Executive Summary
The rapid growth of AI has pushed the European Union (EU) to regulate risks posed by General Purpose Artificial Intelligence (GPAI) models. Under the EU AI Act, a GPAI model can be classified as systemic risk either through ‘high-impact capabilities’ under Article 51(1), with Article 51(2) creating a rebuttable presumption above 10^25 FLOPs, or through Commission designation of sub-threshold models based on capability and impact. However, DeepSeek V3 and R1 show that training compute may be an insufficient proxy for capability, as efficiency, distillation and adaptive-compute techniques can deliver comparable performance at lower compute and cost.
Introduction
The implementation of the EU AI Act reveals a great effort in technology governance. Nevertheless, a systemic-risk framework that gives significant weight to cumulative training compute (European Union, 2024) may struggle with newer models designed to maximise efficiency while reducing training time and cost (Hooker, 2024). DeepSeek’s R1 and V3 illustrate this strategy, combining architectural, training-efficiency and post-training techniques to reach comparable capability at lower cost.
Analysis
The main challenge concerns how the AI Act defines systemic risk. Article 51(1)(a) classifies GPAI with ‘high-impact’ capabilities as systemic risk, while Article 51(2) creates a rebuttable presumption above 10^25 FLOPs (European Union, 2024). However, DeepSeek-V3 achieved a performance similar to models like GPT-4o, but with a fraction of the cost (Hernández-Orallo and Ó Héigeartaigh, 2025). Article 3(65) links systemic risk to GPAI with ‘high-impact capabilities’, which Article 3(64) defines as capabilities that match or exceed those of the most advanced models (European Union, 2024). This generates an effect known as “moving target”, in which as newer and bigger models are released, older models might outlive their “systemic risk” classification while their risk remains unchanged (Hacker, Edwards and Kasirzadeh, 2026). However, the AI Act prevents automatic deregulation, unless the provider submits a request for reassessment and the Commission accepts it (European Union, 2024).
However, Article 51(1)(b) and Annex XIII also allow the Commission to designate models based on capability and impact. As a result, certain models could be overlooked unless the Commission designates them ex officio or following a qualified alert from the scientific panel (European Union, 2024; Heim and Koessler, 2024).
The second challenge the EU has to face is what lower-precision formats such as FP8 can imply. DeepSeek’s V3 model used FP8 mixed-precision training in almost the entire “body” of the model (DeepSeek, 2024). This reduced memory and computational requirements, allowing the company to reach comparable capability to top-tier ones but with a fraction of the cost (Heim and Koessler, 2024).
At the same time, DeepSeek V3 uses a Mixture of Experts (MoE) architecture, in which from the 671 billion parameters, only 37 billion are activated per token (DeepSeek, 2024). While this doesn’t determine the Act´s FLOP count, it means that the model requires less inference compute in comparison to other similarly sized architectures. The effect on training compute is less direct and depends on the sparsity level and the balance between experts. Nonetheless, this weakens the relationship between total model size and compute. These characteristics can be considered under the Annex XIII designation criteria (European Union, 2024).
DeepSeek also uses distillation techniques. In this case DeepSeek’s R1 reasoning data was used to improve smaller models like Qwen or Llama (DeepSeek, 2024). The use of this method is not unregulated since Recital 111 from the AI Act defines cumulative training compute broadly “ the activities and methods that are intended to enhance capabilities of the model prior to deployment” meaning distillation may fall within it (European Union, 2024).
However, DeepSeek-V3 and R1 are Open Source (OS) models, meaning they are free to use and modify. This is relevant because under Article 53 and 54 of the Act (Braun and Benizri, 2025), OS models are exempt from certain obligations, unless they cross the 10^25 threshold. This establishes a presumption of high-impact capabilities that triggers a systemic risk classification, provided it is not successfully rebutted. Alternatively, models may be designated directly by the Commission as systemic risks based on their overall impact and capabilities, a status that DeepSeek currently does not hold. At the same time, once an OS model is released, it spreads across torrents, mirrors and platforms like Hugging Face and GitHub, many with an unknown link-back to a responsible provider (De Gregorio, 2025; Rios and Brito, 2025).
Policy recommendations
- Periodic audit: Articles 91 and 92 allow the Commission to request information and the AI Office to evaluate GPAI models in certain circumstances. Article 92 of the AI Act gives the AI Office power to conduct model evaluations, and the Commission, through previous requests, to access a GPAI once Article 91´s information proves to be insufficient, or if a model poses systemic risk. Article 92(5) places the obligation to supply access in order to perform an evaluation to the provider or its representative. However, Article 54(6) exempts OS GPAI from appointing an EU representative unless the model has a systemic risk. Instead of waiting for an OS model to reach systemic risk, the EU should expand the existing framework by requiring the AI Office to hold periodic compute-verification and capability audits for OS models nearing the threshold or demonstrating frontier-level capabilities .
- Control over chokepoints: repository platforms like Hugging Face and GitHub facilitate the distribution of OS models, however, the AI Act does not currently impose a specific GPAI documentation-verification duty on repository platforms. Uploading a model to a repository does not transfer provider status to the platform, so the provider remains responsible for Annex XI documentation, leaving a gap between documentation and public access. The EU should close the gap by giving them the status of “documentation checkpoints” and requiring them to verify whether a GPAI model includes the required documentation and flag models that do not. As these platforms don’t necessarily have to know what technical documentation is required, the AI Office should provide guidance specifying those requirements (Rios and Brito, 2025).
References
Braun, M. and Benizri, I. (2025). “European Commission Issues Guidelines for Providers of General Purpose AI Models.” WilmerHale. Available at: European Commission Issues Guidelines for Providers of General-Purpose AI Models
DeepSeek-AI (2024). DeepSeek-v3 Techincal Report. Technical Report. Hangzhou: DeepSeek-AI. Avaliable at: [2412.19437] DeepSeek-V3 Technical Report
De Gregorio, A. (2025). Mitigating Cyber Risk in the Age of Open-Weight LLMs: Policy Gaps and Technical Realities.” Arxiv. Available at: Mitigating Cyber Risk in the Age of Open-Weight LLMs: Policy Gaps and Technical Realities
European Union (2022). Regulation- EU- 2022/2065- EN- EUR-Lex. Europe.eu. Available at: EUR-Lex – Official Journal of the European Union
European Union (2024). Regulation – EU – 2024/1689 – EN – EUR-Lex. Europa.eu. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
Hacker, P., Edwards, L and Kasirzadeh, A. (2026). “AI, Digital Platforms and the New Systemic Risk.” Arxiv. Available at: [2509.17878] AI, Digital Platforms, and the New Systemic Risk
Heim, L. and Koessler, L. (2024). “Training compute thresholds: Features and Functions in AI Regulation.” Arxiv. Available at: 2405.10799
Hernández-Orallo, J. and Ó Héigeartaigh, S. (2025). “Implications of DeepSeek V3 and R1 for the EU Code of Practice”, Leverhulme center for the future of intelligence, University of Cambridge. Available at: Implications of DeepSeek V3 and R1 for the EU Code of Practice – LCFI
Hooker, S. (2024). “On the Limitations of Compute Thresholds as a Governance Strategy.”Arxiv. Available at: [2407.05694] On the Limitations of Compute Thresholds as a Governance Strategy
Ríos, F. and Brito, E. (2026). “Why we have six months to regulate the AI that Europe isn’t building?” CEPS. Available at: Why we have six months to regulate the AI that Europe isn’t building – CEPS
