The EU AI Act will enforce systemic risk provisions starting 2 August 2026. If your team is developing or deploying General-Purpose AI Models with systemic risk potential, you need a structured pre-deployment review process now, before the AI Office's enforcement powers begin.
This checklist translates Article 55's systemic risk obligations into a practical review process. Use it to determine whether your model is ready for deployment or needs further mitigation.
Purpose of the Checklist
This checklist guides you through a structured pre-deployment safety review for General-Purpose AI Models that may pose systemic risks under Article 55 of the EU AI Act. It's designed for:
- Model risk teams evaluating model safety before release
- Legal and compliance officers ensuring systemic risk obligations are met
- Product teams identifying necessary mitigations before deployment
- AI governance committees making go/no-go decisions on high-capability models
The checklist ensures that systemic risk models demonstrate adequate safety before deployment, not after incidents occur. Each section aligns with specific AI Act obligations or General-Purpose AI Code of Practice commitments.
Prerequisites
Before using this checklist, ensure you have:
- Determined systemic risk classification: Evaluate if your model meets Article 51 thresholds, such as high-impact capabilities or wide dissemination potential.
- Identified relevant capabilities: Understand what your model can do that might create systemic risks, like cybersecurity vulnerabilities or generating harmful content.
- Assembled a cross-functional review team: Include model developers, security specialists, legal counsel, and domain experts.
- Established baseline documentation: Have Technical Documentation (Annex XI) and model architecture details ready.
The Pre-Deployment Safety Checklist
1. Capability Assessment & Disclosure
☐ Dangerous capability evaluation completed
Document the model's capabilities that create systemic risk. For cybersecurity implications, test if the model can identify and exploit vulnerabilities beyond human performance.
☐ Capability benchmarks documented
Record performance on relevant safety benchmarks, comparing it to human expert performance where applicable.
☐ Notification submitted to AI Office (if deploying after 2 August 2026)
Article 55 requires providers to notify the AI Office of systemic risks. Proactively disclose capabilities rather than waiting for post-market surveillance.
☐ Transparency obligations addressed
Ensure deployers and downstream users can meet Article 50 transparency requirements when your model is embedded in their systems.
2. Mitigation Verification
☐ Mitigations implemented and tested
Document specific mitigations for each identified systemic risk and provide validation evidence. Demonstrate their effectiveness under adversarial conditions.
☐ Red Teaming conducted
Conduct independent adversarial testing to attempt circumvention of your mitigations. Document attack vectors, success rates, and residual risk.
☐ Mitigation limitations documented
Clearly state what your mitigations cannot prevent. If your model can exploit zero-day vulnerabilities, note that usage policies only constrain authorized use.
☐ Residual risk quantified
Identify potential harm after mitigations and under what conditions it could occur. This is the risk you're asking the market to accept.
3. Independent Verification
☐ External evaluation arranged
For models with significant systemic risk potential, engage independent evaluators with relevant domain expertise.
☐ Model access provided to evaluators
Ensure evaluators have sufficient access to validate your safety claims. Define access scope and evaluation protocol in advance.
☐ Evaluation findings incorporated
Document external evaluators' findings and how you've addressed their concerns. If you disagree with their assessment, explain why in writing.
☐ Ongoing monitoring protocol established
Article 55(1)(c) requires monitoring serious incidents and effectiveness of safeguards. Define monitoring criteria, frequency, and triggers for safety reviews.
4. Deployment Conditions
☐ Usage restrictions defined
Specify who can use the model, for what purposes, and under what conditions. Enforce these restrictions through technical or contractual means.
☐ Access controls implemented
Document how you'll enforce deployment restrictions to specific use cases or user types.
☐ Downstream provider obligations established
Clarify safety obligations that transfer to providers who fine-tune or embed your model.
☐ Incident response plan documented
Define your protocol for when something goes wrong, including notification thresholds and model withdrawal conditions.
5. Governance & Accountability
☐ Decision authority identified
Identify who can approve deployment and who can halt it if new risks emerge.
☐ Safety review cadence established
Define when you'll re-evaluate safety, such as after capability improvements or new market deployments.
☐ AI Office engagement documented
Record all communications with the AI Office about systemic risks, including technical meetings and model access requests.
☐ Deployment rationale documented
Provide an evidence-based safety case for why you're confident the model is safe enough to deploy.
Customizing the Checklist
For cybersecurity-capable models: Add items for Responsible Disclosure coordination and critical infrastructure impact assessment.
For models with autonomous capabilities: Include goal alignment verification and oversight mechanisms during autonomous operation.
For models generating synthetic content: Address provenance mechanisms and watermarking implementation.
For foundation models: Monitor downstream use and assess supply chain risks.
Validation Steps
After completing this checklist:
- Convene your governance committee: Present findings and gaps. Don't deploy if critical items remain unchecked.
- Document your safety case: Compile evidence that mitigations are adequate and verifiable. This becomes your defense if the AI Office questions your deployment decision after August 2026.
- Establish pre-deployment review as standard practice: Integrate this checklist into your model development lifecycle.
- Monitor for capability emergence: Regularly re-evaluate models for unexpected capabilities through fine-tuning or novel prompting strategies.
The key question is whether you can demonstrate, with evidence, that your model is safe before deployment. This checklist helps you answer that question honestly.



