GPAI Models with Systemic Risk Under Article 51
If Article 3(1) is the bouncer and Article 6 is the elevator, Article 51 is the penthouse. A handful of foundation models, and only a handful, clear the threshold to be designated General-Purpose AI with Systemic Risk, and from that moment on their providers play a different game. Mandatory model evaluations. Adversarial testing. Cybersecurity protection. Documented mitigations against systemic risk. Incident reporting to the AI Office that competes with the seven-day Article 73 clock for high-risk deployers. For your organization, the question is not whether you become a GPAI-with-systemic-risk provider, almost certainly you do not, but whether the models you build on are. This lesson is how you read Article 51, find the GPAI-with-systemic-risk models hiding in your stack, and write the procurement memo your AI Officer is going to wish you wrote six months earlier.
Why Article 51 Is the Most Strategically Important Article in the GPAI Stack
The EU AI Act has two GPAI tiers. Plain GPAI sits under Article 53: every provider of a general-purpose AI model owes a public training-content summary, copyright policy, Annex XI technical documentation, and Annex XII downstream-deployer information. The bar is broad and largely procedural. The second tier, GPAI-with-systemic-risk under Article 51, is a fundamentally different bar. Article 55 piles on requirements that include state-of-the-art model evaluations, adversarial testing (red teaming) with documented methodology, cybersecurity protection of the model and its physical infrastructure, and tracking-and-reporting of serious incidents. The Commission can compel evaluations and mitigations. The penalty exposure is the same Article 99 framework, but the practical enforcement attention is concentrated on the small number of providers in this tier.
Why does this matter for a deployer whose organization does not train foundation models? Three reasons. First, every commercial agent stack in 2026 is built on a small set of foundation models: GPT-4-class, Claude-class, Gemini-class, Llama-class, Mistral-class. Some of these are GPAI-with-systemic-risk; some are plain GPAI; some are below the threshold. The legal posture of the upstream provider flows down through your Annex XII receivables, your procurement contracts, and your Article 26 deployer obligations. Second, your AI Officer is going to be asked by the audit committee, "What is our exposure if one of our foundation-model providers is sanctioned by the Commission under Article 55?" That question gets answered by the GPAI exposure map you built off of Article 51. Third, the GPAI Code of Practice, finalized July 10, 2025, was written specifically as a presumed-compliance pathway for GPAI providers under Articles 53 and 55. Whether your upstream provider signed the Code reshapes your downstream attestation work materially. The question "did Meta sign? did Anthropic sign? did OpenAI sign? did DeepSeek?" is a procurement question that you have to be able to answer.
And there is a sharper edge. The Aug 2, 2026 GPAI enforcement date did not move under the Omnibus VII political agreement (May 7, 2026). While stand-alone Annex III applicability moved to Dec 2, 2027 and Annex I embedded-product applicability to Aug 2, 2028, the GPAI enforcement track stayed on the original timeline. That means, for the first time in the AI Act's life, the Commission can fine, recall, or compel mitigation against a GPAI-with-systemic-risk provider starting Aug 2, 2026. The first enforcement actions will probably arrive in the following twelve months. Your organization should know which of its models are exposed.
Reading Article 51 - The Two Pathways to GPAI-With-Systemic-Risk Status
Article 51 has two limbs. The first is the compute presumption under Article 51(1)(a). The second is the Commission discretionary designation under Article 51(1)(b) using the Annex XIII criteria. They are not alternatives in the strict sense; both routes can produce a designated model.
Article 51(1)(a) - The 10^25 FLOPs Compute Presumption
The compute presumption is the cleaner of the two limbs. A GPAI model is presumed to have systemic-risk capabilities when "the cumulative amount of computation used for its training measured in floating-point operations is greater than 10^25." That number, ten to the twenty-fifth power FLOPs, is high enough to exclude almost every model in research-lab use and low enough to capture the largest deployed foundation models. The figure is a presumption, not a ceiling. The provider can rebut the presumption by demonstrating to the Commission that, despite crossing the threshold, the model does not exhibit systemic-risk capabilities. In practice, no major provider has yet successfully rebutted the presumption, and the public posture of major providers is to accept the designation if they cross it.
