---
title: "Systemic Risk (GPAI), Definition | MedTech Terms"
description: "Additional AI Act tier for GPAI models above a compute threshold or otherwise designated as posing systemic risk."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/ai-act-systemic-risk#term",
        "name": "Systemic Risk (GPAI)",
        "description": "Article 51 designates a GPAI model as posing systemic risk when it has high-impact capabilities, presumed where the cumulative amount of computation used for training exceeds 10^25 FLOPs, or when so designated by the Commission. Article 55 then requires model evaluation, adversarial testing, tracking and reporting of serious incidents, and adequate cybersecurity protections at the model layer.",
        "url": "https://medtechterms.com/terms/ai-act-systemic-risk",
        "termCode": "ai-act-systemic-risk",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/ai-act-systemic-risk#article",
        "headline": "Systemic Risk (GPAI)",
        "description": "Additional AI Act tier for GPAI models above a compute threshold or otherwise designated as posing systemic risk.",
        "url": "https://medtechterms.com/terms/ai-act-systemic-risk",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/ai-act-systemic-risk"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/ai-act-systemic-risk#term"
        },
        "articleSection": "Regulatory",
        "inLanguage": "en",
        "keywords": "Systemic Risk (GPAI), Regulatory, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-07-25",
        "dateModified": "2026-07-25",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Regulation (EU) 2024/1689, Articles 51 and 55",
            "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
            "publisher": {
              "@type": "Organization",
              "name": "EUR-Lex"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "RAPS Regulatory Focus",
            "url": "https://www.raps.org/news-and-articles/news-articles",
            "publisher": {
              "@type": "Organization",
              "name": "RAPS"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA - Medical Devices",
            "url": "https://www.fda.gov/medical-devices",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/ai-act-gpai#term",
            "name": "General-Purpose AI Model",
            "alternateName": "GPAI",
            "url": "https://medtechterms.com/terms/ai-act-gpai"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/ai-act-high-risk-system#term",
            "name": "High-Risk AI System (EU AI Act)",
            "url": "https://medtechterms.com/terms/ai-act-high-risk-system"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Regulatory",
            "item": "https://medtechterms.com/terms?cat=Regulatory"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Systemic Risk (GPAI)",
            "item": "https://medtechterms.com/terms/ai-act-systemic-risk"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  [Terms](/terms)
3.  [Regulatory](/terms?cat=Regulatory)
4.  Systemic Risk (GPAI)

[All terms](/terms)

Regulatory [Regulated Pathways](/ecosystems/regulated-pathways)[AI / ML in Devices](/ecosystems/ai-ml)[Quality System](/ecosystems/quality-system)

# Systemic Risk (GPAI)

Additional AI Act tier for GPAI models above a compute threshold or otherwise designated as posing systemic risk.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed July 25, 2026 

## Definition

Article 51 designates a  [GPAI](/terms/ai-act-gpai) model as posing systemic risk when it has high-impact capabilities, presumed where the cumulative amount of computation used for training exceeds 10^25 FLOPs, or when so designated by the Commission. Article 55 then requires model evaluation, adversarial testing, tracking and reporting of serious incidents, and adequate cybersecurity protections at the model layer. 

## What this means in practice

MedTech products rarely train models at this scale, but they frequently consume them. When a device relies on a designated systemic-risk  [GPAI](/terms/ai-act-gpai), the manufacturer should map how upstream incident reporting and evaluation flow into the device's own  [post-market surveillance](/terms/post-market-surveillance) and vigilance obligations. 

Common pitfalls

-   • Confusing systemic-risk designation (a property of the model) with high-risk status (a property of the AI system's use case). 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Regulatory

General-Purpose AI Model(GPAI) 

AI model trained on broad data at scale that displays significant generality and can be integrated into many downstream systems.





](/terms/ai-act-gpai)[

Regulatory

High-Risk AI System (EU AI Act)

AI systems captured by Article 6 of the EU AI Act because they are safety components of regulated products or listed in Annex III.





](/terms/ai-act-high-risk-system)

### More in Regulatory

· Same category 

[

Regulatory

510(k) Premarket Notification(510(k)) 

FDA submission demonstrating a device is substantially equivalent to a legally marketed predicate.





](/terms/510k)[

Regulatory

510(k) Summary vs 510(k) Statement

Two alternative disclosure mechanisms in a 510(k) submission, a Summary is public on FDA's website; a Statement promises to share Safety & Effectiveness info on request.





](/terms/510k-summary-vs-statement)[

Regulatory

513(g) Request for Information(513(g)) 

Formal mechanism to ask FDA whether a product is a device and, if so, its likely classification.





](/terms/513g)[

Regulatory

Abbreviated 510(k)

510(k) variant that relies on FDA guidance, special controls, or recognized consensus standards.





](/terms/abbreviated-510k)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (3)

-   [Regulated Pathways](/ecosystems/regulated-pathways)
-   [AI / ML in Devices](/ecosystems/ai-ml)
-   [Quality System](/ecosystems/quality-system)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

EUR-Lex· 1 RAPS· 1 FDA· 1 

1.  [1 
    
    Regulation (EU) 2024/1689, Articles 51 and 55
    
    Verified 
    
    EUR-Lex eur-lex.europa.eu 
    
    
    
    ](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)
2.  [2 
    
    RAPS Regulatory Focus
    
    Verified 
    
    RAPS raps.org 
    
    
    
    ](https://www.raps.org/news-and-articles/news-articles)
3.  [3 
    
    FDA - Medical Devices
    
    Verified 
    
    FDA fda.gov 
    
    
    
    ](https://www.fda.gov/medical-devices)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Navigating an FDA or EU MDR submission?

Blue Goat Cyber supports the cybersecurity content of premarket submissions, from threat models to the 524B narrative.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Regulatory

Sources

3

Updated

7/25/2026

[Compare with another term](/compare?a=ai-act-systemic-risk)

Learn in 60 seconds

Card Lesson Quiz

Additional AI Act tier for GPAI models above a compute threshold or otherwise designated as posing systemic risk.

-   · MedTech products rarely train models at this scale, but they frequently consume them. 
-   · Article 55 then requires model evaluation, adversarial testing, tracking and reporting of serious incidents, and adequate cybersecurity protections at the model layer. 

Remember this

Watch out: Confusing systemic-risk designation (a property of the model) with high-risk status (a property of the AI system's use case).

Related terms

-   [General-Purpose AI Model(GPAI) ](/terms/ai-act-gpai)
-   [High-Risk AI System (EU AI Act) ](/terms/ai-act-high-risk-system)

You may also need

Auto-suggested from Regulatory and shared keywords.

-   [MLOps for Medical Devices(MLOps) ](/terms/mlops-medical-device)
-   [AI Act Technical Documentation (Annex IV) ](/terms/ai-act-technical-documentation)
-   [Notified Body Scrutiny (IVDR Class D) ](/terms/ivdr-notified-body-scrutiny)
-   [AI Act Serious Incident Reporting ](/terms/ai-act-serious-incident-reporting)
-   [Genetic Testing Requirements (IVDR Article 4) ](/terms/ivdr-genetic-testing)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)

[All Regulatory terms](/terms?cat=Regulatory)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    MedTech Truths 
    
    Common misconceptions about medical device development - debunked.
    
    ](https://mdcmisconceptions.com)
-   [
    
    MedTech Launchpad 
    
    MedTech funding rounds, accelerators, and launch resources.
    
    ](https://medtechlaunchguide.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)