AI Act and open-weight models: what changes in 2026
The European AI Act enters its fully binding phase for general-purpose AI (GPAI) models in August 2025, and the first sanctions arrive in 2026. For open-weight models—Llama, Mistral, Qwen, DeepSeek, Gemma—the regulation provides a partial exemption, but it does not cover everything. This guide provides a practical breakdown of what applies to your company when you use or fine-tune an open-weight model, and what remains the model provider’s responsibility.
#Why this guide
Many companies have switched to open weights for the usual reasons: cost, latency, sovereignty, GDPR. The question that keeps coming up in 2026 is: if we download Llama 4 or Mistral Magistral to run it on our servers, who is responsible for the AI Act obligations? The provider? Us? Both?
The short answer: Meta or Mistral handle the GPAI (general-purpose AI) obligations on the provider side. But you, as the deployer—and especially if you fine-tune—take on a separate set of obligations. The ai act open-weight models compliance angle is therefore not binary: it's a shared responsibility.
#2026 schedule: what really applies
Deploy local AI at work: privacy, compliance, multi-user architecture, costs, the one-page memo for leadership.
- Lifetime online access
- PDF + files
- Lifetime updates
The AI Act entered into force in August 2024, but its implementation is staggered. Here's what matters in 2026 for open-weights use.
- February 2025
- Absolute prohibitions (social scoring, manipulation, unauthorized biometric identification). In effect.
- August 2025
- GPAI obligations applicable to providers of general-purpose models. This is what weighs on Meta, Mistral, Google, and others.
- August 2026
- Requirements for high-risk AI systems (Annex III): HR, credit scoring, critical infrastructure, justice. If your deployment falls into one of these categories, it applies to you.
- August 2027
- Extension to AI integrated into regulated products (Annex I: toys, medical devices, vehicles).
#The open-source GPAI exemption: what it covers
Article 53(2) of the AI Act provides an exemption for general-purpose models released under a free and open-source license that allows access, use, modification, and distribution. The text calls this the “free and open-source” regime.
For an open-weights model to qualify for the exemption, three conditions must be met:
- Accessible weights
- The model parameters are publicly published (Hugging Face, Ollama registry, etc.).
- Permissive license
- The license permits, at a minimum, use, modification, and redistribution. Apache 2.0, MIT, and most "open-weights" licenses qualify. The Llama license (community license with a 700M MAU threshold) is a borderline case that the Commission clarified favorably in 2025.
- Disclosed architecture and parameters
- Not just the weights: the model architecture must be publicly documented.
When these conditions are met, the model provider (Meta, Mistral, etc.) is exempt from two major obligations: (1) detailed technical documentation for the AI Office and (2) providing downstream deployers with a complete model card. But—and this is the often-overlooked catch—it still has two obligations that flow through to you.
#The obligations that still apply, even with open source
Here’s what the exemption does not cover and what applies to the model provider regardless—therefore indirectly to you through the value chain.
- Copyright compliance policy (Art. 53(1)(c))
- The provider must publish a policy compliant with Directive 2019/790 on copyright in the Digital Single Market, and in particular honor TDM (Text and Data Mining) opt-outs expressed by rights holders.
- Public summary of training data (art. 53(1)(d))
- A sufficiently detailed summary of the content used for training, for a model provided by the AI Office. This is the famous “training data summary” that Meta, Mistral, and OpenAI now publish.
#The "systemic risk" case: the exemption that disappears
Article 51 defines a special category: GPAI models with systemic risk. In practical terms, a model falls into this category if:
- Compute threshold
- More than 10^25 cumulative FLOPs for training. Llama 3.1 405B and GPT-4 surpass it; Llama 3 70B and most Mistral do not.
- Discretionary designation
- The AI Office may designate a model as systemic based on other criteria (impact on the internal market, capabilities, number of users).
#If you use an open-weight model as is
The most common case: you download Mistral Small 24B, Qwen 3.8 27B, or Gemma 4 12B through Ollama, and expose it to your coworkers or customers. You are a “deployer” under the regulation. Here's what you're responsible for.
