MedTech Terms
    The authoritative reference
    All terms

    Systemic Risk (GPAI)

    Additional AI Act tier for GPAI models above a compute threshold or otherwise designated as posing systemic risk.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed July 25, 2026

    Definition

    Article 51 designates a GPAI model as posing systemic risk when it has high-impact capabilities, presumed where the cumulative amount of computation used for training exceeds 10^25 FLOPs, or when so designated by the Commission. Article 55 then requires model evaluation, adversarial testing, tracking and reporting of serious incidents, and adequate cybersecurity protections at the model layer.

    What this means in practice

    MedTech products rarely train models at this scale, but they frequently consume them. When a device relies on a designated systemic-risk GPAI, the manufacturer should map how upstream incident reporting and evaluation flow into the device's own post-market surveillance and vigilance obligations.
    Common pitfalls
    • Confusing systemic-risk designation (a property of the model) with high-risk status (a property of the AI system's use case).
    Grouped by theme
    Cited by

    Where this term appears across MedTech Terms.

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    EUR-Lex·1RAPS·1FDA·1
    1. 1
      Regulation (EU) 2024/1689, Articles 51 and 55
      Verified
      EUR-Lexeur-lex.europa.eu
    2. 2
      RAPS Regulatory Focus
      Verified
      RAPSraps.org
    3. 3
      FDA - Medical Devices
      Verified
      FDAfda.gov

    Inline markers like [1] jump to the matching reference above.