What models actually cross 10^25 FLOPs in May 2026? The list moves quarter to quarter, but published estimates put the following in or around the threshold: GPT-4 and its successors (OpenAI), Claude 3 / 3.5 / 4 family (Anthropic), Gemini 1.5 / 2 family (Google DeepMind), Llama 3.1-405B and successors (Meta), Mistral Large 2 (Mistral), DeepSeek V3 (DeepSeek). Open-research estimates and independent compute audits put GPT-4-class training around 2 ร 10^25 FLOPs, Claude-3.5 around 1.5-2 ร 10^25 FLOPs, Gemini 1.5 around 2-3 ร 10^25 FLOPs, Llama 3.1-405B around 4 ร 10^25 FLOPs. Smaller open-weight models, Llama 3.1-70B, Mistral Small, Phi-3, sit below the threshold. The list is publicly tracked by the EpochAI compute database, the Stanford CRFM HELM database, and the EU AI Office's emerging GPAI registry.
For your procurement map, you do not need to compute training FLOPs yourself. You need to ask three questions per foundation-model vendor: (1) "Did this model exceed 10^25 cumulative training FLOPs?" (2) "Has the model been notified to the Commission under Article 52?" (3) "Has the Commission designated the model with systemic risk?" Vendor compliance documentation, the Commission's public GPAI list, and the EU AI Office's Stage-4 register are the authoritative sources. Treat published research-community estimates as input, not as the final answer.
Article 51(1)(b) - The Annex XIII Discretionary Designation
The Commission may designate a model with systemic risk even when its training FLOPs are below 10^25, if Annex XIII criteria support the designation. Annex XIII lists ten qualitative and quantitative criteria:
- The number of parameters of the model.
- The quality or size of the dataset, for example measured through tokens.
- The amount of compute used for training the model, measured in FLOPs or estimated from a combination of other variables (cost, training time, energy).
- The input and output modalities of the model (text, image, audio, video, multimodal).
- The benchmarks and evaluations of capabilities of the model, including state-of-the-art benchmarks, autonomous-agent benchmarks, dangerous-capability evaluations.
- Whether the model has a high impact on the internal market because of its reach: for instance, the model is offered for use to at least 10,000 registered business users established in the Union.
- The number of registered end users.
- The autonomy and scalability of the model.
- The tools to which the model has access: agent tooling, code execution, web browsing, file system, external APIs.
- The state of the art relative to other models, particularly for new modalities and emerging capability classes.
The 10,000-business-user criterion is the one to commit to memory. It is the operational threshold that pulls open-weight and below-threshold models into the systemic-risk tier. A model with 9 ร 10^24 training FLOPs but with 50,000 registered business users in the EU is squarely within the Commission's designation reach. A Llama-derivative that is fine-tuned downstream and offered as a SaaS product to 12,000 EU business customers is at risk of designation even if the underlying base model is below the FLOPs presumption.
The Annex XIII pathway is the regulator's escape hatch, the way it can reach a model that the compute presumption misses but that is shaping the market through scale. The Commission's first Article 51(1)(b) designation actions are expected in the second half of 2026 once the GPAI enforcement powers come online. Procurement teams should treat any model with documented 5,000+ EU business users as at-risk for Annex XIII designation and contract accordingly.
What Article 55 Actually Requires of a Designated GPAI-with-Systemic-Risk Provider
Once designated, a GPAI provider falls under Article 55 in addition to Article 53. Article 55(1) lays out the additional obligations:
- Article 55(1)(a) - Model evaluation. Perform model evaluation using state-of-the-art protocols and tools, including conducting and documenting adversarial testing, to identify and mitigate systemic risks.
- Article 55(1)(b) - Risk assessment and mitigation. Assess and mitigate possible systemic risks at the Union level, including the risks' sources, that may stem from the development, placing on the market, or use of general-purpose AI models with systemic risk.
- Article 55(1)(c) - Serious-incident tracking and reporting. Keep track of, document, and report, without undue delay, to the AI Office and as appropriate to national competent authorities, relevant information about serious incidents and possible corrective measures.
- Article 55(1)(d) - Cybersecurity protection. Ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and the physical infrastructure of the model.
Read together, Article 55 establishes a four-pillar regime: evaluate, mitigate, report, secure. The evaluation pillar is where most public attention has landed because it absorbs the academic and industry literature on dangerous-capability testing, biosecurity, cyberweapon, autonomous-replication, persuasion-and-manipulation, and chemical-weapon evals, and gives the AI Office authority to compel methodologies, scope, and disclosure. The cybersecurity pillar is where the supply-chain attestation work lives. The mitigation pillar carries the most political weight: it is what makes the Commission's ongoing relationship with frontier-model providers a policy negotiation rather than a one-time check.
