Section 3
Obligations of providers of general-purpose AI models with systemic risk
Article 55: Obligations of Providers of General-Purpose AI Models with Systemic Risk
1.
In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risksystemic riskmeans a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chainArticle 3(65) shall:
(a)
perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks;
(b)
assess and mitigate possible systemic risks at Union level, including their sources, that may stem from the development, the placing on the marketplacing on the marketmeans the first making available of an AI systemAI systemmeans a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environmentsArticle 3(1) or a general-purpose AI model on the Union marketArticle 3(9), or the use of general-purpose AI models with systemic risksystemic riskmeans a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chainArticle 3(65);
(c)
keep track of, document, and report, without undue delay, to the AI OfficeAI Officemeans the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the CommissionArticle 3(47) and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them;
(d)
ensure an adequate level of cybersecurity protection for the general-purpose AI modelgeneral-purpose AI modelmeans an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the marketArticle 3(63) with systemic risksystemic riskmeans a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chainArticle 3(65) and the physical infrastructure of the model.
2.
Providers of general-purpose AI models with systemic risksystemic riskmeans a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chainArticle 3(65) may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standardharmonised standardA European standard adopted on the basis of a request made by the Commission for the application of Union harmonisation legislationRegulation (EU) 1025/2012 Art. 2(1)(c) is published. Compliance with European harmonised standards grants providers the presumption of conformity to the extent that those standards cover those obligations. Providers of general-purpose AI models with systemic risks who do not adhere to an approved code of practice or do not comply with a European harmonised standardharmonised standardA European standard adopted on the basis of a request made by the Commission for the application of Union harmonisation legislationRegulation (EU) 1025/2012 Art. 2(1)(c) shall demonstrate alternative adequate means of compliance for assessment by the Commission.
3.
Any information or documentation obtained pursuant to this Article, including trade secrets, shall be treated in accordance with the confidentiality obligations set out in Article 78.