Systemic risk: 10²⁵ FLOPs and the Art 55 stack
Lesson 4 of 5 in Transparency and General-Purpose AI: Art 50 and the GPAI Chapter.
Some models are not just ingredients — they are infrastructure. Art 51 singles out GPAI models with systemic risk: those with high-impact capabilities, evaluated by benchmarks and indicators, whose reach could produce actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society as a whole, propagated at scale across the value chain.
The Act operationalises this with the most quoted number in AI regulation: a model is presumed to have high-impact capabilities when the cumulative compute used for its training exceeds 10²⁵ floating-point operations (Art 51(2)). Why compute? Because it is the only capability proxy you can measure before training finishes: you know your FLOPs budget at planning time, which lets duties attach prospectively — and the Act uses exactly that, requiring notification when it is known, or should be known, that the threshold will be met.
The mechanics run in four steps. Notify: the provider tells the Commission without delay and in any event within two weeks of the threshold being met — or of learning it will be met. Rebut: the provider may argue that, exceptionally, despite the compute, the model does not present systemic risks — the presumption is rebuttable, but the Commission decides. Designate: independently of any FLOPs number, the Commission can designate a model as systemic-risk ex officio or on a qualified alert from the scientific panel, using the Annex XIII criteria: parameter count, dataset size and quality, training compute, input/output modalities, benchmark and evaluation performance, reach — including a floor of at least 10,000 registered EU business users — and the number of registered end users. Publish: the Commission maintains a public list of designated systemic-risk models, redacted for trade secrets.
Hold onto the asymmetry: 10²⁵ FLOPs is a presumption you can argue against; Commission designation is a decision you can only ask to reassess. And the threshold is adjustable — the Commission may amend it by delegated act as the technological frontier moves.
Base stack (every GPAI provider)
Art 53 — always on:
- Annex XI technical documentation — training, testing, evaluation results — for the AI Office and national authorities (lifted for qualifying open-source models)
- Annex XII downstream documentation so system builders can comply (lifted for qualifying open-source models)
- Copyright policy, honouring DSM Art 4(3) TDM opt-outs (never lifted)
- Public training-content summary on the AI Office template (never lifted)
- Art 54: non-EU providers appoint an EU authorised representative (open-source exempt unless systemic risk)
Enforced by the AI Office; fines up to €15M or 3% of worldwide turnover (Art 101).
+ Systemic-risk stack (Art 55)
Everything in the base stack — with the open-source carve-out voided — plus:
- State-of-the-art model evaluations, including adversarial testing / red-teaming, to identify and mitigate systemic risks
- Union-level systemic-risk assessment and mitigation — covering risks from development, placing on the market, and use of the model
- Serious-incident tracking, documentation and reporting to the AI Office (and national authorities as relevant) without undue delay
- Adequate cybersecurity for the model and its physical infrastructure — model weights are treated as assets worth stealing
Compliance may be demonstrated via the Code of Practice or adequate alternative means (Art 55(2)); harmonised standards, once cited, would ground a presumption of conformity.
Key terms: systemic risk (GPAI), FLOPs, red-teaming, model weights, Annex XIII
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.