LinkedInInstagramXTikTok

Open-source AI and the EU AI Act: which exemptions actually apply

Why the open-source exemption is misunderstood

“We use an open-source model, so the AI Act does not apply to us.” It is one of the most common assumptions we encounter, and it is wrong in almost every case where it is made.

The EU AI Act does contain exemptions for free and open-source AI. They are real, and for some organisations they are valuable. But they are narrow, they are conditional, they stop entirely at the boundary of high-risk use, and they attach to the actor who releases the software – not to the business that downloads it. The Digital Omnibus on AI, Regulation (EU) 2026/1744, left this architecture essentially intact when it entered into force in July 2026, so the position established in 2024 still stands.

The exemption for AI systems

Article 2(12) provides that the Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems, or as an AI system falling under Article 5 or Article 50.

That is a closed list of three carve-outs, and each one is broad in practice.

High-risk systems. If the system is placed on the market or put into service as a high-risk system under Article 6, the exemption simply does not engage. Open-source status is irrelevant.

Article 5 prohibitions. Nothing about an open licence permits a banned practice. This carve-out widened in scope when the Digital Omnibus added new prohibitions on AI systems generating non-consensual intimate imagery and child sexual abuse material, which apply from 2 December 2026.

Article 50 transparency. This is the carve-out that catches the most businesses. Chatbots, synthetic content marking, deepfake disclosure and emotion recognition notification all fall under Article 50 – and those obligations have applied since 2 August 2026. An open-source chatbot still has to tell people they are talking to a machine.

The exemption for general-purpose AI models

Article 53(2) deals separately with general-purpose AI models. Where a model is released under a free and open-source licence that allows access, usage, modification and distribution, and where its parameters – including the weights, information on the model architecture and information on model usage – are made publicly available, two obligations fall away.

The obligations that are disapplied are Article 53(1)(a), the duty to draw up and maintain technical documentation of the model for the AI Office and national authorities, and Article 53(1)(b), the duty to make information and documentation available to downstream providers integrating the model.

What survives regardless of openness

Two obligations always apply. Article 53(1)(c) requires a policy to comply with Union copyright law, including identifying and complying with a reservation of rights under Article 4(3) of the Copyright in the Digital Single Market Directive. Article 53(1)(d) requires a publicly available, sufficiently detailed summary of the content used for training the model.

Recital 104 explains the reasoning directly: releasing a model openly does not necessarily reveal substantial information about the training data or how copyright compliance was ensured, so the transparency exemption was never intended to reach those two duties.

Systemic risk overrides everything

Article 53(2) states expressly that the exception does not apply to general-purpose AI models with systemic risk. Recital 104 is blunt about it: where a model presents systemic risk, the fact that it is transparent and accompanied by an open-source licence is not a sufficient reason to exclude compliance. Such providers owe the full Article 53 set plus the Article 55 obligations covering model evaluation, adversarial testing, systemic risk assessment and mitigation, incident reporting and cybersecurity protection.

What counts as free and open-source under the Act

There is no definition in the enacting terms. The test is assembled from Article 53(2) and the recitals, and it is stricter than the everyday industry usage of the phrase.

Recital 102 sets the baseline: a licence qualifies where it allows software and data, including models, to be openly shared and where users can freely access, use, modify and redistribute them or modified versions. Crucially, it confirms that a licence remains free and open-source where it requires the original provider to be credited or requires identical or comparable distribution terms to be respected. Attribution and copyleft conditions do not break the exemption.

The monetisation rule

Recital 103 is where most claimed exemptions fail. AI components provided against a price or otherwise monetised do not benefit from the open-source exceptions. “Otherwise monetised” expressly includes monetisation through the provision of technical support or other services related to the component, monetisation through a software platform, and the use of personal data for reasons other than exclusively improving the security, compatibility or interoperability of the software.

Two points of relief sit alongside that. Transactions between microenterprises are excepted, and making a component available through an open repository does not, in itself, constitute monetisation. Publishing on a public repository is fine. Charging for support around it is not.

Do open-weight models qualify?

This is the practical crux, and the short answer is that open weights and free and open-source are not the same thing.

Publishing weights satisfies only one half of the Article 53(2) test. The licence test is separate, and the Commission’s guidelines on the scope of obligations for providers of general-purpose AI models, published in July 2025, indicate that all four rights – access, use, modification and redistribution – must be fully granted. If one is missing, the licence is not free and open-source for these purposes. Access is read as meaning that anyone interested can obtain the model without payment or other restrictions, though non-discriminatory safety or identity verification steps are tolerated. Attribution and same-terms conditions remain acceptable, and a licence can still qualify even if it allows derivatives to be relicensed on proprietary terms.

Features that point away from qualification include non-commercial or research-only restrictions, field-of-use restrictions, and user-scale thresholds requiring a separate commercial licence above a certain number of users. Several widely used “community” licences contain precisely those features. A business relying on one of them should not assume the Article 53(2) exemption is available, and should assess the specific licence rather than the label.

