- Supports the serious-incident report fields for GPAI models with systemic risk under Article 55(1)(c).
"serious incidents"
Assemble the records a GPAI model provider needs for EU AI Act Article 53 obligations, with Article 55 extensions when the model has systemic risk.
This page helps collect technical documentation, downstream-provider information, copyright-policy evidence, a public training-content summary, and systemic-risk testing, incident, and cybersecurity records where applicable.
Structured answer sets in this page tree.
Cited legal and guidance references.
First decide whether the organisation places a on the Union market as its provider or merely integrates another provider's model into an AI system. Providers need the Article 53 baseline pack; providers of GPAI models with systemic risk also need the Article 55 safety, incident, and cybersecurity records. The duties apply at model level and do not replace classification of each downstream AI system.
Start the pack with a model-level record that is separate from product feature records. Article 53 applies to providers of general-purpose AI models, and the Commission guidance explains who must comply and what is expected from them.
Record whether the organisation is the original model provider, has placed a modified or fine-tuned GPAI model on the Union market, or is only integrating another provider's model into an AI system. Keep the model version, release date, Union market release date, distribution method, licence, dependencies, authorised representative status where relevant, and evidence of model authenticity in one place.
Chapter V applied from 2 August 2025. Providers of GPAI models placed on the market before that date must comply from 2 August 2027, while models placed on the market from 2 August 2025 entered the applicable regime immediately. The Commission's enforcement powers apply from 2 August 2026. Keep the first Union market placement date and evidence for each model version because it controls that transition.
Article 53(1)(a) requires providers to draw up and keep up-to-date technical documentation of the model, including training and testing process information and evaluation results, for provision to the AI Office and national competent authorities on request.
Use Annex XI as the minimum table of contents. The pack should show what the model is intended to do, the systems it can be integrated into, acceptable use policies, release and distribution details, architecture and parameter information, input and output modalities and formats, licence, development process, data provenance and curation, training/testing/validation data, computational resources, training time, and known or estimated energy consumption.
Article 53(1)(b) creates a downstream-facing documentation duty. Providers must draw up, keep up-to-date, and make available information and documentation to providers of AI systems that intend to integrate the GPAI model into their AI systems.
The downstream pack should be written for integration decisions. It should help downstream providers understand capabilities and limitations, comply with their own AI Act duties, and integrate the model with the technical means, input/output constraints, licence, acceptable use policy, and data provenance information listed in Annex XII.
Article 53(1)(c) requires a policy to comply with Union copyright law and related rights, including identification of and compliance with rights reservations under Article 4(3) of Directive (EU) 2019/790. The GPAI Code's Copyright Chapter operationalizes this through a maintained copyright policy, assigned responsibilities, crawler and rights-reservation controls, and measures to mitigate copyright-infringing outputs.
Article 53(1)(d) separately requires a sufficiently detailed public summary of training content using the AI Office template. The evidence pack should therefore contain both the internal copyright-policy evidence and the public summary evidence, with clear separation between private records and public-facing disclosures.
If the model is classified or designated as a GPAI model with systemic risk, Article 55 adds obligations on top of Articles 53 and 54. Keep these records in a separate systemic-risk annex so teams can see which controls apply only to systemic-risk models.
A model is presumed to have high-impact capabilities when the cumulative amount of computation used for training exceeds 10^25 floating-point operations. That presumption is not the only route: the Commission may designate a model as presenting systemic risk based on the Annex XIII criteria, and a provider that meets the compute threshold must notify the Commission without delay and within two weeks. Keep the compute method, assumptions, threshold date, notification, and any reasoned argument that the model does not present systemic risk.
The annex should cover model evaluation, documented adversarial testing, assessment and mitigation of Union-level systemic risks and their sources, serious-incident tracking and reporting, corrective measures, and adequate cybersecurity protection for the model and its physical infrastructure.
Close the pack only when every required section has an owner, source, update trigger, and evidence location. Separate authority-facing documentation, downstream-provider material, public summaries, and systemic-risk evidence instead of mixing all records into one policy document.
Do not claim Article 55 readiness unless the model has been assessed against the systemic-risk obligations and the evidence pack includes the extra testing, incident, mitigation, and cybersecurity records. Do not claim open-source exemptions without documenting the licence, public availability of parameters and architecture information, and whether the model presents systemic risk.
The Article 53(2) free and open-source exception is limited. When its conditions are met, it removes Article 53(1)(a) and (b) technical and downstream-documentation duties, but not the copyright policy or public training-content summary duties in Article 53(1)(c) and (d). Article 54(6) separately removes the authorised-representative duty for a qualifying free and open-source model. Neither exception applies to a GPAI model with systemic risk.
Sorena can help convert model, training-data, copyright, downstream-documentation, systemic-risk, incident, and cybersecurity records into a maintained EU AI Act evidence pack.
Ask questions tied to cited sources about GPAI provider obligations, model documentation, training summaries, copyright policy, and systemic-risk evidence.
Review your GPAI model scope, Article 53 evidence gaps, and Article 55 systemic-risk records with Sorena.
"serious incidents"
"scope of the obligations"
"public summary of training content"
"Transparency, Copyright, and Safety and Security"
"copyright policy"
"Safety and Security Chapter"
"downstream providers"
"providers of AI systems"
"policy to comply"
"general-purpose AI models with systemic risk"
"Articles 53 and 55"
"technical documentation of the model"
"Obligations for providers of general-purpose AI models"