The Systemic Risks Named in the Act
Recital 110 of the Regulation enumerates the systemic risks the Commission is most concerned with. They include: chemical, biological, radiological, and nuclear (CBRN) risks; cyberattacks; large-scale discrimination; misinformation harming democratic processes or public safety; large-scale violation of fundamental rights; loss of control over autonomous AI; uncertainty about reproducibility and predictability of model outputs. The Commission's first round of guidance, published in mid-2025, translated this list into the evaluation taxonomy that the AI Office now uses in its compliance dialogues with Anthropic, OpenAI, Google DeepMind, Meta, Mistral, and the other major providers. The taxonomy is essentially the Commission's version of what the U.S. Center for AI Safety and Innovation (CAISI) calls the "frontier capability evaluations" and what UK AISI calls the "dangerous capability evaluations." The three regimes are converging on the same scoreboard.
The AI Office as the Direct Counterparty
Designated GPAI providers report directly to the EU AI Office under Article 55(1)(c). Serious incidents, defined to include malfunction or use of the model that leads or could plausibly lead to death, serious health harm, infrastructure disruption, fundamental-rights infringement, or material property/environment damage, must be reported "without undue delay." The reporting clocks established for high-risk deployer incidents under Article 73 (10 days for death; 2 days for widespread fundamental-rights infringement or critical-infrastructure disruption; 15 days for other serious incidents) do not literally apply to GPAI-systemic-risk providers, but the AI Office is signaling, through its draft guidance and public dialogue, that it expects comparable timeliness. A foundation-model provider that delays incident notification will not be saved by the literal text of the article.
Article 53 - The Base GPAI Tier That Applies Even Without Systemic-Risk Designation
Every GPAI provider, designated or not, owes Article 53 obligations from Aug 2, 2025 (in-force date) with enforcement Aug 2, 2026. The four-part bar:
- Article 53(1)(a) - Annex XI technical documentation. Draw up and maintain technical documentation of the model, including the training and testing process and the results of its evaluation, containing at least the information set out in Annex XI for the purpose of providing it, upon request, to the AI Office and the national competent authorities.
- Article 53(1)(b) - Annex XII downstream-deployer information. Draw up, maintain, and make available information and documentation to providers of AI systems who intend to integrate the GPAI model into their AI systems, containing at least the information set out in Annex XII.
- Article 53(1)(c) - Copyright policy. Put in place a policy to comply with Union law on copyright and related rights, in particular to identify and comply with reservations of rights expressed pursuant to Article 4(3) of the Copyright Directive (the TDM opt-out).
- Article 53(1)(d) - Public training-content summary. Draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office.
Annex XI obliges the provider to document model architecture, training data sources at a high level, evaluation results, energy consumption, distribution channels, intended use, prohibited use, and the methods used to test and evaluate the model. Annex XII obliges the provider to give downstream deployers the model's capabilities and limitations, model evaluation results, training-data characterization, technical means for integration, technical updates, applicable acceptable-use policies, and contact for further information.
For a deployer building on top of a GPAI model, Annex XII is the receivable that anchors your Annex IV technical-file work for any high-risk system you assemble. If your vendor will not produce the Annex XII pack, your procurement is incomplete, and your downstream conformity assessment will be unable to evidence compliance with the Article 13 (information to deployers) and Article 26 (deployer obligations) requirements.
The GPAI Code of Practice - Final Version, Signatory Strategy, and the Non-Signatory Trap
The GPAI Code of Practice, finalized on July 10, 2025, is the operational pathway the Commission designed for GPAI providers to demonstrate compliance with Articles 53 and 55 until harmonized standards are published. The Code has three chapters: Transparency, Copyright, and Safety and Security. Each chapter contains operational commitments: for example, the Transparency chapter aligns with the Annex XI documentation expectations; the Copyright chapter operationalizes the TDM opt-out; the Safety and Security chapter operationalizes Article 55 evaluations, mitigations, incident tracking, and cybersecurity.
Signing the Code is voluntary. The benefit is a presumption of compliance, the Commission has said it will consider Code-of-Practice signatories to be in conformity with the corresponding Articles 53 and 55 obligations. The downside is operational overhead: the safety commitments are substantive, and signatory providers commit to specific evaluation practices and transparency deliverables that non-signatory providers do not.
As of May 2026, the Code's signatory list is a mix of provider responses to the regulatory tradeoff:
- Signatories include Anthropic, OpenAI, Google DeepMind, Microsoft, Mistral, Cohere, and several mid-size European providers. These providers can point to the Code in their downstream-deployer documentation and argue presumptive compliance.
