Skip to main content
European Commission logo
AI Act Service Desk

AI Act Explorer

Recitals
Chapter I: General Provisions
Chapter II: Prohibited AI Practices
Chapter III: High-Risk AI Systems

Section 1: Classification of AI Systems as High-Risk

Section 2: Requirements for High-Risk AI Systems

Section 3: Obligations of Providers and Deployers of High-Risk AI Systems and Other Parties

Section 4: Notifying Authorities and Notified Bodies

Section 5: Standards, Conformity Assessment, Certificates, Registration

Chapter IV: Transparency Obligations for Providers and Deployers of Certain AI Systems
Chapter V: General-Purpose AI Models
Chapter VI: Measures in Support of Innovation
Chapter VII: Governance
Chapter VIII: EU Database for High-Risk AI Systems
Chapter IX: Post-Market Monitoring, Information Sharing and Market Surveillance

Section 1: Post-Market Monitoring

Section 2: Sharing of Information on Serious Incidents

Section 3: Enforcement

Section 4: Remedies

Section 5: Supervision, Investigation, Enforcement and Monitoring in Respect of Providers of General-Purpose AI Models

Chapter X: Codes of Conduct and Guidelines
Chapter XI: Delegation of Power and Committee Procedure
Chapter XII: Penalties
Chapter XIII: Final Provisions
Annexes

Recital 115

Providers of general-purpose AI models with systemic risks should assess and mitigate possible systemic risks. If, despite efforts to identify and prevent risks related to a general-purpose AI model that may present systemic risks, the development or use of the model causes a serious incident, the general-purpose AI model provider should without undue delay keep track of the incident and report any relevant information and possible corrective measures to the Commission and national competent authorities. Furthermore, providers should ensure an adequate level of cybersecurity protection for the model and its physical infrastructure, if appropriate, along the entire model lifecycle. Cybersecurity protection related to systemic risks associated with malicious use or attacks should duly consider accidental model leakage, unauthorised releases, circumvention of safety measures, and defence against cyberattacks, unauthorised access or model theft. That protection could be facilitated by securing model weights, algorithms, servers, and data sets, such as through operational security measures for information security, specific cybersecurity policies, adequate technical and established solutions, and cyber and physical access controls, appropriate to the relevant circumstances and the risks involved.

This Recital relates to