GovernanceCore
Regulation

Systemic risk

Working definition

Reviewed 30 July 2026

In the EU AI Act’s GPAI regime, systemic risk is risk specific to the high-impact capabilities of general-purpose AI models that can have significant effects on the EU market due to their reach, or actual or reasonably foreseeable negative effects on public health, safety, security, fundamental rights, or society as a whole.

Context

Why it matters

GPAI models classified as presenting systemic risk face additional duties for evaluations, adversarial testing, systemic-risk assessment and mitigation, incident reporting, and cybersecurity.

Operating note

What this looks like in practice

  1. 01Assess reach, downstream dependence, capabilities, autonomy, access, and plausible pathways to large-scale harm.
  2. 02Do not treat the EU compute threshold as the only possible route to classification.
  3. 03Link upstream model risk to downstream system monitoring and incident response.

Sources & further research

Primary authority anchors the definition. Research links add conceptual or operational depth. External sources may update independently; always verify legal duties against the current official text.

  1. Official source

    Regulation (EU) 2024/1689, Articles 3(65), 51, and 55

    Defines systemic risk, establishes classification routes, and sets additional provider obligations.

    European Union
    2024
    Open source ↗
  2. Research paper

    Model Evaluation for Extreme Risks

    Proposes evaluation of dangerous capabilities and alignment for models near the capability frontier.

    Shevlane et al.
    2023
    Open source ↗