Why it matters
GPAI models classified as presenting systemic risk face additional duties for evaluations, adversarial testing, systemic-risk assessment and mitigation, incident reporting, and cybersecurity.
What this looks like in practice
- 01Assess reach, downstream dependence, capabilities, autonomy, access, and plausible pathways to large-scale harm.
- 02Do not treat the EU compute threshold as the only possible route to classification.
- 03Link upstream model risk to downstream system monitoring and incident response.