WHAT THE ARTICLE IS ABOUT
The compute threshold that separates standard GPAI from systemic-risk GPAI
Article 51 establishes the classification rules for general-purpose AI models with systemic risk — the most powerful subset of GPAI models that face additional obligations beyond those applicable to all GPAI providers. The primary classification criterion is the amount of compute used to train the model, with a threshold set at 10^25 floating point operations (FLOPs).
WHAT IT SAYS
The 10^25 FLOPs threshold — and the Commission’s discretionary power
- A GPAI model is classified as presenting systemic risk where the cumulative amount of compute used for its training is greater than 10^25 floating point operations (FLOPs)
- Providers whose model meets or approaches this threshold must notify the Commission within two weeks
- The Commission may also classify a GPAI model as systemic risk on its own initiative or following a qualified alert from the scientific panel of independent experts — even if the model does not meet the compute threshold — where it has demonstrated high-impact capabilities
- A provider may present arguments to the Commission that their model, despite meeting the compute threshold, does not present systemic risk — the Commission may accept this if the provider can demonstrate it convincingly
- The Commission is empowered to update the compute threshold through delegated acts as technology evolves
- The classification creates a clear two-tier system: all GPAI providers face baseline obligations under Article 53, while systemic-risk providers face additional obligations under Article 55
WHO IS AFFECTED
Large-scale foundation model providers — not typical SMEs
- Major AI companies training large foundation models — OpenAI, Google DeepMind, Anthropic, Meta, Mistral and similar
- Research institutions and national computing initiatives training frontier AI models
- Companies that fine-tune or build on top of systemic-risk GPAI models — they have downstream obligations
- The European Commission and AI Office who manage the classification and notification process
WHAT IT MEANS FOR SMES
Indirect impact through the GPAI models you use
- Very few SMEs will ever train a model above the 10^25 FLOPs threshold — the compute costs alone make this economically unrealistic for small businesses
- However, most SMEs use GPAI models indirectly — through APIs, SaaS products, and embedded AI features — that are provided by companies subject to this article
- The classification of your AI vendor’s underlying model as systemic-risk means that vendor faces stricter obligations — including adversarial testing and incident reporting — which should ultimately produce safer models for you to rely on
- When selecting AI vendors, ask whether their underlying models are classified as systemic-risk GPAI — this tells you something about the level of regulatory scrutiny their technology is subject to
- The threshold will likely be revised downward over time as compute costs fall — a model that is today only trainable by frontier labs may be trainable by larger SMEs within a few years
Related Articles
- Article 3 — Definitions (defines general-purpose AI model and general-purpose AI system)
- Article 52 — Procedure (the process for challenging or confirming systemic risk classification)
- Article 53 — Obligations for all GPAI providers (the baseline obligations before systemic risk classification)
- Article 55 — Obligations for systemic-risk GPAI providers (the additional obligations triggered by this article)
