Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When is a GPAI model classified as having systemic risk?
Updated
Chapter V of Regulation (EU) 2024/1689 classifies GPAI models with systemic risk under Article 51. Article 51(2) presumes high-impact capabilities when cumulative training compute exceeds 10^25 floating-point operations. Article 55 adds extra duties. Not legal advice. This page does not designate YOUR model.
GPAI models with systemic risk, last verified 9 September 2026 against Chapter V (Articles 51–56), Article 3(63)–(67), Annex XIII, Article 111(3) and Article 113(b) of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). Commission AI Act pages, the AI Office GPAI-scope guidelines, and the GPAI Code of Practice (including its safety and security chapter) are Commission / AI Office materials — guidance, not the regulation. The Code of Practice is voluntary and does not replace Article 55. Regulation (EU) 2026/1744 is an amending regulation; it does not rewrite Article 113(b) for Chapter V. This page is not legal advice, not a filing, not a designation that YOUR model has systemic risk, and does not start a clock.
This is Articles 51–55, not YOUR designation
Audience: a foundation-model provider, engineering leader, or counsel walking Regulation (EU) 2024/1689 Chapter V on general-purpose AI models with systemic risk. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a GPAI provider, or that YOUR model has systemic risk. This page does not file with the AI Office.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Chapter V (Articles 51–56) is the general-purpose AI model chapter. The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 51–56, Article 3(63)–(67), Annex XIII, Article 111(3) and Article 113(b) of 2024/1689 are legal requirements only if they apply. Commission AI Act pages, AI Office GPAI-scope guidelines, and the GPAI Code of Practice (including its safety and security chapter) are Commission / AI Office materials — guidance, not the regulation. This page quotes which kind of text it is relying on.
- The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
- This page does not invent a 2 August 2026 start date for GPAI systemic-risk duties. Article 113(b) of 2024/1689 applies Chapter V from 2 August 2025, with the exception of Article 101. Article 113(c) Annex I product-embedded high-risk is 2 August 2027, not 2026. This page does not invent a 2 August 2026 date for Annex I.
What Articles 3(64), 3(65) and 3(67) actually say
Last verified 9 September 2026 against Article 3 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 3(63) defines a general-purpose AI model. Article 3(64): 'high-impact capabilities' means capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models. Article 3(65): 'systemic risk' means a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain. Article 3(67): 'floating-point operation' means any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base. Those are legal requirements of the definitions. This page does not apply them to YOU.
Chapter V is a separate track from the system-risk pyramid (prohibited practices, high-risk systems, Article 50 transparency). Article 51 classifies GPAI models with systemic risk. Article 52 is the notification and designation procedure for that class. Article 53 is the baseline for providers of GPAI models — the GPAI-requirements guide on this site is that page. Article 54 is the authorised-representative duty for third-country providers. Article 55 adds extras for GPAI models with systemic risk. Article 56 is codes of practice. This page does not find that YOU are a GPAI provider and does not run the systemic-risk threshold. Not legal advice.
Article 113(b) is 2 August 2025, not 2 August 2026
Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 113(b): Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Chapter V is the GPAI chapter, including Articles 51, 52 and 55. GPAI systemic-risk classification, notification, and extra duties therefore apply from 2 August 2025 under Article 113(b), except Article 101. They did not start on 2 August 2026. This page does not move that date.
Article 101 (Commission fines for providers of GPAI models) is the exception named in Article 113(b). Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I. Those dates are not one number.
Article 111(3) of 2024/1689: providers of general-purpose AI models that have been placed on the market before 2 August 2025 shall take the necessary steps in order to comply with the obligations laid down in this Regulation by 2 August 2027. That is a legal requirement of the original regulation, only if it applies. It is not Article 113(c). This page does not decide that YOUR model was placed on the market before 2 August 2025. Regulation (EU) 2026/1744 is an amending regulation. It does not rewrite Article 113(b) for Chapter V. Not legal advice.
