Module 3 of the AI Act GPAI certification: the 10^25 FLOP presumption and how to rebut it, the two-week notification under Art. 52, and the four additional obligations of Art. 55.

Systemic risk is the AI Act's frontier-model regime. It affects a small number of providers directly and a large number indirectly, because every downstream builder inherits the consequences of whether the model they depend on is inside it.

Art. 51 — two routes in

A general-purpose AI model is classified as having systemic risk where either:

(a) it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; or

(b) the Commission decides, on its own initiative or following a qualified alert from the scientific panel, that it has capabilities or an impact equivalent to those under (a), having regard to the criteria in Annex XIII.

Art. 51(2) then sets the quantitative presumption: a model shall be presumed to have high impact capabilities where the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.

Three things about that number.

It is a presumption, and it is rebuttable. Meeting it does not conclusively classify the model. A provider may present arguments that, despite meeting the criterion, the model does not present systemic risk on account of its specific characteristics.

It moves. The Commission may adopt delegated acts to amend the threshold and to supplement benchmarks and indicators in light of evolving technology — algorithmic improvements and hardware efficiency both push it.

It is cumulative training compute, not inference compute and not the compute of a single run.

Annex XIII lists the criteria the Commission considers for designation: the number of parameters; the quality or size of the dataset; the amount of computation; input and output modalities; benchmarks and evaluations of capabilities including the number of tasks without additional training, adaptability, autonomy and scalability, and the tools it has access to; whether it has a high impact on the internal market due to its reach, presumed where it has been made available to at least 10,000 registered business users in the Union; and the number of registered end-users.

Art. 52 — notification

Where a model meets the Art. 51(1)(a) condition, the provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met.

Read the second limb: the clock can start before the threshold is crossed, at the point it becomes known that it will be. A provider planning a training run that will exceed the threshold knows in advance.

The notification shall include the information necessary to demonstrate that the requirement has been met. Where the provider considers that the model does not present systemic risk despite meeting the criterion, it may present sufficiently substantiated arguments with the notification. If the Commission is not persuaded, the model is classified as having systemic risk.

A provider may also request reassessment later, on the basis that the model no longer presents systemic risk — the classification is not permanently one-way.

The Commission publishes and keeps updated a list of models with systemic risk, without prejudice to intellectual property and confidential business information.

Art. 55 — the four additional obligations

Providers of GPAI models with systemic risk shall:

(a) Perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.

(b) Assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, placing on the market or use of the model.

(c) Keep track of, document and report without undue delay to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them.

(d) Ensure an adequate level of cybersecurity protection for the model and the physical infrastructure of the model.

Two things to notice.

(a) requires documentation, not just testing. Adversarial testing that is performed and not written up does not satisfy an obligation whose text says "conducting and documenting".

(d) reaches physical infrastructure. This is not a software security obligation. Weights are an asset whose theft is a systemic-risk event, and the article says so by extending to the infrastructure the model runs on.

Art. 55 obligations sit on top of Art. 53, not instead of it — and the open-source relief in Art. 53(2) does not apply to systemic-risk models, so the Annex XI documentation and Annex XII downstream information are owed even for an openly released frontier model.

Enforcement and fines

Chapter V is enforced centrally by the Commission through the AI Office, with those powers applying from 2 August 2026. National market surveillance authorities enforce against systems; they do not enforce against models.

Fines for GPAI providers sit in Art. 101, at up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher — a separate regime from the Art. 99 bands that apply to other operators. The Commission may impose them for, among other things, infringing the Chapter V obligations, failing to comply with a request for documents or information, failing to comply with a measure requested, or failing to give the Commission access to the model to conduct an evaluation.

What a downstream builder should take from this module

You are unlikely to be a systemic-risk provider. You are very likely to depend on one.

The practical questions to put to a model vendor:

The last one is a business continuity question that most contracts do not answer.

Check yourself

  1. We exceeded 10^25 FLOPs, so our model is definitively a systemic-risk model.It is a rebuttable presumption. Art. 52 lets you present substantiated arguments that the model does not present systemic risk despite meeting the criterion.
  2. We will notify once the training run completes.The two-week clock runs from when the requirement is met OR it becomes known that it will be met, which can be before the run finishes.
  3. Our systemic-risk model is open-source, so Art. 53(a) and (b) do not apply.The open-source relief does not apply to models with systemic risk.
  4. We ran red-team exercises but did not write them up.Art. 55(1)(a) requires conducting AND documenting adversarial testing.

Previous: Module 2 — What every GPAI provider owes (Art. 53) Next: Module 4 — Codes of practice and the standards gap →

Frequently Asked Questions

Art. 51(1)(a) presumes high impact capabilities where the cumulative amount of compute used for the model's training, measured in floating point operations, is greater than 10^25. It is a rebuttable presumption and the Commission may amend the threshold by delegated act to reflect technological developments. Art. 51(2) allows the Commission to designate a model on the basis of other criteria.

Art. 52 requires notification without delay and in any event within two weeks of the moment the requirement is met or it becomes known that it will be met. The provider may accompany the notification with arguments that, although it meets the criterion, the model does not present systemic risk because of its specific characteristics.

Art. 55 adds four: model evaluation in accordance with standardised protocols and tools, including conducting and documenting adversarial testing with a view to identifying and mitigating systemic risk; assessing and mitigating possible systemic risks at Union level; tracking, documenting and reporting serious incidents and possible corrective measures to the AI Office and, as appropriate, to national competent authorities without undue delay; and ensuring an adequate level of cybersecurity protection for the model and its physical infrastructure.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.