- 01Identify the risk level of your use caseRead Annex III of the regulation. If you filter resumes, score candidates, make credit-granting decisions, or manage access to education or essential services, you are high risk—and the full list of obligations applies (risk management, data quality, traceability, human oversight, logging).
- 02Apply Article 50 on transparencyFor any conversational or content-generating system: inform the user that they are interacting with AI, and label generated content as such (text, image, audio, video). A clear disclaimer in the UI is sufficient for chat; visual and audio content must be technically labeled (watermark, C2PA).
- 03Set usage boundaries with an internal policyDocument which models are authorized, for what data, for which use cases, and with what human oversight. This is also your best defense in the event of a CNIL audit or an inspection by the national AI Act authority.
- 04Train your users (Art. 4)Article 4 requires sufficient AI literacy among people who use the system. A documented 1h session is generally considered sufficient for non-high-risk use; more is needed if you are in the high-risk category.
#If you fine-tune the model
As soon as you substantially modify the model (fine-tuning, distillation, or adding substantial LoRA adapters), you move from "deployer" to "provider of a derived GPAI model." Recital 109 of the regulation and the 2025 AI Office guidance clarified what "substantial" means:
- Indicative threshold
- Fine-tuning that represents more than one-third of the base model's initial training compute triggers derived-provider classification. Below that threshold, you generally remain a deployer.
- LoRA and lightweight adapters
- As long as you do not modify the base weights and the adapter is trained on little data (a few thousand examples), you remain in deployer territory.
- Full fine-tuning on a large corpus
- You become a provider. The obligations under Art. 53 (copyright policy + training summary) apply to your training layer.
#Documentation to produce in 2026
Whether you are a deployer or a derived provider, here are the documents that must exist in your files in 2026 (paper or digital, it makes no difference—the important thing is that they are up to date and accessible in case of an inspection).
- AI systems registry
- List of all deployed models, version, use case, assessed risk level, deployment date, internal owner.
- Impact assessment (DPIA + AI risk assessment)
- For every high-risk system or system processing sensitive personal data. The GDPR DPIA and AI Act assessment can be combined into a single document.
- Internal model sheet
- For every model used: provenance, license, download date, weight hash, quantization used, performance evaluated on your use cases, and known biases. Practical note: for a Ollama model, the blob’s sha256 hash is available via `ollama show`.
- Internal AI usage policy and charter
- Document signed by internal users: what is allowed, what is prohibited, which data may be submitted, and which may not.
- Incident log
- Any malfunction, serious bias identified, or inappropriate output. Used both for the AI Act (high-risk traceability) and to guide your improvements.
- If derived provider: training data summary
- Public summary of the data used for fine-tuning, in AI Office format. This document must be publishable.
#Express compliance checklist
Checklist before putting an open-weight model into production in 2026:
- Properly sourced model
- Downloaded from the official registry (verified HuggingFace org, registry Ollama), license read and archived.
- Evaluated use case
- Not on the list of prohibitions (Art. 5), documented risk level (Annex III).
- Transparency in place
- Visible AI disclaimer, watermark for image/audio generation, user training completed.
- Signed DPIA / AI assessment
- For any personal or high-risk processing.
- Training data (if fine-tuning)
- Copyright policy followed, TDM opt-outs honored, training summary prepared.
- Logging enabled
- Inference logs retained according to your statutory retention period (typically 6 months, longer for high-risk cases).
- Audit plan
- A designated representative capable of responding to a request from the national authority within the required timeframe (generally 15 days).
#Go further
Three related guides for deeper exploration: the local LLM and GDPR guide covers personal-data obligations alongside the AI Act; the small-business internal chatbot guide covers the practical setup of a compliant deployment from the start; and for regulated practices (law firms, healthcare), the French local LLM contract-analysis guide details an end-to-end high-risk use case.
Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.