Article 51 classification — quote the presumption, do not invent a number
Last verified 9 September 2026 against Article 51 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Authentic Article 51(1): A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it meets any of the following conditions: (a) it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks; (b) based on a decision of the Commission, ex officio or following a qualified alert from the scientific panel, it has capabilities or an impact equivalent to those set out in point (a) having regard to the criteria set out in Annex XIII.
Authentic Article 51(2): A general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25. That is the article as written. The exponent is 25. This page does not round it, does not substitute a different number, and does not run that computation for YOU. Floating-point operation is defined in Article 3(67). The common shorthand is 10^25 FLOP. The legal requirement is the sentence above.
Article 51(3): The Commission shall adopt delegated acts in accordance with Article 97 to amend the thresholds listed in paragraphs 1 and 2 of this Article, as well as to supplement benchmarks and indicators in light of evolving technological developments, such as algorithmic improvements or increased hardware efficiency, when necessary, for these thresholds to reflect the state of the art. A delegated-act change, if adopted, is a later legal text. This page does not invent one. Last verified 9 September 2026. Not legal advice.
Article 52 procedure — notification and designation, not YOUR filing
Each row is a duty as the cited text states it. Mapping a row is not a finding that it binds YOU, and is not a designation. Walk the checklist questions below with counsel. Last verified 9 September 2026. Not legal advice.
| Step | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 52(1) — notify the Commission | Where a general-purpose AI model meets the condition referred to in Article 51(1), point (a), the relevant provider shall notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met. That notification shall include the information necessary to demonstrate that the relevant requirement has been met. If the Commission becomes aware of a general-purpose AI model presenting systemic risks of which it has not been notified, it may decide to designate it as a model with systemic risk. | Article 52(1) of 2024/1689. Legal requirement, only if it applies. This page does not file that notification and does not start that two-week mark. | 9 September 2026 |
| Article 52(2) — arguments with the notification | The provider of a general-purpose AI model that meets the condition referred to in Article 51(1), point (a), may present, with its notification, sufficiently substantiated arguments to demonstrate that, exceptionally, although it meets that requirement, the general-purpose AI model does not present, due to its specific characteristics, systemic risks and therefore should not be classified as a general-purpose AI model with systemic risk. | Article 52(2) of 2024/1689. Legal requirement of a permitted argument. This page does not write YOUR arguments and does not decide them. | 9 September 2026 |
| Article 52(3) — Commission rejection of those arguments | Where the Commission concludes that the arguments submitted pursuant to paragraph 2 are not sufficiently substantiated and the relevant provider was not able to demonstrate that the general-purpose AI model does not present, due to its specific characteristics, systemic risks, it shall reject those arguments, and the general-purpose AI model shall be considered to be a general-purpose AI model with systemic risk. | Article 52(3) of 2024/1689. Legal requirement of the Commission's conclusion, not this page's. This page does not reject or accept YOUR arguments. | 9 September 2026 |
| Article 52(4) — Commission designation using Annex XIII | The Commission may designate a general-purpose AI model as presenting systemic risks, ex officio or following a qualified alert from the scientific panel pursuant to Article 90(1), point (a), on the basis of criteria set out in Annex XIII. The Commission is empowered to adopt delegated acts in accordance with Article 97 in order to amend Annex XIII by specifying and updating the criteria set out in that Annex. | Article 52(4) of 2024/1689. Legal requirement of a Commission power. This page is not that decision. | 9 September 2026 |
| Article 52(5) — reasoned request to reassess | Upon a reasoned request of a provider whose model has been designated as a general-purpose AI model with systemic risk pursuant to paragraph 4, the Commission shall take the request into account and may decide to reassess whether the general-purpose AI model can still be considered to present systemic risks on the basis of the criteria set out in Annex XIII. Such a request shall contain objective, detailed and new reasons that have arisen since the designation decision. Providers may request reassessment at the earliest six months after the designation decision. | Article 52(5) of 2024/1689. Legal requirement of a permitted request. This page does not file it. | 9 September 2026 |
| Article 52(6) — published list | The Commission shall ensure that a list of general-purpose AI models with systemic risk is published and shall keep that list up to date, without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law. | Article 52(6) of 2024/1689. Legal requirement on the Commission. This page is not that list. | 9 September 2026 |
Annex XIII criteria — Commission designation inputs, not YOUR score
Last verified 9 September 2026 against Annex XIII of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Annex XIII: For the purpose of determining that a general-purpose AI model has capabilities or an impact equivalent to those set out in Article 51(1), point (a), the Commission shall take into account the following criteria. Mapping a row is not a Commission designation and is not YOUR score. Not legal advice.
