The AI Act’s GPAI Security Chapter Is a Weight Security Mandate
On 29 August 2026, Henna Virkkunen confirmed that the AI Office had sent formal requests for information to providers of general-purpose AI (GPAI) models. On 1 September the Commission confirmed it had written to more than thirty AI companies, and its spokesperson Thomas Regnier described two strands: one on safety and security, notably the most advanced models, and one on copyright and transparency. The first strand asked how providers secure their models against attack, whether independent external evaluators have assessed them, and how the models are monitored after release. The second went to providers that had not published training-data summaries and had not taken part in the AI Office’s informal compliance dialogues. More than thirty companies received a request; the Commission has not said how many received the security strand.
Article 91(4) requires the AI Office to state on the face of every such request that supplying incorrect, incomplete or misleading information exposes the provider to fines under Article 101, at up to 3 per cent of worldwide annual turnover or 15 million euro, whichever is higher.
Here is the sentence for your CISO. European law now requires frontier model providers to secure the model and its physical infrastructure, and the Commission-endorsed Code turns that into weight-level controls. The regulator has begun asking for the evidence, and an incomplete or misleading answer can expose a provider to a fine of up to 15 million euro or 3 per cent of worldwide annual turnover. If you procure frontier models, your supplier’s security posture has become a documented and enforceable matter for the first time.
What Article 55 requires
Chapter V applies to providers of general-purpose AI models. Article 51(2) presumes a model presents systemic risk when cumulative training compute exceeds 10^25 floating point operations. The Commission may change that threshold by delegated act and has not done so.
The presumption in Article 51(2) can be rebutted in both directions. A provider can submit a substantiated argument that its model does not present systemic risk despite exceeding the threshold, and the Commission can designate a model below the threshold on the basis of equivalent capability or impact.
Providers of systemic-risk models owe four obligations under Article 55(1):
- Evaluate the model using standardised protocols and tools reflecting the state of the art, including documented adversarial testing aimed at identifying and mitigating systemic risk.
- Assess and mitigate possible systemic risks at Union level, including the sources of those risks.
- Track, document and report serious incidents and possible corrective measures to the AI Office and, where relevant, to national competent authorities, without undue delay.
- Ensure an adequate level of cybersecurity protection for the general-purpose AI model with systemic risk and for the physical infrastructure of the model.
Article 55(1)(d) does not use the word weights. It creates a binding cybersecurity duty over the model and its physical infrastructure, and the Commission-endorsed Code is what turns that duty into protection of model parameters and the environments that store and serve them. The headline still holds, and the legal chain matters: statute creates the duty, Code specifies the controls.
What the Code of Practice turned that into
The General-Purpose AI Code of Practice, published on 10 July 2025, has three chapters. Transparency and Copyright apply to all GPAI providers. Safety and Security applies only to providers of models with systemic risk.
The Safety and Security chapter translates Article 55(1)(d) into Commitment 6, Security Mitigations, at Measures 6.1 and 6.2. Signatories commit to cybersecurity measures protecting against unauthorised access to, release of, or theft of a model with systemic risk. Those measures must align to a security goal the signatory defines, addressing foreseeable threat actors including insiders, and must stay in place until the model is either made publicly available or securely deleted. The commitment does not apply to a model whose capabilities are inferior to any model whose parameters are already publicly downloadable. Where a signatory does not use standard security measures, the alternative has to achieve equivalent mitigation objectives.
The third draft of the Code set a floor: security sufficient to meet at least the RAND SL3 security goal or equivalent, which RAND defined in a 2024 report as the level needed to protect weights against well-resourced non-state actors. The final version removed that floor. Signatories now define, justify and meet their own security goal, and RAND SL3 survives only as an optional reference point. Whether that reads as proportionality or as a weakening depends on what the AI Office accepts when the first answers arrive.
The Commission’s signatory list, last updated on 31 July 2026, names twenty-one full signatories including Amazon, Anthropic, Cohere, Google, IBM, Microsoft, Mistral AI, OpenAI and ServiceNow, alongside smaller European providers. xAI signed the Safety and Security chapter only, which means it must demonstrate compliance with the transparency and copyright obligations by alternative adequate means. Meta is absent from the list. Joel Kaplan, Meta’s Chief Global Affairs Officer, said in July 2025 that the Code introduced legal uncertainties for model developers and measures going beyond the scope of the AI Act. The Commission updates the list as signatures are confirmed, so any count needs its date.
