You looked up the open source exemption, and it read like good news.
One sentence. Three exceptions. No conditions attached to any of it. So you wrote it down and went to check it against the thing your company actually runs, which is a set of weights someone downloaded and fine-tuned on your own data.
The law firm alerts quote that same sentence. So does the vendor documentation. So does the explainer your engineering lead sent you, the one with the green checkmarks.
At some point you start to wonder whether you have misread something.
You have not. You are reading an article that does not cover what you are looking at.
The Sentence in Question
Article 2(12) of the AI Act says this:
“This Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.”
That is the whole thing. It is genuinely useful. If you built a low-risk tool, released it openly, and it is not high-risk, not prohibited, and does not trigger transparency duties, you are outside the Regulation. Not lightly regulated. Outside.
Now read what it does not say.
It does not define a free and open-source license. It does not require you to publish weights, or architecture information, or anything else. It does not mention money. And it does not mention models.
That last one is the problem.
A Model Is Not a System
The AI Act keeps these apart on purpose. Article 3(1) defines an AI system. Article 3(63) defines a general-purpose AI model. Chapter V regulates general-purpose AI models on a separate track from everything else in the Regulation, with its own obligations and its own enforcement.
Article 2(12) says AI systems. So it does not reach the model.
The model exemptions live elsewhere. Article 53(2) provides:
“The obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks.”
Article 54(6) carries the same conditions across to the authorized representative duty.
See the difference. Article 2(12) asks one question: was it released under a free and open-source license? Article 53(2) asks three: does the license permit access, usage, modification and distribution, are the parameters public, and is the model free of systemic risk, which under Article 51 means the largest models, presumed once training compute passes 10^25 floating point operations.
Same phrase, two tests, and which one you are under depends entirely on what you have.
And there’s one more complication. Recital 103 opens by saying that free and open-source AI components cover “the software and data, including models and general-purpose AI models, tools, services or processes of an AI system.” And Recital 102 supplies, for general-purpose models, the same publicly-available-parameters condition that Article 2(12) leaves out. Neither changes the operative text, and recitals do not create obligations. But they tell you something about where this regime keeps its content.
The Money Condition Leaves in a Recital
The monetization limit is the most consequential condition on the open source exemption, and it appears in neither Article 2(12) nor Article 53(2). It is in Recital 103:
“AI components that are provided against a price or otherwise monetised... should not benefit from the exceptions provided to free and open-source AI components. The fact of making AI components available through open repositories should not, in itself, constitute a monetisation.”
Recitals guide interpretation. They do not impose obligations. So a provider who reads the articles gets a shorter answer than a provider who reads the articles plus the recitals, and nothing in the articles tells you to go looking.
The Commission filled some of this in. Its guidelines on the scope of obligations for providers of general-purpose AI models, the Annex to Commission Decision C(2025) 5045 final of 18 July 2025, are non-binding, and they are the clearest reading available.
Paragraph 83 lists what disqualifies a license. Limitations to non-commercial or research-only use. Prohibitions on distributing the model. Requirements to obtain separate commercial licenses for specific use cases. And this one:
“usage restrictions triggered by user scale thresholds (e.g. requiring additional licensing if monthly active users exceed a certain number)”
Now open the Llama 4 Community License Agreement of April 5, 2025, Section 2:
“If, on the Llama 4 version release date, the monthly active users of the products or services made available by or for Licensee, or Licensee’s affiliates, is greater than 700 million monthly active users in the preceding calendar month, you must request a license from Meta”
The guidelines describe that clause almost exactly, without naming it.
We can debate here but my understanding is that some of the most widely deployed open-weight models in Europe may sit outside the AI Act’s open source exemption while being described as inside it in many articles. The guidelines are not binding, the Commission has published no determination on any named model, and this has not been litigated. Read the clause and the paragraph and judge for yourself. But if your compliance position rests on a model being open source, the license text is the document to read.
What Survives a Perfect Open Release
Say the model clears every condition. Truly open license, weights and architecture published, no systemic risk, no charge for anything.
The copyright policy under Article 53(1)(c) still applies. So does the public summary of training content under 53(1)(d). Recital 104 confirms both were deliberately left outside the exemption. Cooperation with the Commission and national authorities still applies. If the model crosses into systemic risk, Article 55 applies in full and the exemption disappears entirely.
