Direct answer
When does a GPAI model have systemic risk (the 10^25 FLOPs threshold)?
You describe: You want to know when an AI model qualifies as GPAI with systemic risk and which additional duties then apply. Likely role: provider of a gpai model.
This applies now
- Article 55: GPAI models with systemic riskApplicable
- Article 53: GPAI model providersApplicable
A GPAI model is presumed to have systemic risk when the cumulative training compute exceeds 10^25 FLOPs; the Commission can also designate models based on capabilities. For those models, the Article 55 duties come on top of Article 53: model evaluations, risk assessment and mitigation, incident reporting and cybersecurity.
Your first actions
- Perform model evaluations and risk mitigation. Evaluate the model including adversarial testing, assess and mitigate systemic risks, report serious incidents and secure the model.
- Maintain GPAI documentation and transparency information. Maintain technical documentation, information for downstream providers, a copyright policy and a public summary of training content.
Record this
- Systemic-risk file
- GPAI compliance file
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationFollow-up questions
Execution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approach