Chronicle/Policy & standards

EU GPAI Code of Practice Safety and Security chapter lists cyber offence as a specified systemic risk

PolicyFrameworkSignificance assistant-drafted

The European Commission received the final General-Purpose AI Code of Practice, whose Safety and Security chapter applies to providers of models with systemic risk under Article 55 of the AI Act. The chapter treats cyber offence as one of four specified systemic risks, requires a security goal covering non-state external and insider threats, and sets serious incident reporting deadlines that include five days for serious cybersecurity breaches.

Why it matters

It is an operational EU text that commits signatory frontier providers to assess automated vulnerability discovery and exploit generation as a systemic risk.

Key facts

As stated in the sources, with where to find them.

  • Specified systemic risk 'Cyber offence': risks from enabling large-scale sophisticated cyber-attacks including on critical infrastructure, e.g. through automated vulnerability discovery, exploit generation, operational use and attack scaling.Appendix 1.4 Specified systemic risks
  • Serious incident reporting: disruption of critical infrastructure within 2 days; serious cybersecurity breach, including (self-)exfiltration of model weights and cyberattacks, within 5 days; death within 10 days; other serious harms within 15 days.Commitment 9, Measure 9.3
  • Measure 6.1 requires a Security Goal naming threat actors, including non-state external threats and insider threats; the rationale may reference the RAND Securing AI Model Weights report.Commitment 6, Measures 6.1-6.2
  • Measure 5.1 lists techniques to enable safe ecosystems of AI agents, such as model identification, specialised communication protocols or incident monitoring tools, as possible safety mitigations.Commitment 5, Measure 5.1

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records