EU AI Act Article 55(1)(d) - Cybersecurity of systemic-risk GPAI models and their physical infrastructure
Systemic risk GPAI providers must implement adequate cybersecurity measures protecting both the model itself and the physical infrastructure on which it runs
Where this comes from
Provision: Article 55(1)(d) - Cybersecurity of systemic-risk GPAI models and their physical infrastructure
Instrument: EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
Citation: Article 55(1)(d), Regulation (EU) 2024/1689
Text version: Regulation (EU) 2024/1689, consolidated 27 July 2026; original OJ L 12 July 2024 and amendment (EU) 2026/1744
Checked against the source: 6 September 2026
Who it applies to
GPAI model provider in scope (Art. 2, Art. 3(63)) — all of these:
- Project involves providing a general-purpose AI model (GPAI)
- GPAI assessed Union model scope: YES
- GPAI assessed Article 51 classification: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assess adequacy of cybersecurity protection for both the model and its physical infrastructure under Article 55(1)(d)
- Record risk-appropriate controls, effectiveness evidence, gaps and remediation
- Justify selected frameworks, independent tests, two-person export controls and cadence as implementation measures
- Record the model-provider scope, relevant model version and Article 111(3) placement-date transition before an enforcement conclusion
- Coverage includes physical infrastructure as well as model security
Evidence an auditor expects
- Technical controlTechnical audit
Cybersecurity for the systemic-risk model and physical infrastructure (Article 55(1)(d))
Provide risk-based control and effectiveness evidence for the model and its physical infrastructure. Any chosen framework, encryption architecture, export control or testing cadence is an implementation measure to justify; the article does not prescribe one named framework or annual certification.
- Test resultsThird-party auditRecommended
Optional independent assessment of the model supply chain
Where selected for the model risk profile, preserve independent security-test scope, methods, findings and remediation. This is recommended supporting evidence rather than an Article 55 requirement for annual external certification.
Questions people ask
- Does EU AI Act Article 55(1)(d) - Cybersecurity of systemic-risk GPAI models and t… apply to my service?
- It applies when Project involves providing a general-purpose AI model (GPAI); GPAI assessed Union model scope: YES; GPAI assessed Article 51 classification: YES.
- When does this become enforceable?
- EU AI Act Article 55(1)(d) - Cybersecurity of systemic-risk GPAI models and t… is enforceable from 2 August 2025. Its current status is: in force.
- What evidence does an auditor expect?
- Cybersecurity for the systemic-risk model and physical infrastructure (Article 55(1)(d)); Optional independent assessment of the model supply chain.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.