Two exemptions, not one
The Act carries two open-source exemptions. They sit in different chapters, they exempt different things, and conflating them is the most reliable way to reach the wrong answer.
Art 2 works at system level. It takes AI systems released under free and open-source licences outside the scope of the Act, subject to carve-outs that account for most of the cases a commercial team cares about.
Art 53(2) works at model level. It does not take an open general-purpose AI model outside the Act at all. It removes part of the documentation burden in Article 53(1) and leaves the rest in place.
The two do not stack. Article 2 relief for a system does nothing for a model you publish, and Article 53(2) relief on a model does nothing for a system somebody builds on it. A team that publishes weights and also ships a product on those weights is standing in both regimes at once, in opposite directions.
Article 2: the system-level exemption
Article 2 provides that the Act does not apply to AI systems released under free and open-source licences. Four things defeat it, and any one of them on its own is enough.
The system is placed on the market or put into service as high-risk. This is the largest hole. Classification under Article 6 runs on what the system does, through the Annex I product safety route or the eight Annex III use cases, and the licence is not an input to that test. An openly licensed CV screener is a high-risk employment system on exactly the same terms as a proprietary one. The application dates give time, not relief: standalone Annex III obligations apply from 2 December 2027 and AI embedded in Annex I products from 2 August 2028. What the classification tests actually ask is set out on the high-risk classification page.
The system falls under Article 5. The eight prohibited practices have applied since 2 February 2025, and the Digital Omnibus, Regulation (EU) 2026/1744, adds a ninth from 2 December 2026 covering AI that generates child sexual abuse material or non-consensual intimate imagery, binding providers and deployers alike. Article 5 breaches sit in the top penalty tier under Article 99: 35,000,000 euro or 7 percent of total worldwide annual turnover, whichever is higher.
The system falls under Article 50. For open releases this is the carve-out that bites first, because so many of them are generative. Article 50(1), 50(3) and 50(4) apply on 2 August 2026, and the 50(2) machine-readable marking duty applies on the same date for systems placed on the market on or after it.
The system is monetised. Article 2 states that the exemption does not apply where the system is monetised. Read that as the condition that fails quietly: paid hosting of the model you published, a commercial licence tier, a paid support contract wrapped around the release. Where a revenue line is attached to the thing you gave away, plan on the exemption being unavailable and satisfy the underlying obligations instead.
One further point that catches non-EU publishers. Article 2 reaches providers placing systems on the Union market wherever they are established, and providers and deployers in third countries where the output produced by the system is used in the Union. A repository is not a jurisdiction.
Article 53(2): the model-level exemption
The Article 53 baseline for a provider of a general-purpose AI model is four duties, and they have applied since 2 August 2025: Annex XI technical documentation, Annex XII information for downstream providers, a copyright policy, and a public summary of training content. Article 53(2) removes the first two for models released under a free and open-source licence. It removes nothing where the model is a systemic-risk model.
| Article 53 duty | Open-source model, no systemic risk | Systemic-risk model |
|---|---|---|
| Annex XI technical documentation | Lifted by Art 53(2) | Owed in full |
| Annex XII information for downstream providers | Lifted by Art 53(2) | Owed in full |
| Copyright policy | Owed | Owed |
| Public summary of training content | Owed | Owed |
| Article 55 systemic-risk duties | Not engaged | Owed in full |
The two duties that survive are the two that are hardest to discharge quietly, and that is not an accident of drafting. A copyright policy is a statement about how the training corpus was assembled. A public summary of training content is, by construction, published. Neither can be satisfied by a document you keep in a drawer and produce on request, which is exactly what Annex XI and Annex XII allow.
Systemic risk is presumed where cumulative training compute exceeds 10^25 FLOP. Above that line Article 55 adds evaluation, adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity protection, and Article 53(2) gives back nothing whatsoever. An open frontier model is the most heavily regulated thing in this article, not the least. The full obligation map sits on the GPAI obligations page. The AI Office takes up enforcement on 2 August 2026.
What counts as a free and open-source licence
Both exemptions turn on the same phrase, and the phrase is doing a lot of work. Note first what it is not: it is a licence condition, not a distribution condition. Publishing weights for anyone to download is not the test. The test is the terms under which you published them.
The two ends are clear enough. A licence in the familiar permissive or copyleft tradition, with no fee, no restriction on who may use the software and no restriction on the field of use, sits inside the phrase on any reading. At the other end, weights released only under a negotiated commercial agreement, or behind a paywall, are not released under a free and open-source licence in any sense the words will bear.
