Skip to main content
Category: EU AI Act & GPAI

General-Purpose AI Model with Systemic Risk

Also known as: GPAISR, GPAI model with systemic risk, GPAI with systemic risk, General-purpose AI model with systemic risk
Simply put

A general-purpose AI model with systemic risk is a category, defined under the EU AI Act, for the most advanced general-purpose AI models whose capabilities could cause large-scale harm. In the available evidence, a model is presumed to fall into this category if it was trained using a very large amount of computing power, or if it is judged to have unusually powerful ('high-impact') capabilities. Because it is a legal classification specific to the EU, its meaning and thresholds are tied to that framework rather than to AI regulation generally.

Formal definition

Under the EU AI Act framework, a general-purpose AI model (GPAI) is classified as presenting systemic risk when it has 'high-impact capabilities' evaluated using appropriate technical tools and methodologies, where systemic risks are understood as risks of large-scale harm arising from the most advanced (state-of-the-art) models. According to the evidence, a GPAI model is presumed to have systemic risk if the cumulative amount of computation used for its training exceeds 10^25 FLOPs, though this compute-based threshold operates as a presumption rather than as the sole determinant, since high-impact capability may also be assessed on other grounds. This is a jurisdiction-specific classification tied to the EU AI Act; the specific thresholds, the presumption mechanism, and the operative definition of 'high-impact capabilities' should be verified against the current text of the instrument and any implementing guidance, as the concept has been characterized in the literature as contested and evolving.

Why it matters

The GPAISR classification is significant because it determines which providers of general-purpose AI models face the EU AI Act's most demanding obligations. Rather than regulating all general-purpose models uniformly, the framework as reflected in the evidence reserves a heightened tier for the most advanced (state-of-the-art) models whose capabilities could, in the view of the regulator, contribute to large-scale harm. For providers, falling into this category typically changes the compliance posture materially; for compliance officers and legal teams, correctly determining whether a model crosses into this classification is therefore a threshold governance question rather than a routine one.

The classification also matters because it operates through a presumption mechanism rather than a single bright-line rule. According to the evidence, a model is presumed to present systemic risk where the cumulative training compute exceeds 10^25 FLOPs, but 'high-impact capabilities' may also be assessed on other grounds. This dual basis means organizations cannot rely solely on a compute figure to conclude a model is out of scope, and it introduces genuine assessment uncertainty. The concept has been characterized in the academic literature as contested and evolving, which is a limitation professionals should keep in view: the operative thresholds, the presumption mechanism, and the working definition of 'high-impact capabilities' should be verified against the current text of the instrument and any implementing guidance rather than treated as settled.

Because this is a jurisdiction-specific classification tied to the EU AI Act, its meaning and thresholds do not transfer to other regulatory regimes or to AI risk discourse generally. Reading it as a universal definition of 'systemic AI risk' would be a category error. It is a legal designation within one framework, and it is distinct from broader model risk management concepts that govern how model risk is measured, monitored, and controlled inside an organization.

Who it's relevant to

Providers of general-purpose AI models
Organizations that develop or place general-purpose AI models on the EU market need to determine whether their models fall within the GPAISR classification, since this designation carries the framework's most demanding obligations. The compute-based presumption and the capability-based assessment described in the evidence both bear on that determination, and neither should be treated as the sole test.
Compliance officers and legal specialists
Professionals responsible for EU AI Act compliance must treat GPAISR as a threshold classification question tied specifically to that instrument. Because the operative thresholds, the presumption mechanism, and the definition of 'high-impact capabilities' are characterized as contested and evolving, they should verify current requirements against the instrument's text and implementing guidance rather than relying on secondary summaries.
Model risk managers and AI governance teams
Those managing model risk or AI governance should note that GPAISR is a jurisdiction-specific legal classification, distinct from internal frameworks for measuring, monitoring, and controlling model risk. Identifying whether a model is presumed to present systemic risk under the EU framework is a separate exercise from an organization's own risk assessment and does not substitute for it.
Auditors and policy specialists
Auditors and policy professionals assessing how an organization maps to the EU AI Act need to understand that the GPAISR category applies only to the most advanced general-purpose models and only within the EU framework. Its meaning and thresholds should not be generalized to other regulatory regimes or to AI risk discourse at large.

Inside GPAISR

General-Purpose AI (GPAI) baseline
GPAISR is a subset of general-purpose AI models. As commonly framed under the EU AI Act, a GPAI model is one trained on broad data that displays significant generality and can competently perform a wide range of distinct tasks, integrable into many downstream systems. GPAISR builds on this baseline by adding a systemic-risk qualification.
Systemic risk designation
The 'systemic risk' element refers to risks considered to have large-scale or wide-reaching potential impact, for example across the value chain or on public health, safety, security, or fundamental rights. Under the EU AI Act framework, models meeting this threshold are subject to additional obligations beyond those applying to ordinary GPAI models. The scope and precise triggers are governed by that specific instrument and should not be assumed to apply outside it.
Capability / compute threshold
In the EU AI Act framework, a model may be presumed to have systemic risk when it meets certain high-impact capability criteria, which have been associated with training-compute thresholds. Because specific numeric thresholds and their revision mechanisms are set and may be updated by the relevant EU bodies, practitioners should verify the current figures against the primary source rather than rely on a fixed number here.
Enhanced provider obligations
Providers of GPAISR models are typically subject to heightened requirements relative to standard GPAI, which in this framework can include model evaluation, adversarial testing, systemic-risk assessment and mitigation, incident tracking and reporting, and cybersecurity measures. The exact list and its enforceability derive from the applicable EU legal instrument and any accompanying codes of practice or guidance.
Jurisdictional and instrument scope
GPAISR as a defined category originates in EU legislation and is not a universal or interchangeable concept. It is distinct from voluntary standards or non-EU guidance, and it should not be treated as equivalent to model risk management categories used in other sectors such as banking.