| Criterion | What Annex XIII says | Kind of text | Last verified |
|---|---|---|---|
| Annex XIII(a) | The number of parameters of the model. | Annex XIII of 2024/1689. Legal requirement of a criterion the Commission takes into account. This page does not count YOUR parameters. | 9 September 2026 |
| Annex XIII(b) | The quality or size of the data set, for example measured through tokens. | Annex XIII of 2024/1689. Legal requirement of a criterion. This page does not measure YOUR data set. | 9 September 2026 |
| Annex XIII(c) | The amount of computation used for training the model, measured in floating point operations or indicated by a combination of other variables such as estimated cost of training, estimated time required for the training, or estimated energy consumption for the training. | Annex XIII of 2024/1689. Legal requirement of a criterion. Distinct from the Article 51(2) presumption, which uses cumulative training compute greater than 10^25 floating point operations. | 9 September 2026 |
| Annex XIII(d) | The input and output modalities of the model, such as text to text (large language models), text to image, multi-modality, and the state of the art thresholds for determining high-impact capabilities for each modality, and the specific type of inputs and outputs (e.g. biological sequences). | Annex XIII of 2024/1689. Legal requirement of a criterion. This page does not classify YOUR modalities. | 9 September 2026 |
| Annex XIII(e) | The benchmarks and evaluations of capabilities of the model, including considering the number of tasks without additional training, adaptability to learn new, distinct tasks, its level of autonomy and scalability, the tools it has access to. | Annex XIII of 2024/1689. Legal requirement of a criterion. This page does not run YOUR benchmarks. | 9 September 2026 |
| Annex XIII(f) | Whether it has a high impact on the internal market due to its reach, which shall be presumed when it has been made available to at least 10 000 registered business users established in the Union. | Annex XIII of 2024/1689. Legal requirement of a criterion, including that reach presumption. This page does not count YOUR business users. | 9 September 2026 |
| Annex XIII(g) | The number of registered end-users. | Annex XIII of 2024/1689. Legal requirement of a criterion. This page does not count YOUR end-users. | 9 September 2026 |
Baseline GPAI versus systemic-risk extras
Article 55 applies in addition to Articles 53 and 54. The GPAI-requirements guide on this site is the Article 53 baseline page. The rows below compare the two tracks as the cited texts state them. Mapping a row is not a finding that either track binds YOU. Last verified 9 September 2026. Not legal advice.