The contested middle is the community and responsible-use licence: weights and code published openly for anyone to download, but with an acceptable-use annex banning categories of application, and sometimes a revenue or user-count threshold above which a separate commercial licence is required. These are common, and they are genuinely unresolved. This article is not going to invent a test for them, because there is no authoritative worked example to point at and a made-up one would be worse than none.
What can be said usefully is how to hold the risk. If your licence restricts field of use, or converts to a paid licence above a threshold, treat the exemption as unavailable for planning purposes and build the position so that it does not depend on the answer. That is cheap for Article 53(2), where the surviving duties are the expensive ones anyway. It is expensive for Article 2, which is a reason to check whether the Article 5, Article 50 and high-risk carve-outs had already taken you out of the exemption before the licence question was ever reached. In most commercial cases they had.
What you did, versus what you owe
The exemptions do not describe a kind of organisation. They describe an act. Find the row that matches the act.
| What you did with the open model or system | What that makes you | What you owe |
|---|---|---|
| Published weights under a free and open-source licence, no fee, below the systemic-risk threshold | Provider of a GPAI model | Copyright policy and public training-content summary. Annex XI and Annex XII lifted by Art 53(2). |
| Published the same model above 10^25 FLOP cumulative training compute | Provider of a GPAI model with systemic risk | All four Article 53(1) duties plus the Article 55 set. Art 53(2) gives nothing. |
| Published an open-source AI system that is not generative, not prohibited and not high-risk | Outside the Act under Art 2 | Nothing, for as long as all four Article 2 conditions hold. |
| Published an open-source system that generates text, image, audio or video | Provider under Article 50 | 50(1) and 50(2) as applicable, from 2 August 2026. The licence is irrelevant. |
| Published an open-source system intended for one of the eight Annex III use cases | Provider of a high-risk system | Articles 9 to 15, Article 43 conformity assessment and Article 49 registration, from 2 December 2027. |
| Charged for access, hosting or a commercial licence tier around the release | Monetised, so outside Art 2 | Whatever the system's own tier carries, assessed as if the exemption did not exist. |
| Downloaded someone else's open model and shipped a product on it under your name | Provider of that system | Everything the system's tier carries, transparency included. Their licence does not cover you. |
| Fine-tuned or repurposed an open model for an Annex III use | Provider of a high-risk system under Art 25 | The full Article 16 set, plus the Article 6(4) classification record before market placement. |
Building on an open model makes you the provider
This is the part that matters most in practice, and it has nothing to do with licensing at all. The provider is the party that develops a system and places it on the market or puts it into service under its own name or trademark. Take an open model, wrap it in a product, ship it: you are the provider of that system. The upstream publisher is the provider of the model, and the two roles carry different obligation sets under different articles.
Article 25 then adds a second route, and its third limb is the one written for exactly this situation. Modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk makes you a provider of a high-risk system with the full Article 16 obligation set. Putting your name or trademark on a high-risk system does the same, as does a substantial modification that keeps it high-risk. The three triggers, and the way they travel through a supply chain, are worked through on the provider and deployer roles page.
Two practical consequences follow. First, if your product could be high-risk, the Article 6(4) documentation has to exist before the system is placed on the market, not after a regulator asks. Where you rely on the Article 6(3) derogation, all four conditions must hold, profiling of natural persons is an absolute bar, and a self-assessed non-high-risk system still has to be registered in the EU database in simplified form. Second, the Commission missed its February 2026 statutory deadline for the Article 6 classification guidelines, so authoritative worked examples are scarce and the reasoning you record now is the reasoning you will be defending.
It protects publishing, not deploying
Everything above reduces to one sentence. The Article 2 exemption attaches to the act of releasing a system under a free and open-source licence. It does not attach to the artefact and follow it wherever it goes.
The clearest demonstration is inside the text of the exemption itself. The first carve-out is not about the licence, it is about an act: the system being placed on the market or put into service as a high-risk system. When you take an openly licensed system and put it into service for an Annex III purpose inside your own organisation, you have performed that act, and the carve-out applies to you on its own terms. The licence under which somebody else published it is not a defence, because it was never addressed to your act in the first place.
So the practical question is never "is this model open source?" It is: which act did we perform, what does that act make us, and which of the four Article 2 conditions did it break. Answer those three in order and record the reasoning. If the answer is that you deployed rather than published, the exemption was never yours to rely on, and the transparency and high-risk analysis starts from zero.
If you have not run that analysis on a system you built on open weights, the free triage classifier walks the classification tests in order and names the article each answer rests on.