Common questions

Answers to the questions practitioners most commonly ask about GPAISR.

Does the 'systemic risk' designation for a general-purpose AI model mean the model is inherently dangerous or defective?
No. As commonly framed in EU AI Act discussions, the classification concerns a model's potential scale of impact and capabilities rather than a finding that a specific model is dangerous or defective. The designation is a trigger for additional obligations placed on the provider, not a judgment that the model has caused or will cause harm. Reading it as a defect label conflates a risk-tiering mechanism with a product-safety determination, and readers should treat the precise criteria and thresholds as matters defined by the relevant regulatory text rather than by intuition about model quality.
Is meeting the GPAISR obligations the same as having good AI governance or a mature model risk management program in place?
Not necessarily. Complying with the specific obligations associated with GPAI models with systemic risk is a legal or regulatory compliance activity scoped to a particular jurisdiction and instrument. AI governance refers more broadly to the organizational structures, policies, and accountability arrangements an organization uses to oversee AI, while model risk management concerns the identification, measurement, monitoring, and control of risks arising from model use. These areas overlap in practice, but satisfying GPAISR-specific duties does not by itself establish a complete governance framework or a mature model risk management program, and conflating them can leave gaps in oversight.
How should an organization determine whether a model it provides or uses falls within the GPAISR category?
The determination typically depends on criteria and thresholds set out in the relevant regulatory text, and the specific parameters should be confirmed against the current official instrument rather than assumed. Practically, organizations often begin by cataloguing the general-purpose models they develop or deploy, identifying whether their role is that of a provider or a downstream deployer, and then assessing each model against the applicable classification criteria. Because the precise thresholds and their interpretation may evolve, many organizations treat this as a periodic reassessment rather than a one-time exercise, and document the basis for their classification decisions.
What internal roles and lines of defense are commonly involved in managing GPAISR-related obligations?
Responsibilities are often distributed across functions in a way that mirrors the three-lines model many organizations use, without collapsing the distinctions between them. The first line typically includes the teams that build, fine-tune, or deploy the model and own the associated controls day to day. A second line, such as risk or compliance functions, commonly provides oversight, challenge, and policy setting. A third line, such as internal audit, may provide independent assurance. The precise allocation depends on the organization's size, sector, and existing governance structure, so this should be treated as a common pattern rather than a prescribed arrangement.
What documentation practices help an organization demonstrate that GPAISR obligations are being addressed?
Organizations commonly maintain records that show how a model was classified, what obligations were identified as applicable, and how those obligations are being met over time. This can include documentation of model characteristics relevant to the classification, evidence of monitoring and control activities, and records of decisions and their rationale. Because the specific documentation expectations flow from the applicable regulatory instrument, organizations should map their records to the current requirements rather than to a generic template, and treat documentation as evidence that supports, but does not by itself guarantee, compliance.
How do GPAISR obligations relate to obligations that apply to downstream deployers who integrate the model into their own systems?
Obligations are generally allocated according to an actor's role, so a provider of a general-purpose model with systemic risk and a downstream deployer that integrates it may face different duties. In practice this means an organization needs to identify its own role for each use case, since the same entity can be a provider in one context and a deployer in another. Coordination between providers and deployers, including the flow of information needed for each party to meet its respective obligations, is often important, but the specific division of responsibility should be confirmed against the applicable regulatory text rather than assumed.

Common misconceptions

All large general-purpose AI models are GPAISR.
GPAISR is a narrower category than GPAI. A model is a general-purpose model by virtue of its generality, but it is classified as carrying systemic risk only when it meets the additional high-impact criteria defined in the applicable framework. Many GPAI models fall outside the systemic-risk designation and are subject only to the baseline GPAI obligations.
The GPAISR designation is a globally applicable AI risk standard.
As commonly understood, GPAISR is a category created within a specific EU legislative framework and is scoped to that jurisdiction. It is not interchangeable with voluntary standards or with guidance and risk frameworks issued by other bodies, and it does not automatically apply to organizations outside that legal scope.
Meeting GPAISR obligations eliminates the systemic risk posed by the model.
The obligations associated with GPAISR are risk-management and oversight measures intended to reduce, monitor, and mitigate systemic risk; they do not eliminate it. Residual risk typically remains after controls such as evaluation, adversarial testing, and mitigation are applied.

Best practices

Confirm whether a given model actually meets the systemic-risk criteria under the current version of the applicable EU framework before applying GPAISR obligations, rather than assuming that model size alone triggers the designation.
Verify the current capability and compute thresholds and any updates against the primary regulatory source, since these figures may be revised by the relevant EU bodies over time.
Maintain documented model evaluation, adversarial testing, and systemic-risk assessment processes where the framework requires them, and treat these as ongoing rather than one-time activities.
Establish incident tracking and reporting workflows so that relevant events can be identified and escalated in line with the framework's expectations.
Distinguish GPAISR legal obligations from broader AI governance and model risk management practices in internal documentation, so that jurisdiction-specific requirements are not conflated with voluntary standards or other sectors' guidance.
Document residual risk explicitly after mitigation measures are applied, recognizing that controls reduce rather than remove systemic risk.