Glossary · AI Act

Systemic Risk (GPAI)

The AI Act's designation for the most capable general-purpose AI models, whose reach could cause large-scale harm across the EU.

Explained in depth: AI Act overview

A general-purpose AI model poses systemic risk when it has high-impact capabilities, presumed when the compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it based on criteria such as user reach, scalability, and potential negative effects on public health, safety, security, fundamental rights, or society as a whole. Providers of systemic-risk models carry the heaviest GPAI obligations: state-of-the-art model evaluations including adversarial testing, assessment and mitigation of systemic risks at Union level, tracking and reporting of serious incidents to the AI Office, and adequate cybersecurity for the model and its infrastructure. The AI Office maintains and updates the practical criteria as the technology evolves.

Why it matters

The systemic-risk tier only touches a handful of frontier model providers directly, but it shapes the whole ecosystem: the evaluations, incident reporting, and safety documentation required at the top become the baseline evidence that enterprise customers downstream ask for.

Used in

See also

← All glossary terms