GovCompass

Art. 51 EU AI Act: classifying a GPAI model as systemic risk

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 51 sets out when a general-purpose AI model is classified as having systemic risk. A model crosses into the systemic-risk category when it has high-impact capabilities, which is presumed once the cumulative compute used to train it exceeds 10^25 floating-point operations (FLOP), or when the Commission designates it as such. Systemic-risk classification triggers the additional obligations of Art. 55 on top of the baseline Art. 53 obligations that apply to every GPAI provider.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

What Art. 51 does

The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → regulates general-purpose AIgeneral-purpose AIA model trained on broad data that can be adapted to many downstream tasks; the AI Act sets specific obligations for it, with extra duties when it poses systemic risk.Open full entry → at the level of the model, not the system. Chapter V creates a tiered regime: every providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → of a general-purpose AI modelgeneral-purpose AI modelEU AI Act term for a model displaying significant generality and capable of many distinct tasks, typically integrated into downstream systems; carries its own obligation set, with extra duties for models posing systemic risk.Open full entry → carries the baseline obligations of Art. 53, and a smaller group whose models reach a higher capability bar carries the additional, heavier obligations of Art. 55. Art. 51 is the gate between the two tiers. It defines when a GPAI model is classified as a general-purpose AI model with systemic risksystemic riskEU AI Act category for the most capable general-purpose models (presumed above a training-compute threshold), triggering extra duties: evaluations, adversarial testing, incident reporting, cybersecurity.Open full entry →.

The two routes into systemic risk

A model is classified as systemic riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → by either of two routes.

The first is high-impact capabilities. A model has systemic risk if it has high-impact capabilities, evaluated using appropriate technical tools, methodologies, and benchmarks. Art. 51(2) attaches a presumption to this: a model is presumed to have high-impact capabilities when the cumulative amount of compute used for its training, measured in floating-point operations, exceeds 10^25 FLOP. This compute threshold is the practical trigger that captures the current frontier of the most advanced models.

The second is Commission designation. Independently of the compute presumption, the Commission can designate a model as having systemic risk on the basis of the criteria in Annex XIII, where it has capabilities or impact equivalent to those captured by the threshold. This route lets the regime catch a model that poses systemic risk for reasons other than raw training compute.

The threshold is not fixed

The 10^25 FLOP threshold is a presumption, not an immovable line. Art. 51(3) empowers the Commission to amend the thresholds and to supplement the benchmarks and indicators by delegated act, so that the classification keeps pace with technological change. As training becomes more efficient, the same capability frontier can be reached at lower compute, so the threshold can be lowered over time to continue capturing only the genuinely most capable models. A provider whose model exceeds the compute threshold can also contest the systemic-risk presumption by demonstrating that, despite the compute, the model does not have high-impact capabilities matching the most advanced models.

Why it matters

Systemic-risk classification is consequential because it is the line that separates the baseline GPAI regime from the frontier-model regime. Below the line, a provider carries the Art. 53 obligations: technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, downstream transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry →, a copyright policy, and a public summary of training content. Above the line, the provider additionally carries the Art. 55 obligations: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting to the AI OfficeAI OfficeThe European Commission body that coordinates implementation of the EU AI Act and supervises general-purpose AI models. National market surveillance authorities enforce the Act for most AI systems; the AI Office is the central point for the general-purpose AI layer. See general-purpose AI, EU AI Act.Open full entry →, and cybersecurity protection for the model. For most organizations the practical relevance is indirect: the foundation modelsfoundation modelA model trained on broad data at scale that can be adapted to many downstream tasks; called a general-purpose AI model in EU AI Act terminology.Open full entry → they build on are typically provided by the small group of companies whose models cross this threshold, which means those models are subject to systematic safety evaluation by law.

In the seven pillars of responsible AI

Art. 51 is primarily an accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → provision: it determines which party carries which set of model-level obligations. The systemic-risk regime it gates also reaches into the security and robustnesssecurity and robustnessThe principle that an AI system resists attack, manipulation and adversarial or unexpected input. The vectors include data poisoning, model extraction, membership inference and prompt injection; the controls are ML security testing and a hardened data-and-model pipeline. Under the EU AI Act, high-risk AI systems must be resilient against attempts to alter their use, outputs, or performance by exploiting vulnerabilities (Article 15). See prompt injection, adversarial input, guardrail, responsible AI.Open full entry → and the safety and reliabilitysafety and reliabilityThe principle that an AI system performs as intended and fails in ways the organization can absorb. The characteristic AI failure is not a crash but decay: accuracy drops after deployment while nothing throws an error, so the organization keeps trusting numbers that are no longer true. Under the EU AI Act, high-risk AI systems must achieve an appropriate level of accuracy and robustness and perform consistently across their lifecycle (Article 15). See drift, evaluation set, high-risk AI system, responsible AI.Open full entry → pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry →, because the Art. 55 obligations it triggers are about evaluating, mitigating, and securing against model-level risk.

Continue reading

Legal referencesArt. 51
Share Share on LinkedIn

More on Safety & reliability

Regulatory sandboxes: innovation under EU AI Act supervision

Analysis

Regulatory sandboxes under Art. 57-61 are controlled environments, supervised by the national authority, in which organizations can develop and test innovative AI systems with guidance and temporary relief from certain administrative requirements, without suspending the material safeguards or incident-reporting duties.

Regulatory sandbox explained: innovation space under the EU AI Act

Guide

Joining a national AI regulatory sandbox under Art. 57-61 follows a structured path: prepare a project dossier, apply in one of the submission windows, sign a sandbox agreement with the supervisor, report progress and incidents during testing, and produce a final report that supports full compliance afterwards.

Art. 26.1 EU AI Act: following provider instructions as a deployer

Reference

Art. 26.1 requires deployers to use high-risk AI systems strictly in accordance with the provider's instructions for use. This means using the system only for its intended purpose, within its specified technical configuration, and by qualified users, and documenting that compliance. Deviating from the instructions can shift liability entirely to the deployer.

Art. 26.4 EU AI Act: input data quality for deployers

Reference

Art. 26.4 requires deployers of high-risk AI to ensure that input data is relevant and sufficiently representative for the system's intended purpose. The deployer is responsible for data quality in operation, even though the provider sets the specifications under Art. 10.