ISHIGHRISK AI
Analysis

The open-source exemptions, and what they do not cover

Free and open-source AI gets two narrow exemptions under Articles 2 and 53. Neither survives high-risk classification, Article 50, or systemic-risk scale.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

There are two open-source exemptions and they do different work. Article 2 takes AI systems released under a free and open-source licence outside the Act, but it collapses the moment the system is placed on the market or put into service as high-risk, falls under Article 5 or Article 50, or is monetised. Article 53(2) lifts the Annex XI and Annex XII documentation duties for open-source GPAI models while leaving the copyright policy and the public training-content summary standing, and it gives a systemic-risk model nothing at all. Neither exemption travels downstream: build a product on an open model published by somebody else and you are the provider of that system, with Article 25 available to make you the provider of a high-risk one.

Two exemptions, not one

The Act carries two open-source exemptions. They sit in different chapters, they exempt different things, and conflating them is the most reliable way to reach the wrong answer.

Art 2 works at system level. It takes AI systems released under free and open-source licences outside the scope of the Act, subject to carve-outs that account for most of the cases a commercial team cares about.

Art 53(2) works at model level. It does not take an open general-purpose AI model outside the Act at all. It removes part of the documentation burden in Article 53(1) and leaves the rest in place.

The two do not stack. Article 2 relief for a system does nothing for a model you publish, and Article 53(2) relief on a model does nothing for a system somebody builds on it. A team that publishes weights and also ships a product on those weights is standing in both regimes at once, in opposite directions.

Article 2: the system-level exemption

Article 2 provides that the Act does not apply to AI systems released under free and open-source licences. Four things defeat it, and any one of them on its own is enough.

The system is placed on the market or put into service as high-risk. This is the largest hole. Classification under Article 6 runs on what the system does, through the Annex I product safety route or the eight Annex III use cases, and the licence is not an input to that test. An openly licensed CV screener is a high-risk employment system on exactly the same terms as a proprietary one. The application dates give time, not relief: standalone Annex III obligations apply from 2 December 2027 and AI embedded in Annex I products from 2 August 2028. What the classification tests actually ask is set out on the high-risk classification page.

The system falls under Article 5. The eight prohibited practices have applied since 2 February 2025, and the Digital Omnibus, Regulation (EU) 2026/1744, adds a ninth from 2 December 2026 covering AI that generates child sexual abuse material or non-consensual intimate imagery, binding providers and deployers alike. Article 5 breaches sit in the top penalty tier under Article 99: 35,000,000 euro or 7 percent of total worldwide annual turnover, whichever is higher.

The system falls under Article 50. For open releases this is the carve-out that bites first, because so many of them are generative. Article 50(1), 50(3) and 50(4) apply on 2 August 2026, and the 50(2) machine-readable marking duty applies on the same date for systems placed on the market on or after it.

2 Aug 2026Article 50(1), 50(3) and 50(4) apply. Article 50(2) marking applies to generative systems placed on the market on or after this date. AI Office enforcement begins.
2 Dec 2026Article 50(2) marking applies to generative systems placed on the EU market before 2 August 2026, a transitional period of four months under recital 38 of Regulation (EU) 2026/1744.

The system is monetised. Article 2 states that the exemption does not apply where the system is monetised. Read that as the condition that fails quietly: paid hosting of the model you published, a commercial licence tier, a paid support contract wrapped around the release. Where a revenue line is attached to the thing you gave away, plan on the exemption being unavailable and satisfy the underlying obligations instead.

One further point that catches non-EU publishers. Article 2 reaches providers placing systems on the Union market wherever they are established, and providers and deployers in third countries where the output produced by the system is used in the Union. A repository is not a jurisdiction.

Article 53(2): the model-level exemption

The Article 53 baseline for a provider of a general-purpose AI model is four duties, and they have applied since 2 August 2025: Annex XI technical documentation, Annex XII information for downstream providers, a copyright policy, and a public summary of training content. Article 53(2) removes the first two for models released under a free and open-source licence. It removes nothing where the model is a systemic-risk model.

