EU AI Act Compliance

EU AI Act Open Source Models: What the Exemptions Actually Cover

Open source AI models get special treatment under the EU AI Act, but the exemption has firm limits. Here is what deployers using Mistral, Llama, or similar models actually need to know.

· 5 min read · By

EU-law graduate (Maastricht University) · MSc International Tax Law (AI & technology). Builds AI systems and advises SMEs on EU AI Act compliance.

The EU AI Act open source models exemption sounds like a clean escape hatch. It is not. Article 2(12) of the AI Act carves out certain open source AI components from some obligations, but the moment your company fine-tunes, integrates, or deploys one of those models in a business context, the exemption starts shrinking fast. This post explains exactly where the line sits, when you cross it, and what that means for your compliance posture today.

What Article 2(12) Actually Says

The AI Act's open source carve-out is found in Article 2(12). It exempts providers who make AI models available under open source licences from several of the Act's obligations, provided the model weights are publicly released and the release is not commercially motivated in a way that triggers full provider status.

The exemption is specifically about releasing model components to the public. It was designed to protect open source developers, researchers, and communities from bearing the same compliance burden as a commercial AI company shipping a finished product. Think of the teams publishing foundational weights on Hugging Face rather than a company building a payroll-screening tool on top of Llama 3.

Critically, the exemption covers certain obligations under Chapter III (requirements for high-risk AI systems) and Chapter V (general-purpose AI models) only in specific circumstances. It does not grant a blanket exemption across the entire regulation.

Recital 102 of the AI Act clarifies the intent: open source release should be encouraged because it supports innovation and transparency, but that encouragement stops where genuine commercial deployment or high-risk use begins.

Who the Exemption Is Actually For

Before going further, it helps to be clear about who sits at each point in the supply chain.

  • Original developers publishing model weights openly (e.g., Meta releasing Llama, Mistral AI releasing Mistral 7B) may benefit from the open source carve-out at the point of release.
  • Deployers, meaning companies that take those weights and use them to build or run an AI system in their own business, do not automatically inherit that exemption.

This matters enormously. As a deployer under Article 26, your obligations flow from how you use the system, not from the licence the underlying model carries. Open source does not mean obligation-free when it lands inside your HR platform, your customer service bot, or your document screening tool.

When Fine-Tuning Takes You Out of the Exemption

This is where things get concrete. Suppose your company takes an open source model, say Mistral 7B or Llama 3 8B, and fine-tunes it on your own HR data to assist with CV screening. The original model release may have qualified for the open source carve-out. Your fine-tuned derivative almost certainly does not.

Here is why. The moment you modify model weights and deploy the resulting system in a business process, you become a provider under Article 3(3) of the AI Act, not merely a deployer. You have put a new AI system into service under your name. Provider obligations then apply, and they are substantially heavier.

For high-risk systems, those obligations include:

  • Establishing a quality management system (Article 17)
  • Conducting a conformity assessment before deployment (Article 43)
  • Registering the system in the EU database (Article 71)
  • Providing technical documentation (Annex IV)

CV screening and recruitment tools fall squarely into Annex III as high-risk AI systems. Fine-tuning an open source model for that purpose does not reduce the regulatory classification. It may actually deepen it.

What About Unmodified Deployment?

Suppose you do not fine-tune at all. You take a publicly released model and deploy it as-is through an API wrapper or on your own infrastructure. Does the exemption protect you then?

No. Even unmodified deployment for a business purpose makes you a deployer under the Act. Deployer obligations under Article 26 apply regardless of the model's open source status. Those include:

  • Implementing the provider's instructions for use
  • Monitoring the system for risks and incidents
  • Keeping logs where technically feasible
  • Conducting a Fundamental Rights Impact Assessment (FRIA) for certain high-risk systems (Article 27)
  • Ensuring affected employees or individuals are informed about AI-assisted decisions (Article 86)

The open source label on the model's licence file changes none of this. Your legal obligation is determined by what the system does and who is affected by it.

Practical Implications for Mistral, Llama, and Similar Models

Let us get specific about the models European SMEs are actually using.

Mistral models (Mistral 7B, Mixtral, Mistral Small) are released under the Apache 2.0 licence. The company behind them is a commercial entity. The open source release of weights may attract the Article 2(12) carve-out for Mistral AI itself. For you as the deployer, it does not.

Meta's Llama models (Llama 2, Llama 3, Llama 3.1) use a custom community licence. Again, the release may benefit the original publisher. Your deployment does not.

Practical checklist for any SME using these models:

  1. Identify the use case. Is the system making or supporting decisions about people in employment, credit, education, or essential services? If yes, it is likely high-risk under Annex III.
  2. Determine your role. Did you modify the weights in any way, including fine-tuning or instruction tuning? If yes, you are a provider, not just a deployer.
  3. Check transparency obligations. Article 50 requires disclosure when people interact with AI systems that generate text, audio, or images. This applies whether the underlying model is open source or proprietary.
  4. Maintain AI literacy. Article 4 requires that your staff who work with AI systems have appropriate understanding of how those systems work and their limitations. Open source models are not exempt from this obligation.
  5. Document everything. Whether you are a provider or deployer, the AI Act rewards documented decision-making. Record why you chose the model, how you tested it, and what risk controls you applied.

The Deadline Picture

The prohibition on unacceptable risk AI systems (Article 5) has been enforceable since 2 February 2025. Obligations for high-risk AI systems in Annex III start applying on 2 August 2026. General-purpose AI model obligations (Chapter V) apply from 2 August 2025 for providers of those models.

If you are a deployer of an existing open source model in a high-risk context, August 2026 is your preparation deadline. That sounds distant. It is not. Conformity assessments, FRIA exercises, log management systems, and staff AI literacy programmes take months to implement properly, especially for companies without a dedicated compliance function.

Start the inventory now. Map every AI system in use, note the underlying model, and assign a risk classification. That single step, done rigorously, will tell you whether the open source label on your model actually changes anything for your compliance obligations. Spoiler: in most real business deployments, it does not change much at all.

Run your free 2-minute compliance check at comply.khairos.ai to see where your current AI systems sit on the risk scale and which obligations already apply to your business.

Need help getting compliant?

The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.

Start the free check →