GPAI Model with Systemic Risk

A GPAI model with systemic risk is a general-purpose AI model meeting EU AI Act criteria for high-impact capabilities, subject to additional obligations including model evaluation, adversarial testing, incident reporting, and cybersecurity requirements.

How Systemic Risk Is Determined

Under the EU AI Act, a GPAI model is presumed to have systemic risk if it meets a defined compute threshold (currently 10^25 floating point operations for training), or if designated by the European Commission based on other high-impact capability indicators.

The category was created because a small number of extremely capable models produce disproportionate systemic risk. Regulating them at the model level lets obligations propagate to every downstream deployer without requiring each deployer to independently manage the same set of risks.

Additional Obligations for Systemic-Risk GPAI

Beyond the baseline GPAI obligations, systemic-risk models must undergo model evaluation and adversarial testing, report serious incidents to the European AI Office, ensure adequate cybersecurity protection, and assess and mitigate systemic risks throughout the model lifecycle.

Why Enterprises Should Care

Enterprises deploying systemic-risk GPAI inherit specific expectations even without being providers themselves. Deployers should verify provider compliance, understand which models in their environment fall into this category, and integrate provider incident reporting into their own incident response processes.

Related Terms

Full AI Visibility. Full Control. One Connected Platform.

Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.