What the EU AI Act Requires of Open-Weight Models
- Authority
- European Parliament and Council
- Rule type
- regulation
- Jurisdiction scope
- EU
- Effective date
- Aug 2, 2025
- Source text
- Read primary rule text ↗
Open-source exemption waives only some GPAI documentation duties; copyright policy, training summary, and systemic-risk obligations remain.
Dated 3 August 2026, UTC. This is a legal-risk briefing, not legal advice. It focuses on EU AI Act obligations for open-weight general-purpose AI models, fine-tuners, legal-tech vendors, law firms, and in-house legal teams with EU exposure. Status note: the Digital Omnibus material used here describes a May 2026 provisional agreement, with formal adoption expected before 2 August 2026; because that expected window has now passed, any obligation table used for live deployment should be checked against the enacted text rather than copied from the provisional summary.

The practical question behind open-weight AI model regulation and legal risk is not whether the model feels open. It is whether the EU AI Act treats that release as falling within a particular exemption, whether the model reaches the systemic-risk tier, and whether a downstream team has changed the model enough to become a provider in its own right.
That distinction matters at procurement speed. A legal-tech team may be offered downloadable weights, permissive hosting rights, and the ability to fine-tune. Those are useful controls. They are not, by themselves, an answer to the Act’s allocation of responsibility.
Open weights are not the same thing as the AI Act’s open-source exemption
The European Commission AI Office’s Q&A is the right starting point because it does not treat “open” as a mood. It separates general-purpose AI model obligations, the open-source exemption, and the systemic-risk regime. Under that Q&A, the open-source exemption for GPAI models relieves qualifying providers from some documentation and downstream-information duties, but it does not remove every GPAI obligation and does not apply where the model is classified as presenting systemic risk under Article 51.[1]
There is a common but dangerous shortcut here: “the weights are available, therefore the model is open source, therefore the EU AI Act largely does not apply.” Each link in that sentence needs checking. Open-weight availability may help a buyer inspect, constrain, self-host, or fine-tune a model. But open weights do not automatically mean that the release satisfies the Act’s conditions for the open-source exemption, and the exemption itself is only partial.
Open-source guidance outside the Commission materials makes the same caution useful in plainer procurement terms: an open-source software project, an open-weight model release, and a commercial model distributed under a restrictive license can sit in different legal positions even if all three are described in marketing language as “open.” Linux Foundation Europe and Orrick both warn, in different ways, against assuming that model-weight availability alone answers the Act’s open-source analysis.[2][3]
What the exemption waives, and what it leaves standing
For ordinary GPAI models that qualify for the open-source exemption and do not present systemic risk, the relief is meaningful but narrow. The Commission Q&A identifies the waived obligations as technical documentation and information for downstream providers. It also states that the copyright-policy obligation and the public summary of training content remain.[1]
| Issue | Treatment for a qualifying open-source GPAI model without systemic risk |
|---|---|
| Technical documentation obligation for GPAI providers | Waived under the open-source exemption, according to the Commission Q&A.[1] |
| Information to be supplied to downstream providers | Waived under the open-source exemption, according to the Commission Q&A.[1] |
| Copyright policy | Still applies; the exemption does not remove it.[1] |
| Public summary of training content | Still applies; the exemption does not remove it.[1] |
| Systemic-risk obligations | The exemption does not apply once the model is classified as presenting systemic risk.[1] |

That table is the part that should survive the meeting. If the vendor says the model is open, the next question is not whether the team likes open models. It is whether the vendor is relying on the Act’s open-source exemption, which conditions it claims to satisfy, and where it has put the surviving copyright and training-summary obligations.
The surviving obligations are not cosmetic. A copyright policy is not the same as source-code availability, and a public training-data summary is not the same as a model card written for customers. A law firm or legal-tech buyer does not need to solve the upstream provider’s full compliance program, but it does need to know whether the provider has treated “open” as a reason not to prepare documents that the Act still expects.
Fine-tuning can turn the downstream team into a provider
The most exposed legal-tech scenario is not a pure download. It is a download followed by fine-tuning, adaptation, hosting, evaluation, and resale or internal deployment. The upstream release may begin as somebody else’s GPAI model. After enough modification, the downstream actor may have created a new regulatory role for itself.
Quinn Emanuel’s March 2026 analysis of GPAI obligations describes the Commission’s indicative criterion for when fine-tuning may make the modifier a new provider: where the fine-tuning compute exceeds one-third of the compute used to train the original model. That is an indicative criterion, not a statutory bright line. It is still a useful warning because it turns an engineering number into a legal diligence question.[4]

