RatedWithAI

RatedWithAI

Accessibility scanner

EU AI ActJuly 30, 2026

EU AI Act Open-Source Exemption 2026: Why Fine-Tuning Llama Doesn't Get You Out

"We use open-source models, so the AI Act doesn't apply to us" is the most common thing engineering teams get wrong about European AI regulation. The exemption is real, but it is scoped to the act of releasing openly — not to the act of building a paid product on top of someone else's open weights. In most commercial setups, the carve-out is already gone before the first customer signs up.

Monetised = Out
Charging for access cancels the free-and-open framing
High-Risk = Out
Use case overrides licence in every high-risk area
Fine-Tune = Provider
Rebranding open weights makes you provider of record

What the Exemption Is Actually For

The open-source relief in the AI Act exists to protect a specific activity: publishing research artefacts, model weights, tools, and components under a licence that lets anyone use, study, modify, and redistribute them freely. The policy goal is that a university lab or an independent maintainer should not need a conformity-assessment budget to put a model on a public repository.

Notice what that goal does not include. It says nothing about a company that pulls those weights down, fine-tunes them on proprietary data, wraps them in an API, and sells seats. That company is not the beneficiary the carve-out was drafted for, and the conditions attached to the exemption are precisely the ones that describe its business model.

Four Conditions That Cancel the Carve-Out

Monetisation in any form

A paid tier, a metered API, a bundled SaaS plan, or an exchange of personal data for access beyond interoperability and security purposes all move the release out of the free-and-open category. The licence text on the weights is irrelevant once the distribution is commercial.

High-risk classification by use

If the deployed system is used for recruitment and worker management, education and exam scoring, creditworthiness, essential public services, biometrics, or the other listed high-risk areas, the full high-risk regime applies. The Act classifies by what the system decides about people, not by how the code was licensed.

Transparency-triggering interactions

Systems that interact with people, generate or manipulate synthetic audio, image, video, or text, or infer emotion carry disclosure and machine-readable-marking duties. An open licence does not relieve you of telling a user they are talking to a machine or labelling generated media.

Prohibited practices

Social scoring, certain emotion inference in workplaces and schools, untargeted scraping for facial recognition databases, and manipulative techniques exploiting vulnerabilities are banned outright. There is no open-source route into a prohibited practice.

The Fine-Tuning Trap: How Deployers Become Providers

The most expensive misreading is not about the exemption at all — it is about role. Teams assume that because they did not train a foundation model, they are downstream users with light obligations. But provider status attaches to whoever puts an AI system or general-purpose model on the EU market under their own name or trademark, and to whoever substantially modifies a system or repurposes it for a high-risk use.

Fine-tune an open-weight model on your customer data, give it a product name, sell it to European businesses, and you have satisfied that description. The upstream lab that released the base weights has not taken on your product's obligations, and it cannot: it has no visibility into your training data, your evaluation results, your intended purpose, or your customers. The documentation and risk-management duties land where the knowledge is, which is with you.

Role test: answer these before claiming deployer status

  • Does the product carry your name or trademark when a European customer buys it?
  • Did you fine-tune, distil, retrain, or materially alter the model's behaviour?
  • Did you define an intended purpose the base model was not released for?
  • Would a customer contact you, not the upstream lab, about an incorrect or harmful output?

Any yes is a strong signal you are the provider for that system, whatever the base model's licence says.

What Survives Even When the Relief Applies

For general-purpose models released openly, the relief is partial rather than total. The duties that tend to persist are the copyright-facing ones: maintaining a policy to comply with EU copyright law including honouring machine-readable reservations of rights from text and data mining, and publishing a sufficiently detailed summary of the content used for training. Models judged to present systemic risk are outside the relief altogether and pick up evaluation, incident-reporting, and cybersecurity duties on top. The honest way to read the exemption is as a reduction in paperwork for genuine open releases, not as a jurisdictional escape hatch.

Compliance Checklist for Open-Weight Deployments

1. Fix Your Role in Writing
  • Document, per system, whether you are provider, deployer, importer, or distributor — and why
  • Re-run the determination after any fine-tune, prompt-architecture change, or new intended purpose
  • Record the base model, version, licence, and the date you pulled the weights
2. Classify by Use, Not by Licence
  • Map each deployment against the high-risk areas: employment, education, credit, essential services, biometrics
  • Flag every user-facing surface that triggers chatbot disclosure or synthetic-media marking
  • Confirm no deployment drifts toward a prohibited practice such as workplace emotion inference
3. Build the Evidence the Upstream Lab Cannot Give You
  • Keep evaluation results for your fine-tuned checkpoints, not just the base model's published benchmarks
  • Retain logs sufficient to reconstruct a specific output, and define a retention period
  • Write the intended-purpose and known-limitations statements your customers will rely on
4. Handle the Copyright Layer
  • Maintain a copyright policy covering rights reservations for text and data mining
  • Prepare a training-content summary at the level of detail regulators expect, including your own fine-tuning data
  • Check that the base licence actually permits your commercial use and any acceptable-use riders attached to it

Find the compliance gaps in your AI product

RatedWithAI scans the surfaces regulators and claimants actually look at first — disclosure notices, accessible interaction paths, and the flows where an automated decision reaches a real person. Start with a free scan of your product.

Scan Your Product for Free →

Frequently Asked Questions

Are open weights the same thing as open source for AI Act purposes?

Not automatically. Many popular releases ship weights under a bespoke community licence with acceptable-use policies, field-of-use limits, or user-count thresholds. A licence that restricts who may use the model or for what purpose is doing something a free and open-source licence does not do, which weakens any claim to the carve-out. Read the actual licence rather than the launch-post adjective.

We are a US company with no EU entity. Does any of this reach us?

The Act follows the market, not the incorporation certificate. If your system is placed on the EU market, or if its output is used in the EU, you can be in scope, and a provider established outside the Union placing a high-risk system on the EU market is expected to designate an authorised representative there. Having no European subsidiary removes a convenience, not the obligation.

Does running the model through an inference host change who the provider is?

Generally no. The hosting provider supplies compute; you supply the model choice, the fine-tune, the system prompt, the guardrails, and the intended purpose. Those are the elements the obligations attach to. Cloud contracts can allocate cost and add security commitments, but they do not transfer provider status for the product you sell.

How does this interact with the GDPR obligations we already have?

They stack rather than substitute. The GDPR governs the personal data flowing through the system — lawful basis, minimisation, data-subject rights, and automated-decision safeguards. The AI Act governs the system itself — classification, documentation, human oversight, and transparency. A completed data protection impact assessment is useful input to an AI Act risk-management file, but it is not a substitute for one.

Is there any real advantage to choosing open models for compliance?

Yes, but it is evidentiary rather than exemptive. Open weights let you inspect the architecture, run your own evaluations, host inside your own boundary, and keep logs you fully control — all of which make the documentation and oversight duties easier to satisfy honestly. That is a better argument for open models than a carve-out that mostly will not apply to you.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.