GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-054 Safety and Security Model Report

Tier 3+AIGeneral-purpose model

Description

A safety and security model report exists for each general-purpose AI model designated as carrying systemic risk before it is placed on the market. The report describes the model and its behaviour, documents the systemic risk identification, analysis and mitigation carried out under the framework, the external evaluations and reports obtained, the reasons the systemic risk was found acceptable with the conditions under which that finding would stop holding, and how the model changes the systemic risk landscape. The report is updated when the framework's triggers fire and at the interval the applicable code of practice sets for the most capable models on the market, each update carries a changelog, the AI Office is given access by the time the model is placed on the market and within the period the code sets after each update, and a summarised version with the removals needed to protect mitigations and commercial information is published where the code requires it.

Rationale

The report is the artefact the AI Office reads; the framework (AIG-050) and the evaluations (AIG-051) are what it describes, so a report that restates them at length is worse than one that cites them and states the reasoning. The six-month refresh for the most capable models and the five-business-day access period are the Code's figures and belong in the evidence. Publication of a summary is required only where it is needed to assess or mitigate systemic risk, with the Code's exemption for models no more capable than one already on the market. The profile marks this control recommended rather than required because its only sources are Code measures and the Code is a voluntary route to demonstrating compliance (ADR-038, ADR-046 decision 4); a provider that does not adhere to the Code demonstrates Art.55 compliance another way and records how. Boundary with AIG-050 and AIG-051 as above. Boundary with AIG-047: the model documentation may be cited by the report and is not repeated in it. gpai-provider seat (ADR-031).

Applicability (9 profiles)

SaaS AI Providerstablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Enterprise AI Deployerstablenot-applicableout of scope

A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.

GPAI Model Providerstablerecommendedrole duty

The Safety and Security Model Report is a Code of Practice measure and the Code is a voluntary route to demonstrating Art.55 compliance (ADR-038, ADR-046 decision 4). Recommended for a provider of a model designated as carrying systemic risk; a provider that does not adhere to the Code records how it demonstrates Art.55 compliance instead.

High-Risk Provider (EU)stablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Public Body Deployer (EU)stablenot-applicableout of scope

A general-purpose model providers duty (gpai-model-provider, ADR-046). The deployer takes the model documentation and the published training summary the provider issues into its AIG-032 assessment.

Data Act Cloud Provider (EU)stablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

DORA ICT Provider (EU)stablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

HIPAA Business Associate (US)stablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

NIS2 Cloud Provider (EU)stablenot-applicableout of scope

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Framework Mappings (10)

COP-S-10Additional documentation and transparencypartial
COP-S-10.2Public transparencyfull
COP-S-7Safety and Security Model Reportsfull
COP-S-7.1Model description and behaviourfull
COP-S-7.2Reasons for proceedingfull
COP-S-7.3Documentation of systemic risk identification, analysis, and mitigationfull
COP-S-7.4External reportsfull
COP-S-7.5Material changes to the systemic risk landscapefull
COP-S-7.6Model Report updatesfull
COP-S-7.7Model Report notificationsfull

Evidence (1)

reportdocumentmanual

The safety and security model report for a designated model at its current version, with its changelog and the record of access given to the AI Office.

Example: Aurora-2 Safety and Security Model Report v2.3, 11 August 2026, changelog at annex A, AI Office access confirmed 13 August 2026.

Test: Verify: (1) the report exists with a version dated before the model's placement date, (2) it describes the model and its behaviour, the identification, analysis and mitigation carried out, the external evaluations obtained, the reasons for proceeding with the reversal conditions and the change to the systemic risk landscape, each either stated or cited to the framework, the determination or the evaluation report, (3) each update in the period follows a framework trigger or falls within the interval the code sets, and carries a changelog entry, (4) the access record shows the AI Office given access by placement and within the period the code sets after each update, (5) where a public summary was required, it is published with the removals recorded and justified.

Questions (2)

boolean

Does a safety and security model report exist for each designated model before it is placed on the market?

The report is the document delivered to the AI Office. The framework and the evaluation reports it describes are AIG-050 and AIG-051 and do not stand in for it.

multi

Which of the following does the report cover?

The model and its behaviourThe systemic risk identification, analysis and mitigation carried outExternal evaluations and reports obtainedThe reasons for proceeding and the conditions that would reverse themHow the model changes the systemic risk landscapeUpdates on triggers and at the code's interval, with a changelogAccess given to the AI Office by placement and after each updateA published summary where the code requires itNone of the above

Options follow the report's sections then its lifecycle. Cited content counts where the citation points to the framework, the determination or the evaluation report.