AIG-050 Systemic Risk Framework and Acceptance Determination
Description
For each general-purpose AI model designated as carrying systemic risk, a safety and security framework exists that describes the processes and measures for assessing and mitigating systemic risk across the model's lifecycle. The framework identifies the systemic risks and the scenarios by which each could materialise, states the methods by which each is modelled and its probability and severity estimated, defines acceptance criteria as measurable capability tiers of which at least one the model has not reached, applied with a safety margin, states the trigger points at which further evaluation runs, and allocates responsibility and resources for each risk to named roles. A recorded determination exists before the model is placed on the market and after each trigger, stating whether the systemic risk is acceptable, the reasons and the conditions under which the determination would no longer hold. The framework and each change to it are confirmed by the accountable owner and notified to the AI Office within the periods the applicable code of practice sets.
Rationale
The framework is the document the Code of Practice calls the Safety and Security Framework and the determination is what Commitment 4 calls the acceptance determination. The capability-tier form of the acceptance criteria is what separates this from a risk register: a tier is a threshold on what the model can do, measured by the evaluations AIG-051 runs, and the determination is whether the model sits below the tier that would make the risk unacceptable, with a margin for capability gained after assessment, under-elicitation in testing and circumvented mitigations. The conditions that would reverse the determination are the part most often left out and the part an authority reads first. Notification periods to the AI Office, four weeks after the Art.52(1) notification and two weeks before placement for the confirmed framework, are the Code's and belong in the evidence rather than the text. Boundary with AIG-005: that control governs risk to the users and subjects of a system; this one governs risk at Union level from a designated model. Boundary with AIG-054: that control is the report to the AI Office about a model; this one is the framework the report describes. gpai-provider seat (ADR-031).
Applicability (9 profiles)
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
Condition: ai_risk_class in gpai-systemic
Art.55(1)(b) binds the provider of a model designated as carrying systemic risk.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Framework Mappings (20)
| EU-AI-Art.55.2 | Systemic Risk Obligations — Systemic Risk Assessment and Mitigation | full |
| COP-S-1 | Safety and Security Framework | full |
| COP-S-1.1 | Creating the Framework | full |
| COP-S-1.2 | Implementing the Framework | partial |
| COP-S-1.3 | Updating the Framework | full |
| COP-S-1.4 | Framework notifications | full |
| COP-S-2 | Systemic risk identification | full |
| COP-S-2.1 | Systemic risk identification process | full |
| COP-S-2.2 | Systemic risk scenarios | full |
| COP-S-3 | Systemic risk analysis | partial |
| COP-S-3.1 | Model-independent information | full |
| COP-S-3.3 | Systemic risk modelling | full |
| COP-S-3.4 | Systemic risk estimation | full |
| COP-S-4 | Systemic risk acceptance determination | full |
| COP-S-4.1 | Systemic risk acceptance criteria and acceptance determination | full |
| COP-S-4.2 | Proceeding or not proceeding based on systemic risk acceptance determination | full |
| COP-S-8 | Systemic risk responsibility allocation | full |
| COP-S-8.1 | Definition of clear responsibilities | full |
| COP-S-8.2 | Allocation of appropriate resources | full |
| COP-S-8.3 | Promotion of a healthy risk culture | informative |
Evidence (2)
The safety and security framework for a designated model, confirmed by its accountable owner, with its notification record to the AI Office.
Example: Aurora-2 Safety and Security Framework v3, confirmed by the Chief Scientist on 4 June 2026, notified to the AI Office on 6 June 2026.
Test: Verify: (1) the framework names the identified systemic risks and a scenario for each, (2) it states the modelling and estimation method for each risk, (3) each risk carries acceptance criteria stated as measurable capability tiers with at least one tier the model has not reached and a stated safety margin, (4) it states the trigger points for further evaluation, (5) each risk carries a named role and an allocated resource, (6) the confirmation by the accountable owner is dated and the notification to the AI Office falls inside the period the code sets, for the framework and for each change in the period.
The acceptance determination record for a release or a trigger, with its reasons, the evaluation results it rests on and the conditions that would reverse it.
Example: Acceptance determination AD-2026-04 for Aurora-2 v2.3, signed 11 August 2026, resting on evaluation report EV-2026-09.
Test: Verify: (1) a determination exists for the release before its placement date and for each trigger fired in the period, (2) it states for each risk which tier the model sits in against the evaluation results it cites, (3) it applies the stated margin rather than the raw result, (4) it states the reasons for proceeding and the conditions under which the determination would no longer hold, (5) a determination that found risk unacceptable shows the mitigation and the re-determination that followed, (6) the signatory is the accountable owner the framework names.
Questions (3)
Does a safety and security framework exist for each general-purpose model designated as carrying systemic risk?
Answer for models the Commission has designated or that meet the designation threshold. A general AI risk process covering the systems built on the model is AIG-005, not this framework.
Which of the following does the framework state?
Options follow the order of the framework's contents. The capability-tier form of the criteria is the item that separates a framework from a risk register.
When is the acceptance determination recorded?
Options run from the fullest practice to none. A determination without the conditions that would reverse it is the second option even when it is repeated at triggers.