The classic trap
Annex XIII sets the criteria used by the European Commission, through the EU AI Office, to designate a general-purpose AI model as carrying systemic risk (Article 51). The trap is not reserved for OpenAI or Anthropic-scale players: a European provider exceeding 10,000 registered business users in the Union, or combining advanced multimodality with agentic autonomy, can tip over without anticipation. Consequence: reinforced obligations (adversarial evaluation, red-teaming, incident reporting, cybersecurity), with fines up to EUR 15 million or 3% of worldwide turnover under Article 101 of the AI Act.
The 7 criteria and their operational reading
- Number of parameters: indicative threshold of 10^25 cumulative training FLOPs (Article 51(2)) triggers presumption. Above 100 billion parameters, heightened scrutiny.
- Dataset quality and size (in tokens): trace provenance, filtering and rights of corpora, as authorities cross-check this with copyright compliance (Article 53).
- Training compute: maintain a log of FLOPs, estimated cost, GPU-time and energy consumption. Must be provided on AI Office request.
- I/O modalities: text-to-text, text-to-image, multimodal, biological sequences (CBRN risk). Each modality has its own state-of-the-art threshold.
- Benchmarks and capabilities: number of zero-shot tasks, adaptability to learn new tasks, level of autonomy (agents), accessible tools (code execution, web browsing, APIs).
- Internal market reach: objective threshold of 10,000 registered business users established in the Union. Counter to monitor in real time.
- Number of registered end-users: societal impact indicator, cross-checked with EU geographic coverage.
The key defensive argument before the EU AI Office is evidence traceability: without a detailed registry of FLOPs, datasets and usage metrics, impossible to contest a systemic risk presumption or to demonstrate the contrary (Article 52).
How Luxgap automates this risk
Our Luxgap GPAI Systemic Threshold Monitor turns the seven Annex XIII criteria into a real-time dashboard that fires an alert as soon as a presumption threshold is approached, before the EU AI Office detects it on its side. The tool natively connects to your ML stack (MLflow, Weights and Biases, Hugging Face Hub, AWS SageMaker, Azure ML, Vertex AI), your distribution platforms (Kong API gateway, AWS API Gateway, Stripe for invoiced business accounts) and your GPU infrastructure (NVIDIA DCGM, Slurm, Kubernetes) to continuously compute cumulative FLOPs, training tokens, active parameters and EU business user population.
- Continuously computes cumulative training FLOPs and alerts upon crossing 70% of the 10^25 threshold defined in Article 51(2), with projected date of reach.
- Automatically counts registered business users established in the Union via IP geolocation, VAT number and SIRET/RCS, and triggers an AI Office notification workflow when approaching 10,000.
- Maps each model's active I/O modalities (text, image, audio, video, biological sequences) and benchmarks internal scores (MMLU, HumanEval, GPQA, BIG-bench) against state-of-the-art thresholds published by the AI Office.
- Traces every dataset's provenance (license, copyright, TDM opt-out under Article 4 of Directive 2019/790) and generates the detailed training content summary required by Article 53(1)(d).
- Evaluates agentic autonomy level (tool access, code execution, web browsing, memory persistence) against an AI Office-aligned grid and flags high-impact capabilities.
- Produces a cryptographically sealed timestamped PDF report, opposable to the EU AI Office during an Article 52 procedure, demonstrating compliance status at the date of inspection.
Available as a complement to a Luxgap CISO or AI Compliance Officer mandate or as a dedicated SaaS brick depending on your perimeter. Request your demonstration and our teams prepare a free 48h scan of your ML stack to measure your distance to Annex XIII thresholds before any engagement.