There is a second route into provider status that sits outside the exemption question entirely. Article 25(1) treats a distributor, importer, deployer or other third party as the provider of a high-risk system, with the full Article 16 obligations, where they put their name on it, make a substantial modification that keeps it high-risk, or change its intended purpose.
Downloading weights and fine-tuning them on company data can meet the second or third limb.
Article 25 applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I, under Article 113(c), which lines up with the deadlines set out above.
Of the three routes in Article 25, the third is the one that fits. It names general-purpose AI systems repurposed into a high-risk use. The second needs a system already classified as high-risk, so it doesn't reach an open release. Though fine-tuning and deploying usually makes you the provider under the ordinary definition first, without needing Article 25.
Article 25(2) carries the part that matters for an open release. Once that route transfers provider status, the initial provider must cooperate closely with the new provider and make available the necessary information and reasonably expected technical access. The final sentence removes that duty where the initial provider has clearly specified its system is not to be changed into a high-risk one. A release carrying that statement shifts the documentation burden entirely onto whoever repurposes it.
The Article 5 / 54(6) pairing at the end is the sharpest point here. The correction-channel gap isn't specific to open weights; it's the ordinary model-update problem with the one fallback removed. Banking examiners under the April 2026 Federal Reserve/OCC model-risk guidance already find 43% of institutions can't update models they fully own, host on their own infrastructure, and have a designated owner for.
Strip out ownership, hosting, and the authorized representative, and updating an already-mirrored model doesn't get harder. It stops being anyone's job.
Open and outside systemic risk means no authorised representative. So a correction has no address in the European Union, and the deployer left holding the model has obligations but no way to act on them.
There is a second route into provider status that sits outside the exemption question entirely. Article 25(1) treats a distributor, importer, deployer or other third party as the provider of a high-risk system, with the full Article 16 obligations, where they put their name on it, make a substantial modification that keeps it high-risk, or change its intended purpose.
Downloading weights and fine-tuning them on company data can meet the second or third limb.
Article 25 applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I, under Article 113(c), which lines up with the deadlines set out above.
Of the three routes in Article 25, the third is the one that fits. It names general-purpose AI systems repurposed into a high-risk use. The second needs a system already classified as high-risk, so it doesn't reach an open release. Though fine-tuning and deploying usually makes you the provider under the ordinary definition first, without needing Article 25.
Article 25(2) carries the part that matters for an open release. Once that route transfers provider status, the initial provider must cooperate closely with the new provider and make available the necessary information and reasonably expected technical access. The final sentence removes that duty where the initial provider has clearly specified its system is not to be changed into a high-risk one. A release carrying that statement shifts the documentation burden entirely onto whoever repurposes it.
The Article 5 / 54(6) pairing at the end is the sharpest point here. The correction-channel gap isn't specific to open weights; it's the ordinary model-update problem with the one fallback removed. Banking examiners under the April 2026 Federal Reserve/OCC model-risk guidance already find 43% of institutions can't update models they fully own, host on their own infrastructure, and have a designated owner for.
Strip out ownership, hosting, and the authorized representative, and updating an already-mirrored model doesn't get harder. It stops being anyone's job.
Open and outside systemic risk means no authorised representative. So a correction has no address in the European Union, and the deployer left holding the model has obligations but no way to act on them.