| Topic | Baseline GPAI — Articles 53 and 54 | Systemic-risk extras — Article 55, in addition | Kind of text | Last verified |
|---|---|---|---|---|
| Who it attaches to | Providers of general-purpose AI models — Article 53(1). Third-country providers appoint an authorised representative before placing the model on the Union market — Article 54. | Providers of general-purpose AI models with systemic risk — Article 55(1), in addition to Articles 53 and 54. | Articles 53, 54 and 55 of 2024/1689. Legal requirements, only if they apply. This page does not find that YOU are either kind of provider. | 9 September 2026 |
| Technical documentation and downstream information | Article 53(1)(a) Annex XI technical documentation; Article 53(1)(b) Annex XII information for downstream providers. | Article 55 does not replace Annex XI or Annex XII. Those baseline duties stay. Article 55(1)(a) adds model evaluation, including adversarial testing. | Articles 53(1)(a)–(b) and 55(1)(a) of 2024/1689. Legal requirements. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. | 9 September 2026 |
| Copyright policy and training-content summary | Article 53(1)(c) copyright policy, including DSM Directive Article 4 TDM reservation; Article 53(1)(d) public training-content summary. | Article 55 does not replace points (c) and (d). Article 53(2)'s exception for points (a) and (b) shall not apply to general-purpose AI models with systemic risks. | Articles 53(1)(c)–(d), 53(2) and 55 of 2024/1689. Legal requirements. The training-data-transparency guide on this site is the Article 53(1)(d) page. The copyright-policy guide on this site is the Article 53(1)(c) page. | 9 September 2026 |
| Model evaluation / adversarial testing | Article 53(1)(a) includes results of evaluation in Annex XI documentation. That is documentation of evaluation, not the Article 55(1)(a) extra. | Article 55(1)(a): perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks. | Article 55(1)(a) of 2024/1689. Legal requirement, only if Article 55 applies. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link. This product does not run adversarial testing for you. | 9 September 2026 |
| Systemic-risk assessment and mitigation | No Article 53 equivalent of Union-level systemic-risk assessment. | Article 55(1)(b): assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the market, or the use of general-purpose AI models with systemic risk. | Article 55(1)(b) of 2024/1689. Legal requirement, only if Article 55 applies. This page does not assess YOUR systemic risk. | 9 September 2026 |
| Serious-incident tracking and reporting | No Article 53 equivalent of GPAI serious-incident reporting to the AI Office. | Article 55(1)(c): keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them. Article 3(49) defines serious incident for an AI system. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. | Article 55(1)(c) of 2024/1689. Legal requirement, only if Article 55 applies. This page does not file a serious-incident report and does not start a clock. Distinct from CRA Article 14 and from AI Act Article 73 (high-risk systems). | 9 September 2026 |
| Cybersecurity | No Article 53 equivalent of the Article 55(1)(d) cybersecurity duty for the model and its physical infrastructure. | Article 55(1)(d): ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model. | Article 55(1)(d) of 2024/1689. Legal requirement, only if Article 55 applies. A dedicated AI-cybersecurity-requirements guide is not on this site yet. Naming it is not a link. This product does not certify cybersecurity. | 9 September 2026 |
| Codes of practice | Article 53(4): providers may rely on Article 56 codes of practice to demonstrate compliance with Article 53(1) until a harmonised standard is published. | Article 55(2): providers of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Providers who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission. | Articles 53(4), 55(2) and 56 of 2024/1689. Legal requirement that the code is a permitted route. The GPAI Code of Practice itself, including its safety and security chapter, is a voluntary tool — guidance, not the regulation. It does not replace Article 55. | 9 September 2026 |
Does this look like systemic-risk GPAI? — questions, not a designation
The table below is a question list. Answering a row is not a designation that YOUR model has systemic risk, not an Article 52 notification, and not a Commission decision. Walk it with counsel. Last verified 9 September 2026. Not legal advice.
| Question | What the cited text points at | What this page does not do |
|---|---|---|
| Does the Act apply to YOU at all? | Articles 2 and 3 — AI system or GPAI model placed on the Union market, put into service in the Union, or producing output used in the Union, and the Article 2 exclusions. | Does not run applicability for YOU. |
| Are YOU a provider of a general-purpose AI model? | Articles 3(3) and 3(63). The GPAI-requirements guide on this site is the Article 53 baseline page. | Does not determine that YOU are a GPAI provider. |
| Does Article 51(1)(a) look like it is in play — high-impact capabilities, including the Article 51(2) presumption? | Article 51(2): presumed when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25. | Does not run the FLOP threshold for you. Does not designate YOUR model. |
