EU AI Act · Arts. 52, 55
Systemic-risk model duties: evaluations, incident reporting, cybersecurity
Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1), rebuttal possible under 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.
By the Shieldra Compliance Team · Last updated 2026-07-29
What do you actually have to do?
Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1), rebuttal possible under 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.
Statutory basis: Arts. 52, 55 — https://artificialintelligenceact.eu/article/55/
When does it apply?
- 2027-08-02 — legacy models placed before 2 August 2025: comply by 2 August 2027 (Art. 111(3))
- 2025-08-02 — in force since 2 August 2025
Does ISO 42001 or NIST AI RMF cover this duty?
Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.
| Mapped requirement | Strength | Why (and what’s missing) |
|---|
| ISO/IEC 42001 6.1.2 | Partial | A defined AI risk assessment process supports systemic-risk assessment, but Art. 55 also demands model evaluations, adversarial testing, and Commission notification. |
| ISO/IEC 42001 A.6 | Partial | A.6 verification-and-validation practice contributes to the required model evaluations, not to the adversarial-testing, incident-reporting, or cybersecurity duties. |
| ISO/IEC 42001 A.8 | Partial | A.8 incident-reporting processes support serious-incident reporting, but Art. 55 sets specific recipients and timelines. |
| NIST AI RMF MEASURE-2.6 | Partial | Regular safety evaluation against mapped risks with residual-risk demonstration contributes to the systemic-risk assessment and mitigation duty. |
| NIST AI RMF MEASURE-2.7 | Partial | Adversarial-robustness and jailbreak evaluation is the same practice as Art. 55 adversarial testing and cybersecurity assurance, but not at the depth or cadence the Act mandates. |
| NIST AI RMF MANAGE-4.3 | Partial | Documented incident tracking and communication supports serious-incident reporting, but Art. 55 fixes the recipients and deadlines. |
Disclaimer
Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-07-29.
Frequently asked questions
What does "Systemic-risk model duties: evaluations, incident reporting, cybersecurity" require?
Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1), rebuttal possible under 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.
When does this obligation apply?
legacy models placed before 2 August 2025: comply by 2 August 2027 (Art. 111(3)). in force since 2 August 2025
Who does this obligation apply to?
The provider role under the EU AI Act. Statutory basis: Arts. 52, 55.