Systemic risk: 10²⁵ FLOPs and the Art 55 stack

Lesson 4 of 5 in Transparency and General-Purpose AI: Art 50 and the GPAI Chapter.

Some models are not just ingredients — they are infrastructure. Art 51 singles out GPAI models with systemic risk: those with high-impact capabilities, evaluated by benchmarks and indicators, whose reach could produce actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society as a whole, propagated at scale across the value chain.

The Act operationalises this with the most quoted number in AI regulation: a model is presumed to have high-impact capabilities when the cumulative compute used for its training exceeds 10²⁵ floating-point operations (Art 51(2)). Why compute? Because it is the only capability proxy you can measure before training finishes: you know your FLOPs budget at planning time, which lets duties attach prospectively — and the Act uses exactly that, requiring notification when it is known, or should be known, that the threshold will be met.

The mechanics run in four steps. Notify: the provider tells the Commission without delay and in any event within two weeks of the threshold being met — or of learning it will be met. Rebut: the provider may argue that, exceptionally, despite the compute, the model does not present systemic risks — the presumption is rebuttable, but the Commission decides. Designate: independently of any FLOPs number, the Commission can designate a model as systemic-risk ex officio or on a qualified alert from the scientific panel, using the Annex XIII criteria: parameter count, dataset size and quality, training compute, input/output modalities, benchmark and evaluation performance, reach — including a floor of at least 10,000 registered EU business users — and the number of registered end users. Publish: the Commission maintains a public list of designated systemic-risk models, redacted for trade secrets.

Hold onto the asymmetry: 10²⁵ FLOPs is a presumption you can argue against; Commission designation is a decision you can only ask to reassess. And the threshold is adjustable — the Commission may amend it by delegated act as the technological frontier moves.

Base stack (every GPAI provider)

Art 53 — always on:

  • Annex XI technical documentation — training, testing, evaluation results — for the AI Office and national authorities (lifted for qualifying open-source models)
  • Annex XII downstream documentation so system builders can comply (lifted for qualifying open-source models)
  • Copyright policy, honouring DSM Art 4(3) TDM opt-outs (never lifted)
  • Public training-content summary on the AI Office template (never lifted)
  • Art 54: non-EU providers appoint an EU authorised representative (open-source exempt unless systemic risk)

Enforced by the AI Office; fines up to €15M or 3% of worldwide turnover (Art 101).

+ Systemic-risk stack (Art 55)

Everything in the base stack — with the open-source carve-out voided — plus:

  • State-of-the-art model evaluations, including adversarial testing / red-teaming, to identify and mitigate systemic risks
  • Union-level systemic-risk assessment and mitigation — covering risks from development, placing on the market, and use of the model
  • Serious-incident tracking, documentation and reporting to the AI Office (and national authorities as relevant) without undue delay
  • Adequate cybersecurity for the model and its physical infrastructure — model weights are treated as assets worth stealing

Compliance may be demonstrated via the Code of Practice or adequate alternative means (Art 55(2)); harmonised standards, once cited, would ground a presumption of conformity.

Key terms: systemic risk (GPAI), FLOPs, red-teaming, model weights, Annex XIII

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.