| If the Article 51(1)(a) condition is met, has the Article 52(1) notification been considered? | Notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met. | Does not file that notification. Does not start that two-week mark. |
| Has the Commission designated the model under Article 51(1)(b) / Article 52(4) using Annex XIII? | Commission decision, ex officio or following a qualified alert from the scientific panel, having regard to Annex XIII. | Is not that Commission decision. Does not apply Annex XIII as YOUR score. |
| If classified, which Article 55(1) points, if any — (a) model evaluation including adversarial testing, (b) systemic-risk assessment and mitigation, (c) serious-incident tracking and reporting, (d) cybersecurity of the model and its physical infrastructure? | Article 55(1), in addition to Articles 53 and 54. | Does not pick YOUR points. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link. |
| Article 113(b) is 2 August 2025, not 2 August 2026. Does Article 111(3) look relevant? | Article 111(3) is 2 August 2027 for GPAI models already on the market before 2 August 2025. Article 113(c) Annex I is 2 August 2027, not 2026. | Does not date YOUR duties. Does not invent a 2 August 2026 start date for GPAI. |
| Does the GPAI Code of Practice replace Article 55? | No. Article 55(2) permits relying on an Article 56 code until a harmonised standard is published. The Code, including its safety and security chapter, is voluntary guidance, not the regulation. | Does not treat the Code as replacing Article 55. |
Legal requirement versus Commission and AI Office guidance
The table below labels each text. Do not treat guidance as the article, and do not treat the article as optional because a Code of Practice exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 51–56, Article 3(63)–(67), Annex XIII, Article 111(3), Article 113(b) | Legal requirement — the regulation, only if it applies. Chapter V GPAI, including Articles 51, 52 and 55, from 2 August 2025 under Article 113(b), except Article 101. | Does not determine that YOUR model has systemic risk. Does not date GPAI from 2 August 2026. |
| Regulation (EU) 2026/1744 — Digital Omnibus on AI | An amending regulation. It does not rewrite Article 113(b) for Chapter V. | Does not treat an amending-regulation recital as moving GPAI systemic-risk duties to 2 August 2026. Article 113(c) Annex I remains 2 August 2027 in the original regulation. |
| European Commission AI Act page and AI Act Service Desk | Commission materials. Guidance, not the regulation. | Does not treat a Commission timeline as rewriting Article 113(b). |
| Commission guidelines on the scope of obligations for providers of GPAI models (18 July 2025) | Commission materials. Guidance, not the regulation. They discuss classification, including the Article 51(2) presumption and rebuttal. | Does not run the FLOP threshold. Does not treat a 10^23 FLOP discussion in those guidelines as Article 51(2). Article 51(2) is greater than 10^25 floating point operations. |
| EU AI Office GPAI Code of Practice (published 10 July 2025), including the safety and security chapter | Commission / AI Office guidance, not the regulation. A voluntary tool. Article 55(2) permits relying on an Article 56 code to demonstrate compliance with Article 55(1) until a harmonised standard is published. | Does not treat the Code, or its safety and security chapter, as replacing Article 55. |
What to do now
As of last verification on 9 September 2026, Chapter V GPAI duties, including Articles 51, 52 and 55, have applied since 2 August 2025 under Article 113(b), except Article 101. Article 111(3) gives providers of models placed on the market before 2 August 2025 until 2 August 2027 to take the necessary steps. The list below is operational preparation. It is not a designation that YOUR model has systemic risk. Walk it with counsel.
- Ask counsel whether YOU are a provider of a general-purpose AI model under Articles 3(3) and 3(63), and whether Article 51 looks like it is in play. This page does not run those tests. Marking eu_ai_act in an obligation map is not that determination and is not a designation.
- If counsel finds Article 51(1)(a) in play, walk Article 52(1)'s notification — without delay and in any event within two weeks — against YOUR facts. This product does not file with the AI Office and does not run the FLOP threshold for you.
- If classified, walk Article 55(1)(a)–(d) in addition to Articles 53 and 54. Do not treat the GPAI Code of Practice, including its safety and security chapter, as a substitute for Article 55. It is voluntary. Do not date these duties from 2 August 2026. Article 113(b) is 2 August 2025.
- The GPAI-requirements guide on this site is the Article 53 baseline page. The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not a designation. Walk it with counsel. The GPAI-requirements guide on this site is the Article 53 baseline page.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- Are YOU a provider of a general-purpose AI model? Articles 3(3) and 3(63). This page does not determine that YOU are a GPAI provider.
- Does Article 51(1)(a) or Article 51(1)(b) look like it is in play? Article 51(2) presumes high-impact capabilities when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25. This page does not run that computation.