- Non-signatories include Meta (publicly declined, citing operational concerns), Alibaba, Baidu, DeepSeek, and most providers based outside the EU or U.S. Non-signatory providers still owe Article 53 obligations and Article 55 obligations if designated; they simply lose the regulatory-presumption benefit.
- Undecided at time of writing: several mid-size providers and open-weight initiatives whose signatory status is being tracked publicly.
For your procurement memo, the signatory status of your upstream provider has three consequences. First, regulatory documentation flow-down. A signatory provider has standardized Annex XII outputs and known transparency commitments; a non-signatory provider obligates you to produce more downstream attestation work to fill the gap. Second, Article 53(1)(c) copyright posture. A signatory provider has a documented policy aligned to the Code's copyright chapter; a non-signatory provider's policy may be opaque or weaker. Third, Article 53(1)(d) public training-data summary. The Code defines a template; non-signatory providers may produce a summary in their own format, and your downstream documentation has to bridge any gap.
The non-signatory trap to avoid: assuming that a non-signatory provider's Article 53 disclosures are absent. They are not. The obligation applies regardless of Code-of-Practice posture. The non-signatory provider is simply more likely to disclose less, later, and in less standardized formats. Procurement contracts should specify the Annex XI, Annex XII, copyright policy, and public training-data summary deliverables explicitly, with delivery dates, regardless of signatory status. The contract is the floor; the Code is the ceiling.
Building the GPAI Exposure Map - The L1 Procurement Artifact
The L1 deliverable in this area is the GPAI exposure map: a table covering every foundation model used directly or indirectly across your AI portfolio, with columns for tier (GPAI-with-systemic-risk under Article 51, plain GPAI under Article 53, below-GPAI), signatory status, Annex XI receivable status, Annex XII receivable status, copyright policy status, public training-data summary status, and the downstream-deployer mitigation work it triggers. Here is the column structure:
- Model. Vendor and version. (E.g., "OpenAI GPT-4o (May 2026 release)", "Anthropic Claude 4 Opus (April 2026 release)", "Meta Llama 3.1-405B base", "DeepSeek V3 (December 2025 release)".)
- Deployment surface. Where the model touches the enterprise. (E.g., "customer-service chatbot," "coding assistant," "marketing-content generator," "embeddings for resume ranker," "agentic workflow for internal IT helpdesk.")
- Article 51 status. Designated GPAI-with-systemic-risk; presumed under Article 51(1)(a) compute; under Annex XIII Article 51(1)(b) review; below threshold.
- GPAI Code of Practice signatory. Yes / No / Undecided. With source.
- Annex XI documentation status. Received / Partial / Missing. Cite the specific receivable.
- Annex XII downstream-deployer documentation status. Received / Partial / Missing. Cite the specific receivable.
- Copyright policy status (Article 53(1)(c)). Confirmed compliant / Partial / Missing.
- Public training-data summary status (Article 53(1)(d)). Available / Partial / Missing.
- Mitigation owner and review date. Operational responsibility for closing gaps; next review.
For a Fortune-500 in May 2026, this map typically contains 8-20 rows: every commercial foundation-model vendor, every open-weight model used internally for fine-tuning, every model embedded in a SaaS product the enterprise has procured. The map sits next to the AI inventory and the tiering register, and it is the artifact procurement carries into every contract renegotiation. The audit committee should see the map quarterly.
Five-Vendor Walk-Through - Applying the GPAI Analysis
Vendor 1 - OpenAI (GPT-4o, GPT-5 series)
Article 51 status: presumed under Article 51(1)(a) compute (well above 10^25 FLOPs). Article 55 applies. GPAI Code signatory: yes. Annex XI documentation: extensive (system cards, model cards, evaluation results, scoping documents). Annex XII: provided through OpenAI's enterprise documentation portal. Copyright policy: documented; aligned to the Code's copyright chapter; TDM opt-out compliance under scrutiny by EU rights-holder organizations. Public training-data summary: provided per Code template. Mitigation work for the deployer: relatively low, most receivables are off-the-shelf. Procurement contract: standard enterprise terms apply; the OpenAI / Promptfoo integration post-March 2026 acquisition adds a vendor-concentration risk in the eval-tools market that should be tracked separately.
