk · Article 55

Article 55 adds four additional obligations on top of the [Article 53](/en/ai-act-guide/article-53) baseline for providers of GPAI models classified with systemic risk under [Article 51](/en/ai-act-guide/article-51): (a) perform model evaluation including adversarial testing; (b) assess and mitigate possible systemic risks; (c) track, document, and report serious incidents to the AI Office and national authorities; (d) ensure adequate cybersecurity protection. Compliance can be demonstrated through adherence to codes of practice under [Article 56](/en/ai-act-guide/article-56) or equivalent measures until harmonised standards are adopted.

How to satisfy it: Establish a model evaluation programme using standardised protocols (benchmarks, evaluations, stress tests) before each major release.

Article 55 on EUR-Lex · as of 2026-08-03 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

This page is generated from Legalithm’s open obligation Map. It states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.