Article 55 imposes a set of enhanced obligations on providers of GPAI models with systemic risk. These obligations go significantly beyond the baseline requirements of Article 53 and reflect the heightened concern about wide-scale, difficult-to-reverse harms that such models could enable.
The Four Article 55 Obligations
- (a) Perform model evaluations, including adversarial testing and red-teaming, to identify and mitigate systemic risks
- (b) Assess and mitigate possible systemic risks at Union and non-Union levels, including their sources, through the model evaluation process
- (c) Track, document, and report without undue delay to the AI Office and relevant national competent authorities any serious incidents and possible corrective measures
- (d) Ensure an adequate level of cybersecurity protection for the GPAI model with systemic risk and its physical infrastructure
Adversarial Testing and Red-Teaming
Article 55(1)(a) requires adversarial testing to be carried out on a model-specific basis with particular attention to systemic risks. This is distinct from the broader safety evaluation practices used during model development. The AI Office may issue guidelines on testing methodologies and on the specific systemic risks that evaluations must address. External experts, including representatives from academia and civil society, may be involved in evaluations.
Regulation (EU) 2024/1689 — Article 55(1)(a)
“Perform model evaluations in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.”