Vendor 2 - Anthropic (Claude 3.5, 4 series)
Article 51 status: presumed under Article 51(1)(a) compute. Article 55 applies. GPAI Code signatory: yes. Annex XI documentation: extensive (Anthropic Responsible Scaling Policy, model cards, Constitutional AI evaluation reports). Annex XII: provided in vendor documentation. Copyright policy: documented. Public training-data summary: provided per Code template. Mitigation work for the deployer: low. The Anthropic public posture (RSP, ASL evaluations, third-party red teams) provides more deployer-side defensible evidence than most competitors.
Vendor 3 - Google DeepMind (Gemini 1.5, Gemini 2)
Article 51 status: presumed under Article 51(1)(a) compute. Article 55 applies. GPAI Code signatory: yes. Annex XI documentation: provided via the Google Cloud Vertex AI documentation. Annex XII: provided. Copyright policy: documented; TDM opt-out under continued scrutiny. Public training-data summary: provided per Code template. Mitigation work for the deployer: low to medium, the Vertex AI scope is broad and Annex XII receivables can be inconsistent across model variants.
Vendor 4 - Meta (Llama 3.1-405B, Llama 4 series)
Article 51 status: presumed under Article 51(1)(a) compute (Llama 3.1-405B is publicly estimated at ~4 ร 10^25 FLOPs). Article 55 applies. GPAI Code signatory: no (publicly declined, citing operational concerns). Annex XI documentation: provided via Meta's published model cards and Llama documentation. Annex XII: provided through Llama community documentation, but less standardized than Code-signatory peers. Copyright policy: documented; Meta's posture has been litigated extensively. Public training-data summary: provided per Meta's own format, not the Code template. Mitigation work for the deployer: elevated. Because Meta is a non-signatory, deployers must produce additional downstream attestation work: internal evaluations, provenance documentation, Article 50(2) marking commitments, and contractual flow-down language that fills the gap the non-signatory leaves. Procurement contracts should include explicit Annex XI / XII delivery and update obligations.
Vendor 5 - DeepSeek (V3, R1 series)
Article 51 status: under Article 51(1)(a) compute review (DeepSeek V3 training-FLOPs estimates vary across published research; some estimates put it above 10^25, some below). Likely Annex XIII candidate even if below threshold (the model has substantial EU business-user footprint via downstream re-distributors). Article 55 may apply on designation. GPAI Code signatory: no. Annex XI documentation: published partially via the DeepSeek technical reports. Annex XII: limited; English-language documentation gaps. Copyright policy: limited disclosure. Public training-data summary: minimal. Mitigation work for the deployer: high. Procurement should weigh the open-weight benefit against the elevated attestation work required for a non-signatory, low-disclosure provider with European business-user reach approaching the Annex XIII threshold.
Annex XI vs. Annex XII - The Provider's Two Documentation Streams
The two annexes are easy to confuse and serve very different purposes. Annex XI is the upstream regulator-facing technical documentation. Annex XII is the downstream-deployer-facing information pack. Both are mandatory for GPAI providers under Article 53.
| Annex XI (provider โ regulator) | Annex XII (provider โ deployer) |
|---|---|
| General description of the model | Description of the model's capabilities and limitations |
| Training and testing process | Model evaluation results, including on benchmarks |
| Energy consumption | Training data characterization (high level) |
| Distribution channels | Means for technical integration of the model into AI systems |
| Intended and prohibited use | Technical updates and modifications relevant to downstream integration |
| Evaluation methodology and results | Applicable acceptable-use policies |
| Risk assessment (if Article 51-designated) | Contact point for further information |
For deployer-side procurement, Annex XII is the working receivable. If a vendor cannot produce the Annex XII pack on procurement request, the deployer's downstream conformity-assessment work (for any high-risk AI system built on top) is fundamentally constrained. The Article 26 deployer obligation to "use the high-risk AI system according to the instructions for use" assumes the deployer has those instructions, which is Annex XII territory.
Three Common GPAI Mistakes - And the Audit-Defensible Counter-Stances
Mistake 1 - Conflating GPAI With GPAI-With-Systemic-Risk
Every GPAI provider owes Article 53. Only designated providers owe Article 55. Many enterprise programs conflate the two tiers and either over-spec procurement requirements ("the vendor must produce Article 55 evaluations even though it is below threshold") or under-spec them ("we don't need Annex XII because Llama is open source"). The fix is to apply the Article 51 status column to every model in the map, then apply the Article 53 obligations universally and Article 55 obligations only where designated. Article 53 is the floor for every GPAI; Article 55 is the additional ceiling for the designated subset.