The exemption does not travel downstream

This is the point that matters most to the businesses reading this, because most of you are users rather than publishers.

Each exemption is assessed at the level of the actor and the release in question. It is not a property of the artefact that follows it through the value chain. Three consequences follow.

If you deploy an open-source model in a high-risk use case, the exemption is simply switched off. Article 2(12) does not apply where the system is placed on the market or put into service as high-risk. Whoever puts the resulting system on the market under their own name carries the full Chapter III regime, and under Article 25 a deployer who brands it, substantially modifies it, or changes its intended purpose to a high-risk one becomes the provider.

You inherit no documentation. Here is the asymmetry that hurts. The upstream open-source model provider is exempt from producing technical documentation and downstream information under Article 53(1)(a) and (b). The upstream open-source supplier of tools and components is exempt from the Article 25(4) cooperation duty. Yet you still owe complete technical documentation for the high-risk system you have built. There is no one to ask, and you must reconstruct data governance, evaluation and documentation evidence yourself. Note one important limit on that carve-out: the Article 25(4) exclusion does not extend to general-purpose AI models, so a free and open-source model supplier can still be brought into a written agreement.

Your own release terms govern your own exemption. Fine-tune an open model and publish your version behind a paid API, under a restrictive licence, or with paid support attached, and you get no exemption for your release – whatever the upstream licence said.

Praktiskt exempel

A Swedish SaaS company downloads an openly published language model, fine-tunes it on its own data, and builds a tool that screens job applications for its customers. It assumes it is outside the AI Act because the base model is open source.

Every part of that assumption fails. Recruitment sits in Annex III, so the system is high-risk and Article 2(12) does not engage. The company brands the tool as its own, so under Article 25(1)(a) it is the provider. The customer-facing interface generates text for candidates, so Article 50 applies today. And because the upstream provider was exempt from producing downstream documentation, the company must build its Annex IV technical file from scratch.

The open-source choice reduced its licensing cost and increased its regulatory burden. That trade-off is entirely manageable – but only if it is understood before the product ships.

Vanliga misstag som företag gör

The first is treating “open source” as a category that removes the AI Act. It removes specific obligations from specific actors in specific circumstances.

The second is equating open weights with an open-source licence. Weights are one condition among several, and the licence terms are usually where the exemption is lost.

The third is ignoring the monetisation rule. Charging for support, bundling paid services, or offering the same component through a paid platform will defeat the exemption even where the licence itself looks permissive.

The fourth is assuming Article 50 does not apply. It applies to open-source systems by express carve-out, and it has been in force since August 2026.

The fifth is planning a high-risk product around an open model without confirming what documentation exists. The absence of upstream documentation is a design constraint, not a detail.

Rekommenderade åtgärder

Read the actual licence of every model in your stack against the four-rights test, rather than relying on how it is described. Check the monetisation position for anything you publish yourself, including paid support and platform access.

Classify your use case before your model. Whether Annex III applies is determined by what the system does, not by what it was built from – and once high-risk applies, the exemption question is over. Assess documentation availability early, and treat missing upstream documentation as a cost line in the build.

Confirm your Article 50 position today, since that obligation is live. And if you contribute or publish models, decide deliberately whether you want to preserve exemption status, because commercial choices about support and platform access will determine it.

Vanliga frågor

Does the copyleft requirement in our licence break the exemption?

No. Recital 102 confirms that a licence remains free and open-source where it requires the original provider to be credited and requires identical or comparable distribution terms to be respected. Attribution and share-alike conditions are compatible with the exemption. Restrictions on field of use, commercial use, or user numbers are a different matter.

We host an open-source model for customers and charge for it. Are we exempt?

Almost certainly not, as regards that offering. Recital 103 treats provision against a price, monetisation through a software platform, and monetisation through related technical support or services as taking the component outside the exemption. Publishing on an open repository is not itself monetisation, but charging for access or support around it is.

Did the Digital Omnibus change the open-source rules?

Not materially. Article 2(12) and Article 53(2) were not amended. Article 25(4) was amended to add “AI model” to the list of items a third-party supplier may provide, while the free and open-source carve-out in that paragraph – including its exclusion of general-purpose AI models – was retained. The new Article 5 prohibitions do widen the practical reach of the Article 2(12) carve-out from December 2026.

Slutsats

The AI Act’s open-source exemptions are genuine but narrow. For AI systems, they disappear the moment the system is high-risk, prohibited, or subject to transparency duties. For general-purpose AI models, they remove two documentation obligations while leaving copyright policy and training-content summary intact, and they vanish entirely for models with systemic risk. Open weights are not the same as an open-source licence, monetisation defeats the exemption, and none of it travels downstream to the business deploying the model. Lawgent helps businesses assess whether the models in their stack genuinely qualify, understand what obligations they inherit as deployers and integrators, and build compliant products on open foundations.

Lämna ett svar

Din e-postadress kommer inte publiceras. Obligatoriska fält är märkta *


0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken