Law / European Union

AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk)

Regulation (EU) 2024/1689, Article 55

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 2 August 2025.

An AI governance rule binding public and private bodies.

As of 20 September 2026.

What it requires

  • If the Commission has classified your general-purpose AI model as carrying systemic risk, in addition to your Article 53 duties, perform model evaluation using standardised, state-of-the-art protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks.
  • Assess and mitigate the systemic risks your model may pose at Union level, including where those risks originate, whether in the model's development, its placing on the market, or its use.
  • Keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving your model and any corrective measures you have taken or plan to take. The Regulation states no fixed number of days for this report and no explicit moment its clock starts from, only that it must be made without undue delay.
  • Ensure an adequate level of cybersecurity protection for your model and its physical infrastructure throughout the model's lifecycle.
  • You may rely on an AI Office code of practice, or a harmonised standard once one is published, to demonstrate compliance with these duties. If you rely on neither, demonstrate an alternative adequate means of compliance instead.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 55 binds providers of general-purpose AI models that the Commission has classified as carrying systemic risk, in addition to the disclosure and copyright duties Article 53 places on every general-purpose AI model provider. A model is presumed to carry systemic risk when its training used more than 10^25 floating-point operations. The Commission may also designate a model this way on the basis of equivalent capabilities or impact.

Those providers must perform model evaluation using standardised, state-of-the-art protocols, including adversarial testing to identify and mitigate systemic risks. They must also assess and mitigate the systemic risks their model may pose at Union level, including where those risks originate.

They must keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving their model and any corrective measures. And they must maintain an adequate level of cybersecurity protection for the model and its physical infrastructure.

The reporting duty names no fixed number of days and no explicit moment the clock runs from; it states only that the report must be made without undue delay. Article 73's reporting duty for high-risk AI systems sets a general ceiling of 15 days running from when the provider becomes aware of the incident. That ceiling tightens to 10 days where the incident caused a person's death.

It tightens to 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure. 'Serious incident' is defined once, in Article 3, point (49), for the whole Regulation, as an incident or malfunctioning that leads to a person's death or serious harm to health, a serious and irreversible disruption of critical infrastructure, an infringement of Union law protecting fundamental rights, or serious harm to property or the environment.

That definition is written for an AI system, a term the Regulation defines in Article 3, point (1). A general-purpose AI model is a separate defined term in the same Article. Article 55 supplies no definition of a serious incident keyed to a model rather than a system. A provider may rely on an AI Office code of practice, or a harmonised standard once one is published, to demonstrate compliance with these duties, and must show an alternative adequate means of compliance if it relies on neither.

Article 113's third paragraph, point (b), applies Chapter V, which contains Article 55, from 2 August 2025, a year ahead of the Regulation's general application date. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) left that point unchanged, replacing only points (a) and (c) and adding point (d). A provider whose model was already on the market before that date has until 2 August 2027 to come into compliance.

When LexLint raises it

  • trains_models
  • generates_content

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app