Mistake 2 - Treating the 10^25 FLOPs Threshold as a Ceiling
The compute threshold is a presumption, not a ceiling. Article 51(1)(b) gives the Commission discretionary designation power for below-threshold models that meet Annex XIII criteria. The 10,000-EU-business-user criterion is the most common pull-in. An open-weight model with broad EU SaaS distribution is at risk of Annex XIII designation, and the procurement contract should anticipate the possibility. Treating below-10^25 as automatically safe is a common Mistake 2 finding in 2026.
Mistake 3 - Assuming Non-Signatory Providers Have No Article 53 Obligations
This is the most expensive mistake on the procurement side. A non-signatory provider, Meta, DeepSeek, Alibaba, Baidu, others, still owes Article 53 obligations from Aug 2, 2025 (with enforcement Aug 2, 2026). Article 53(1)(a) Annex XI documentation, Article 53(1)(b) Annex XII downstream-deployer information, Article 53(1)(c) copyright policy, Article 53(1)(d) public training-data summary all apply regardless of Code signatory status. The Code is a presumption-of-compliance mechanism; it is not a substitute for the underlying obligations. Procurement contracts with non-signatory providers should be more, not less, prescriptive about delivery and update of the four Article 53 receivables.
Aligning the GPAI Exposure Map With ISO 42001, NIST AI RMF, and Supply-Chain Attestation
The GPAI exposure map serves multiple frameworks simultaneously. ISO/IEC 42001:2023 Annex A control A.10 (third-party relationships) requires the organization to address risks associated with third-party providers of AI systems and components; the GPAI exposure map is the A.10 artifact for foundation-model upstream. NIST AI RMF 1.0 function Map 4 ("Risks and benefits are mapped for all components, including third-party software and data") and Govern 6.1 (third-party policies) sit on the same evidence. The CycloneDX 1.7 ML-BoM specification provides the machine-readable schema for representing the GPAI exposure pattern in build pipelines: the model identifier, version, training-data references, evaluation-result hashes, and provenance attestations flow from the exposure map into the ML-BoM and from there into supply-chain attestation work. The dual-citation pattern continues: write the map once, cite it against four frameworks.
Key Takeaways
- Article 51 is the penthouse of the GPAI stack. Designated providers face Article 55's evaluate-mitigate-report-secure regime in addition to Article 53. The penalty exposure is the same Article 99 framework; the practical enforcement attention is concentrated on the small group of designated providers.
- Two pathways to systemic-risk designation. Article 51(1)(a), the 10^25 cumulative FLOPs compute presumption. Article 51(1)(b): the Commission's discretionary Annex XIII designation, with the 10,000-EU-business-user criterion as the most common operational pull-in.
- Article 53 applies to every GPAI provider regardless of designation. Annex XI technical documentation, Annex XII downstream-deployer information, Article 53(1)(c) copyright policy, Article 53(1)(d) public training-data summary. Enforcement Aug 2, 2026 (the date Omnibus VII did not move).
- Annex XII is the receivable that anchors deployer-side conformity work. If your vendor cannot produce the Annex XII pack on request, your downstream Annex IV technical-file work is constrained, and your Article 26 deployer obligations are unevidenced.
- The GPAI Code of Practice is a presumption-of-compliance pathway, not a substitute for the underlying obligations. Signatories (Anthropic, OpenAI, Google DeepMind, Microsoft, Mistral, Cohere) get a regulatory benefit. Non-signatories (Meta, Alibaba, Baidu, DeepSeek) still owe Article 53 and Article 55 (if designated).
- Non-signatory procurement requires more, not less, contractual diligence. Specify the Annex XI, Annex XII, copyright policy, and public training-data summary deliverables explicitly with delivery dates. The contract is the floor; the Code is the ceiling.
- The GPAI exposure map is the L1 procurement artifact. A table covering every foundation model in the stack, with tier, signatory status, receivable status, and mitigation owner per row. Audit committee sees it quarterly.
- Aug 2, 2026 did not move for GPAI enforcement. Omnibus VII delayed stand-alone Annex III (Dec 2, 2027) and Annex I (Aug 2, 2028) but left the GPAI enforcement track on the original timeline. Commission enforcement powers go live in 2026.
- The 10^25 FLOPs threshold is a presumption, not a ceiling. Below-threshold models can be designated under Annex XIII when business-user reach, autonomy, scalability, modality, or capability benchmarks support designation.
- The exposure map is multi-framework evidence. ISO 42001 A.10 third-party relationships, NIST AI RMF Map 4 + Govern 6.1 third-party policies, CycloneDX 1.7 ML-BoM supply-chain attestation. Write once, cite four times.
Skill.re