Article 53 dutyOpen-source model, no systemic riskSystemic-risk model
Annex XI technical documentationLifted by Art 53(2)Owed in full
Annex XII information for downstream providersLifted by Art 53(2)Owed in full
Copyright policyOwedOwed
Public summary of training contentOwedOwed
Article 55 systemic-risk dutiesNot engagedOwed in full

The two duties that survive are the two that are hardest to discharge quietly, and that is not an accident of drafting. A copyright policy is a statement about how the training corpus was assembled. A public summary of training content is, by construction, published. Neither can be satisfied by a document you keep in a drawer and produce on request, which is exactly what Annex XI and Annex XII allow.

Systemic risk is presumed where cumulative training compute exceeds 10^25 FLOP. Above that line Article 55 adds evaluation, adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity protection, and Article 53(2) gives back nothing whatsoever. An open frontier model is the most heavily regulated thing in this article, not the least. The full obligation map sits on the GPAI obligations page. The AI Office takes up enforcement on 2 August 2026.

What counts as a free and open-source licence

Both exemptions turn on the same phrase, and the phrase is doing a lot of work. Note first what it is not: it is a licence condition, not a distribution condition. Publishing weights for anyone to download is not the test. The test is the terms under which you published them.

The two ends are clear enough. A licence in the familiar permissive or copyleft tradition, with no fee, no restriction on who may use the software and no restriction on the field of use, sits inside the phrase on any reading. At the other end, weights released only under a negotiated commercial agreement, or behind a paywall, are not released under a free and open-source licence in any sense the words will bear.

The contested middle is the community and responsible-use licence: weights and code published openly for anyone to download, but with an acceptable-use annex banning categories of application, and sometimes a revenue or user-count threshold above which a separate commercial licence is required. These are common, and they are genuinely unresolved. This article is not going to invent a test for them, because there is no authoritative worked example to point at and a made-up one would be worse than none.

What can be said usefully is how to hold the risk. If your licence restricts field of use, or converts to a paid licence above a threshold, treat the exemption as unavailable for planning purposes and build the position so that it does not depend on the answer. That is cheap for Article 53(2), where the surviving duties are the expensive ones anyway. It is expensive for Article 2, which is a reason to check whether the Article 5, Article 50 and high-risk carve-outs had already taken you out of the exemption before the licence question was ever reached. In most commercial cases they had.

What you did, versus what you owe

The exemptions do not describe a kind of organisation. They describe an act. Find the row that matches the act.

What you did with the open model or systemWhat that makes youWhat you owe
Published weights under a free and open-source licence, no fee, below the systemic-risk thresholdProvider of a GPAI modelCopyright policy and public training-content summary. Annex XI and Annex XII lifted by Art 53(2).
Published the same model above 10^25 FLOP cumulative training computeProvider of a GPAI model with systemic riskAll four Article 53(1) duties plus the Article 55 set. Art 53(2) gives nothing.
Published an open-source AI system that is not generative, not prohibited and not high-riskOutside the Act under Art 2Nothing, for as long as all four Article 2 conditions hold.
Published an open-source system that generates text, image, audio or videoProvider under Article 5050(1) and 50(2) as applicable, from 2 August 2026. The licence is irrelevant.
Published an open-source system intended for one of the eight Annex III use casesProvider of a high-risk systemArticles 9 to 15, Article 43 conformity assessment and Article 49 registration, from 2 December 2027.
Charged for access, hosting or a commercial licence tier around the releaseMonetised, so outside Art 2Whatever the system's own tier carries, assessed as if the exemption did not exist.
Downloaded someone else's open model and shipped a product on it under your nameProvider of that systemEverything the system's tier carries, transparency included. Their licence does not cover you.
Fine-tuned or repurposed an open model for an Annex III useProvider of a high-risk system under Art 25The full Article 16 set, plus the Article 6(4) classification record before market placement.

Building on an open model makes you the provider

This is the part that matters most in practice, and it has nothing to do with licensing at all. The provider is the party that develops a system and places it on the market or puts it into service under its own name or trademark. Take an open model, wrap it in a product, ship it: you are the provider of that system. The upstream publisher is the provider of the model, and the two roles carry different obligation sets under different articles.