- If Article 51(1)(a) is met, has Article 52(1) notification been considered — without delay and in any event within two weeks? This page does not file it.
- If classified, which Article 55(1) points, if any — (a) model evaluation including adversarial testing, (b) systemic-risk assessment and mitigation, (c) serious-incident tracking and reporting, (d) cybersecurity? This page does not pick YOUR points.
- Article 113(b) is 2 August 2025, not 2 August 2026. Article 111(3) is 2 August 2027 for models already on the market before 2 August 2025. Article 113(c) Annex I is 2 August 2027, not 2026.
- The GPAI Code of Practice, including its safety and security chapter, is voluntary and does not replace Article 55.
- Document the assessment, including a not-systemic-risk decision. This page does not keep YOUR file and does not designate YOUR model.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That inventory does not classify YOUR model under Article 3(63) or Article 51, does not decide that YOU are a GPAI provider, does not designate systemic risk, and does not file with the AI Office or a market-surveillance authority. Marking in-scope is not a designation and not auto-filing. A named human still owns the assessment.
This product does not run the FLOP threshold for you, does not produce Annex XI technical documentation, does not perform Article 55 model evaluation or adversarial testing, does not file Article 52 notifications or Article 55(1)(c) serious-incident reports, does not file with the AI Office, and does not issue certifications. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that your model has systemic risk.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 3(63)–(67), 51–56, 111(3) and 113(b) and Annex XIII, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(b) applies Chapter V from 2 August 2025, with the exception of Article 101. Article 113(c) Article 6(1) from 2 August 2027. Regulation (EU) 2026/1744 is an amending regulation; it does not rewrite Article 113(b) for Chapter V. The European Commission's AI Act page and the AI Act Service Desk are Commission materials, not the regulation. Commission GPAI-scope guidelines (18 July 2025) and the GPAI Code of Practice (10 July 2025), including its safety and security chapter, are agency/Commission guidance, not the regulation. The Code of Practice is voluntary and does not replace Article 55. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The EU AI Act framework guide on this site is the education page under frameworks. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated map of GPAI-with-systemic-risk classification and extra duties distilled from Regulation (EU) 2024/1689 Articles 51–55 and Annex XIII, with Commission and AI Office materials labelled as guidance, not the regulation. Whether YOUR model has systemic risk, and which duties bind YOU, is a legal question for counsel on your facts. This page does not start a clock and does not file with the AI Office.
Does this page designate our model as systemic-risk?
No. Mapping a row is not a determination that the Act applies, that YOU are a provider under Article 3(3), that a model is a general-purpose AI model under Article 3(63), or that it is classified under Article 51. Article 52(4) designation is a Commission decision. Counsel applies those articles to YOUR facts. Last verified 9 September 2026.
Did systemic-risk GPAI duties start on 2 August 2026?
No. Article 113(b) of Regulation (EU) 2024/1689 applies Chapter V from 2 August 2025, with the exception of Article 101. Chapter V includes Articles 51, 52 and 55. That is not 2 August 2026. Article 111(3) gives providers of GPAI models placed on the market before 2 August 2025 until 2 August 2027 to take the necessary steps. Article 113(c) Annex I product-embedded high-risk is 2 August 2027, not 2026. Last verified 9 September 2026.
Does the Code of Practice replace Article 55?
No. The GPAI Code of Practice, including its safety and security chapter, is a voluntary tool. Article 55(2) permits relying on an Article 56 code of practice to demonstrate compliance with Article 55(1) until a harmonised standard is published. Providers who do not adhere to an approved code still have to demonstrate alternative adequate means of compliance. The Code is guidance, not the regulation, and is not a substitute for Article 55. Last verified 9 September 2026.
Does ShipReady run the FLOP threshold, or file with the AI Office?
No. This product does not run the Article 51(2) cumulative-training-compute presumption for you, does not file Article 52 notifications, does not designate systemic risk, does not perform Article 55 model evaluation, and does not issue certifications. Signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture the organisation recorded. Marking in-scope is not a designation and not auto-filing. A named human still owns the assessment.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.