Then there is everything downstream. Article 50 transparency, if the system talks to people or generates synthetic content. Prohibited practices. High-risk classification.
The exemption is documentation relief for model providers and a scope exclusion for genuinely low-risk systems. It is not a status your project acquires and keeps.
However, building on an exempt open model does not make your system exempt.
Another Exception?
Article 25(4) requires a written agreement between the provider of a high-risk AI system and the third party supplying components into it, specifying the information and technical access the provider needs to comply. Its second subparagraph exempts open source suppliers:
“This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.”
Other than general-purpose AI models.
The Digital Omnibus on AI replaced the first subparagraph of Article 25(4). The list of what a third party can supply now reads “an AI system, AI model, tools, services, components, or processes.” AI model is new.
The second subparagraph was not touched.
So the written agreement duty grew to reach model suppliers, and the open source relief still excludes exactly the thing model suppliers supply. The single place the AI Act offers open source contributors contractual relief in the high-risk value chain is the place it withholds it from them, and the amendment made the mismatch wider rather than narrower.
Three Exits with Three Different Clocks
There is probably one date in your file for this. There are three dates though.
Article 2(12) names the three ways out of the exemption in a single line of text, which is why they get planned for as one deadline.
They do not arrive together.
Article 5, prohibited practices. In force since February 2, 2025, and the Omnibus added two new points that apply from December 2, 2026. Article 99(3) puts breaches here in the top tier: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
Article 50, transparency. In force since August 2, 2026. The machine-readable marking duty in Article 50(2) carries a four-month transitional period for systems that were already on the market, and that period is running right now. It closes December 2, 2026. Up to €15 million or 3%.
High-risk classification. 2 December 2027 for standalone systems in the Annex III use cases: employment, credit, education and the rest. August 2, 2028 for AI embedded in products already covered by EU product safety law. Up to €15 million or 3%.
Two of the three are already live. The third is fifteen months out, and it moved to get there. Before the Omnibus, standalone high-risk obligations would have applied from August 2, 2026 and embedded high-risk from August 2, 2027.
Which leaves the exit most open source coverage is organized around as the one that cannot bite yet, and the two that can as the ones drawing the least attention.
The Omnibus also inserted new paragraphs 1a, 1b and 1c into Article 6, recutting what counts as a safety component. 1a takes out systems that only assist users or optimize performance. 1b puts back in systems whose failure would endanger health or safety. 1c takes out products that need third-party assessment only for risks other than safety. Article 6(3), the classification off-ramp, was not amended.
The Prohibition That Was Not Costed for Open Weights
The Omnibus added two prohibited practices to Article 5, applying December 2, 2026. Point (ba) covers AI systems that generate or manipulate realistic images, video, audio or similar material of an identifiable person’s intimate parts, or of an identifiable person in sexually explicit activity, without that person’s explicit consent. Point (bb) covers systems generating or manipulating child sexual abuse material within Directive 2011/93/EU, except where a “without right” defense applies under national law.
Realistic narrows point (ba): it reaches convincing output, not obvious fabrication. Article 5(1b) narrows it again. Editing that neither increases the exposure of intimate parts nor changes the nature of the depicted activity is not manipulation for these purposes. On a provision carrying a 7% ceiling, that is the line between a prohibited system and a lawful one.
The rest of the limits sit in a new Article 5(1a). For placing on the market, the prohibition bites where that generation is the intended purpose, or where the system’s design, training, architecture, capabilities or user-facing functionalities make it
“a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse”
The standard is reasonableness, not perfection, and open-weight providers can argue prevention: refusal training, classifiers, usage policies, published safeguards.
Correction is a different question. The provision asks for safeguards to correct observed or reported misuse, and there is no mechanism that reaches a checkpoint after it has been downloaded, mirrored and fine-tuned. You cannot patch it. You cannot recall it. You frequently cannot observe it. The obligation assumes a channel back to the artifact, and open weights is the distribution model defined by not having one.
The same distinction cuts the other way.
Article 5 is written throughout in terms of “an AI system.” Article 5(1a) turns on “the system’s design, training, architecture, capabilities or user-facing functionalities.” The reasoning that keeps a model outside Article 2(12) keeps a bare weights release outside Article 5. Being outside an exemption costs you obligations, and being outside a prohibition costs the public a protection. The prohibited practices guidelines do not resolve it. As far as I can find, nothing does.