Article 25 then adds a second route, and its third limb is the one written for exactly this situation. Modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk makes you a provider of a high-risk system with the full Article 16 obligation set. Putting your name or trademark on a high-risk system does the same, as does a substantial modification that keeps it high-risk. The three triggers, and the way they travel through a supply chain, are worked through on the provider and deployer roles page.

Two practical consequences follow. First, if your product could be high-risk, the Article 6(4) documentation has to exist before the system is placed on the market, not after a regulator asks. Where you rely on the Article 6(3) derogation, all four conditions must hold, profiling of natural persons is an absolute bar, and a self-assessed non-high-risk system still has to be registered in the EU database in simplified form. Second, the Commission missed its February 2026 statutory deadline for the Article 6 classification guidelines, so authoritative worked examples are scarce and the reasoning you record now is the reasoning you will be defending.

It protects publishing, not deploying

Everything above reduces to one sentence. The Article 2 exemption attaches to the act of releasing a system under a free and open-source licence. It does not attach to the artefact and follow it wherever it goes.

The clearest demonstration is inside the text of the exemption itself. The first carve-out is not about the licence, it is about an act: the system being placed on the market or put into service as a high-risk system. When you take an openly licensed system and put it into service for an Annex III purpose inside your own organisation, you have performed that act, and the carve-out applies to you on its own terms. The licence under which somebody else published it is not a defence, because it was never addressed to your act in the first place.

So the practical question is never "is this model open source?" It is: which act did we perform, what does that act make us, and which of the four Article 2 conditions did it break. Answer those three in order and record the reasoning. If the answer is that you deployed rather than published, the exemption was never yours to rely on, and the transparency and high-risk analysis starts from zero.

If you have not run that analysis on a system you built on open weights, the free triage classifier walks the classification tests in order and names the article each answer rests on.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is open-source AI exempt from the EU AI Act?

Partly, and less often than the phrase suggests. Article 2 provides that the Act does not apply to AI systems released under free and open-source licences, but the exemption falls away if the system is placed on the market or put into service as a high-risk system, if it falls under Article 5 or Article 50, or if it is monetised. Separately, Article 53(2) relieves providers of open-source general-purpose AI models of part of the Article 53(1) documentation burden. Neither exemption removes a system from the Act once one of those conditions is met.

Does the open-source exemption cover high-risk AI?

No. The Article 2 exemption expressly does not apply where the system is placed on the market or put into service as a high-risk system, so an openly licensed system built for one of the eight Annex III use cases carries the full high-risk obligation set. The licence changes nothing about the Article 6 classification. For standalone Annex III systems those obligations apply from 2 December 2027, and for AI embedded in Annex I products from 2 August 2028.

Do open-source GPAI models still need a training data summary?

Yes. Article 53(2) lifts the Annex XI technical documentation and the Annex XII information for downstream providers, but the copyright policy and the public summary of training content survive the exemption. Both have applied since 2 August 2025. A model released under a free and open-source licence therefore still has to publish a training-content summary and operate a copyright policy, and a model with systemic risk gets no relief at all.

Does fine-tuning an open-source model make me the provider?

It can, and the question that matters is what you did with it rather than who trained it. If you place a system built on the model on the market or put it into service under your own name or trademark, you are the provider of that system and you owe whatever its tier carries. Article 25 goes further: modifying the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk makes you the provider of a high-risk system, with the full Article 16 obligation set. The upstream publisher's licence does not travel with the model to shield you.

Does charging for an open-source AI model kill the exemption?

For the Article 2 system-level exemption, yes. Article 2 states that the exemption does not apply where the system is monetised, so any revenue arrangement attached to the release puts it out of reach. Treat paid hosting, a paid commercial licence tier and paid support around the release as reasons to assume the exemption is gone and to work from the underlying obligations instead. Article 53(2) is drafted around the licence rather than around monetisation, so the two conditions are not interchangeable.

Do open-source generative AI systems have to be watermarked?

Yes, because Article 50 is one of the express carve-outs from the Article 2 exemption. Providers of systems generating synthetic audio, image, video or text must mark the output in a machine-readable format detectable as artificially generated or manipulated. That duty applies on 2 August 2026 for systems placed on the market on or after that date, and on 2 December 2026 for generative systems already placed on the EU market before 2 August 2026. An open licence has no effect on either date.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.