EU AI Act · Arts. 52, 55

Systemic-risk model duties: evaluations, incident reporting, cybersecurity

Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1)); you may argue the model does not present systemic risk (Art. 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.

What do you actually have to do?

Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1)); you may argue the model does not present systemic risk (Art. 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.

Statutory basis: Arts. 52, 55 — https://artificialintelligenceact.eu/article/55/

Who does this apply to?

  • Provider

When does it apply?

  • 2027-08-02 — legacy models placed before 2 August 2025: comply by 2 August 2027 (Art. 111(3))
  • 2025-08-02 — in force since 2 August 2025

Does ISO 42001 or NIST AI RMF cover this duty?

Requirement-level mappings from Shieldra's crosswalk pack (v2026.07.30). Partial mappings contribute evidence but deliberately do not count as coverage.

Mapped requirementStrengthWhy (and what’s missing)
ISO/IEC 42001 6.1.2PartialA defined AI risk assessment process supports systemic-risk assessment, but Art. 55 also demands model evaluations, adversarial testing, and Commission notification.
ISO/IEC 42001 A.6PartialA.6 verification-and-validation practice contributes to the required model evaluations, not to the adversarial-testing, incident-reporting, or cybersecurity duties.
ISO/IEC 42001 A.8PartialA.8 incident-reporting processes support serious-incident reporting, but Art. 55 sets specific recipients and timelines.
NIST AI RMF MEASURE-2.6PartialRegular safety evaluation against mapped risks with residual-risk demonstration contributes to the systemic-risk assessment and mitigation duty.
NIST AI RMF MEASURE-2.7PartialAdversarial-robustness and jailbreak evaluation is the same practice as Art. 55 adversarial testing and cybersecurity assurance, but not at the depth or cadence the Act mandates.
NIST AI RMF MANAGE-4.3PartialDocumented incident tracking and communication supports serious-incident reporting, but Art. 55 fixes the recipients and deadlines.

Disclaimer

Compliance guidance, not legal advice. Confirm obligations with counsel. Pack verified 2026-09-16.

Frequently asked questions

What does "Systemic-risk model duties: evaluations, incident reporting, cybersecurity" require?

Notify the Commission within two weeks of meeting the systemic-risk threshold (Art. 52(1)); you may argue the model does not present systemic risk (Art. 52(2)). Perform model evaluations and adversarial testing, assess and mitigate systemic risks, report serious incidents, and ensure cybersecurity protection.

When does this obligation apply?

legacy models placed before 2 August 2025: comply by 2 August 2027 (Art. 111(3)). in force since 2 August 2025

Who does this obligation apply to?

The provider role under the EU AI Act. Statutory basis: Arts. 52, 55.