Signing is voluntary and confers no immunity. The Commission and the AI Board have confirmed the Code as an adequate voluntary tool for demonstrating compliance, and Article 101 directs the Commission to take account of commitments made in codes of practice under Article 56 when fixing a fine.
Why weight security is the right frame
Model weights are the concentrated output of a training run that at the frontier commonly costs hundreds of millions of dollars. For a closed-weight model, every serving-layer control a provider relies on assumes nobody else holds them. An attacker who obtains the weights can perform unlimited white-box attacks offline. Further training at comparatively low cost can weaken or remove post-training safety behaviour. Every rate limit and monitoring control the provider built around its API stops applying.
Guardrails, abuse detection, rate limiting and refusal behaviour are properties of the serving system. Weight theft removes the model from that system. securing.ai/ has covered the attack path in model stealing, the query-based approximation of it in query attacks, and the distinction between open and closed weight release.
Most compliance summaries skip the words physical infrastructure in Article 55(1)(d). Data centre physical security, hardware supply chain integrity and the security posture of a third-party compute provider are all inside a regulatory obligation owed by the model provider. A frontier lab renting capacity now has a documented dependency on its cloud provider’s controls.
What the requests for information change
GPAI obligations applied from 2 August 2025, and for the next twelve months the Commission had no power to fine anyone for breaching them. The AI Office ran what its guidelines describe as a period of collaboration with providers adhering to the Code, treating incomplete implementation as good faith. Enforcement powers became exercisable on 2 August 2026 and the Commission used them within four weeks.
The requests demand evidence and are not findings of infringement. Their content still tells procurement teams what to ask for. The regulator asked for adversarial testing records, external evaluation reports and post-market monitoring evidence. Either a provider has those artefacts or it does not, and the answers will eventually inform Commission decisions.
Agence Europe reported on 2 September that the requests followed several incidents involving AI models over the summer. Various secondary accounts describe specific containment failures during evaluations. I could not corroborate any individual incident against a primary source and I am not repeating them here.
What a buyer should ask a model provider
Four questions produce answers that mean something, and all four map to obligations the provider already owes.
Ask whether the model is classified as a GPAI model with systemic risk. If it is, ask whether that classification follows from the 10^25 FLOP presumption or from a Commission designation. Presumption means the provider is inside Article 51(2) on its own training-compute numbers. Designation means the Commission put it there.
Ask whether the provider signed the Safety and Security chapter of the Code of Practice. If not, ask what it does instead. Meta’s refusal is public and is a legitimate procurement input rather than a disqualification.
Ask for customer-shareable evaluation summaries instead of the regulator-facing reports themselves. A frontier provider may be unable to hand over an external evaluator’s full report even under a non-disclosure agreement. What it can supply is scope and methodology, an independent assurance statement, evidence of remediation, and an account of what was withheld and why.
Ask where the weights are stored and who can access them, and which compute providers are inside the Article 55(1)(d) perimeter. Subcontracted infrastructure is the part providers describe least often and the part with the largest attack surface.
The compute threshold is a proxy for spending
Article 51(2) presumes systemic risk above 10^25 FLOP of training compute. Compute is a proxy for capability and the relationship between them keeps changing. Training efficiency improvements mean a model trained below the threshold in 2027 may exceed the capability of one trained above it in 2024. Distillation produces capable models from far less compute than the teacher required.
A capability-based threshold would match the risk more closely and nobody has proposed a workable definition of one. The Commission has a delegated power to amend the figure and has not used it. Any organisation relying on the systemic-risk classification as a security signal should treat it as a proxy for training expenditure and not for how dangerous a model is.
As the compute needed for frontier capability falls, more capable models will fall below the 10^25 FLOP threshold. The Act regulates the largest training runs. What a stolen set of weights lets an attacker do does not depend on what they cost to produce.
The other four provisions of the AI Act that touch a security function are covered in the EU AI Act for security teams.
In the early 2000s, running emerging-technology risk labs at CyberAgency, a defence client asked my team to break the AI systems they planned to put into weapons. We did. That is where my work on AI security started, two decades before the current wave of attention. I kept at it through risk labs at IBM, Accenture, PwC and KPMG. In 2016 I co-wrote a book on AI and leadership. My commercial work today is quantum, at Applied Quantum, which is why this site sells nothing.