Your own exposure is clearer than the drafters’ intent. Article 5(1a)(b) prohibits use where “the deployer uses the system for the purpose of generating or manipulating such material.” Download open weights, fine-tune away the refusal behavior, generate the output, and you are inside the prohibition with no exemption available at any point, because Article 5 is one of the three named exits from Article 2(12). On that limb, and only that limb, accidental output is outside: the use prohibition turns on purpose. The placing-on-the-market limb is built to catch unintended output where it is foreseeable, reproducible and inadequately guarded.
The Argument Running the Other Way
Everything above says the exemption is narrower than it looks. There is a serious published argument that it is too wide, and it deserves the floor.
Simona Ramos and Fabio Pianese, writing in AI and Ethics this year, go after the definition itself. The AI Act never requires training data disclosure. Publish the weights, publish a descriptive summary of what went into them, and you qualify. They call the result open-washing: partial disclosure earning a regulatory exemption that exists to reward transparency, leaving downstream users carrying risks with no identifiable party accountable for them.
I would say that both readings hold at once. The exemption is too narrow for the person who assumes it covers their fine-tuned model, and too wide for the person who assumes it guarantees them a model they can actually inspect.
What to Do
Work out whether you have a system or a general-purpose model. If you deployed something users interact with, you have a system and Article 2(12) is your provision. If you published weights of a general-purpose model, Articles 53(2) and 54(6) are yours. If you did both, you have both, assessed separately. And if you openly released a narrow, single-purpose model, note that Chapter V does not reach you and neither does Article 2(12), which speaks to systems.
Read the license, not the announcement. Check it against guidelines paragraph 83: non-commercial limits, distribution bans, user-scale thresholds, separate commercial licenses for particular uses. Any one of them and the model is arguably not open source for AI Act purposes, whatever it is called.
Check for monetization before you rely on the exemption. Paid support bundled with access, dual licensing, hosted access behind payment, ad-served access, data collection beyond model security. Recital 103, and guidelines paragraphs 86 to 89.
Stop treating upstream openness as your answer. Write down your own role for each system. The exemption belongs to whoever made the release.
If you supply a model into someone’s high-risk system, expect the written agreement. The Article 25(4) carve-out does not cover general-purpose models, and after the Omnibus the duty names AI models explicitly.
If you deployed a generative system before August 2, 2026, check your Article 50(2) marking. The transitional period ends December 2, 2026.
If you fine-tune image, video or audio generation models, put December 2, 2026 in the calendar. Not the 2027 date. That one.
What Is Left Unresolved
An authorized representative exists so that EU authorities have someone inside the Union to serve, question, and hold responsible when the provider is somewhere else.
Article 54(6) removes that requirement for providers of free and open-source general-purpose AI models without systemic risk. Reasonable enough, in 2024, for a regime built around documentation.
From December 2, 2026, Article 5(1a) makes lawfulness turn partly on whether misuse gets corrected after release. It does that for the class of providers least able to correct anything, many of them outside the Union, and by virtue of 54(6), with no one inside it to ask.
The obligation needs a channel back to the artifact. The exemption removed the channel back to the provider.
Two holes in the same instrument, pointing in opposite directions. One lets a provider look open without being open. The other lets a provider be open without being reachable.
Scope is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.






There is a second route into provider status that sits outside the exemption question entirely. Article 25(1) treats a distributor, importer, deployer or other third party as the provider of a high-risk system, with the full Article 16 obligations, where they put their name on it, make a substantial modification that keeps it high-risk, or change its intended purpose.
Downloading weights and fine-tuning them on company data can meet the second or third limb.
Article 25 applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I, under Article 113(c), which lines up with the deadlines set out above.
The Article 5 / 54(6) pairing at the end is the sharpest point here. The correction-channel gap isn't specific to open weights; it's the ordinary model-update problem with the one fallback removed. Banking examiners under the April 2026 Federal Reserve/OCC model-risk guidance already find 43% of institutions can't update models they fully own, host on their own infrastructure, and have a designated owner for.
Strip out ownership, hosting, and the authorized representative, and updating an already-mirrored model doesn't get harder. It stops being anyone's job.