The risk is easy to miss because fine-tuning often appears in procurement documents as a feature. “Can be fine-tuned on your precedent bank” sounds like control. For an EU AI Act allocation, the follow-up is less flattering: who calculates the compute used for the fine-tune, who compares it with the original training compute, who keeps the record, and who accepts provider obligations if the adaptation is treated as a new model?
A law-firm innovation team can also inherit ambiguity from the upstream provider. If the original training compute is not disclosed, the one-third comparison becomes difficult to perform. If the downstream vendor performs the fine-tuning, the buyer needs to know whether the vendor has taken the provider position or is quietly leaving the characterization unresolved. If the firm performs the fine-tuning itself, the issue should not be left to an engineer’s notebook and a procurement clause drafted before the model was adapted.
This is where open weights can increase responsibility rather than reduce it. The ability to modify the model is operationally valuable. It also creates a facts-and-records problem that a closed hosted API may not create in the same way. The answer is not to avoid fine-tuning; it is to treat fine-tuning as a role-change event that needs an owner before the model enters production.
Systemic risk removes the comfort of the exemption
The systemic-risk tier is another place where “open” can mislead. The Commission Q&A states that a GPAI model is presumed to have high-impact capabilities when the cumulative amount of computation used for its training, measured in floating point operations, is greater than 10^25. For models classified as presenting systemic risk, the open-source exemption does not apply.[1]
That 10^25 FLOPs point should be handled carefully. It is a presumption under Article 51, not an automatic and unrebuttable statutory label. A provider that crosses the threshold may seek to show that the model does not present systemic risk. The practical consequence for buyers is still significant: once the model is near that tier, open-source exemption language belongs in a risk file, not in a one-line procurement approval.[1]
This is also where policy debate can obscure the obligation map. In July 2026, Anthropic stated that it had never advocated banning open-weight models as a category.[6] That statement is relevant as a boundary marker: the live policy argument is not identical to the legal question. The EU AI Act analysis still has to ask which role the actor occupies, which tier the model falls into, and which obligations attach.
The Q3 2026 timeline is split, not frozen
The GPAI part of the EU AI Act is already part of the timeline. Quinn Emanuel’s March 2026 alert states that obligations for GPAI model providers took effect on 2 August 2025, with transition treatment until 2 August 2027 for providers of GPAI models already placed on the EU market before 2 August 2025. The same alert notes potential penalties of up to EUR 15 million or 3% of total worldwide annual turnover for certain infringements.[4]
That means an open-weight model released before the GPAI date is not simply outside the framework forever. It may have transition treatment. It may also be modified, redistributed, or integrated in ways that create fresh obligations for a downstream actor. The date of the original release is only one entry in the table.
The Digital Omnibus then complicates the separate high-risk timetable. Gibson Dunn’s 27 May 2026 summary of the provisional agreement reported that Annex III high-risk obligations would be deferred to 2 December 2027 and Annex I high-risk obligations to 2 August 2028, while Article 50 transparency obligations would largely remain live on 2 August 2026. The same source described the agreement as provisional in May 2026, with formal adoption expected before 2 August 2026.[5]
| Date or period | Why it matters for open-weight deployments |
|---|---|
| 2 August 2025 | GPAI provider obligations took effect, according to the March 2026 Quinn Emanuel summary.[4] |
| 2 August 2026 | Gibson Dunn reported that Article 50 transparency obligations would largely remain live on this date under the provisional Digital Omnibus agreement; enacted text should be checked as of August 2026.[5] |
| 2 August 2027 | Transition treatment for GPAI models already placed on the EU market before 2 August 2025 runs to this date, according to the same summary.[4] |
| 2 December 2027 | Gibson Dunn reported a deferral of Annex III high-risk obligations to this date under the provisional agreement.[5] |
| 2 August 2028 | Gibson Dunn reported a deferral of Annex I high-risk obligations to this date under the provisional agreement.[5] |
For a legal buyer, the point is not to memorize every date in isolation. It is to avoid collapsing three regimes into one answer. GPAI provider duties, high-risk system duties, and transparency duties can sit on different clocks. A vendor response that says “the high-risk obligations were deferred” does not answer whether GPAI obligations already apply, whether Article 50 transparency duties are live, or whether fine-tuning has changed the provider analysis.
Where the buyer’s diligence should land
The useful diligence file for an open-weight model is not a philosophical defense of openness. It is a role-and-obligation map. The upstream provider may owe GPAI obligations. A downstream fine-tuner may become a provider. A deployer may still have transparency, use-case, professional-responsibility, confidentiality, security, and contractual obligations that are not erased by the upstream model’s license.
For procurement, the minimum useful questions are concrete: what is the model’s release basis, what open-source exemption is being claimed, what copyright policy and public training-summary materials exist, whether the provider asserts or rejects systemic-risk status, what training-compute information is available, what fine-tuning compute will be used, and which party accepts provider obligations if the adapted model crosses the Commission’s indicative fine-tuning criterion.
There is a separate privacy question that should not be overclaimed here. Commentary around EDPB Opinion 28/2024 has noted that models trained on personal data cannot always be treated as anonymous merely because the model is not a database of records. That point should be checked against the primary opinion before being built into an EU AI Act obligation table. It may matter for GDPR analysis, but it is not needed to decide the narrower open-source-exemption question addressed in this article.
For Article-level tracking, use the site’s EU AI Act compliance obligations reference. For the deployer-side allocation problem that upstream GPAI duties do not solve, see who bears risk when you deploy open-weight AI models. For the separate U.S. track, use the counterpart on Chinese AI models and U.S. regulation. For EU procurement, the working conclusion is narrower and more durable: open weights are a fact to verify inside a compliance posture, not a compliance conclusion.
References
- General-purpose AI models in the AI Act – Questions and Answers, European Commission AI Office.
- What Open Source Developers Need to Know about the EU AI Act, Linux Foundation Europe, 3 April 2025.
- EU AI Act: Application to Open-Source Projects, Orrick, updated 25 July 2025.
- EU AI Act: Obligations on General-Purpose AI Model Providers, Quinn Emanuel, 25 March 2026.
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, Gibson Dunn, 27 May 2026.
- Our position on open-weights models, Anthropic, 27 July 2026.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →