Intermediate 14 minCompliance

AI Act and open-weight models: what changes in 2026

The European AI Act enters its fully binding phase for general-purpose AI (GPAI) models in August 2025, and the first sanctions arrive in 2026. For open-weight models—Llama, Mistral, Qwen, DeepSeek, Gemma—the regulation provides a partial exemption, but it does not cover everything. This guide provides a practical breakdown of what applies to your company when you use or fine-tune an open-weight model, and what remains the model provider’s responsibility.

By Clara M.·Update 2026-08-27·Tested on Windows, macOS, and Linux

#Why this guide

Many companies have switched to open weights for the usual reasons: cost, latency, sovereignty, GDPR. The question that keeps coming up in 2026 is: if we download Llama 4 or Mistral Magistral to run it on our servers, who is responsible for the AI Act obligations? The provider? Us? Both?

The short answer: Meta or Mistral handle the GPAI (general-purpose AI) obligations on the provider side. But you, as the deployer—and especially if you fine-tune—take on a separate set of obligations. The ai act open-weight models compliance angle is therefore not binary: it's a shared responsibility.

i
Guide scope
This refers to the EU AI Act (Regulation 2024/1689), not the GDPR (which remains fully applicable in parallel) or the NIS2 Directive. If you process personal data, both regimes apply cumulatively.

#2026 schedule: what really applies

The AI at Work Kit

Deploy local AI at work: privacy, compliance, multi-user architecture, costs, the one-page memo for leadership.

  • Lifetime online access
  • PDF + files
  • Lifetime updates

The AI Act entered into force in August 2024, but its implementation is staggered. Here's what matters in 2026 for open-weights use.

February 2025
Absolute prohibitions (social scoring, manipulation, unauthorized biometric identification). In effect.
August 2025
GPAI obligations applicable to providers of general-purpose models. This is what weighs on Meta, Mistral, Google, and others.
August 2026
Requirements for high-risk AI systems (Annex III): HR, credit scoring, critical infrastructure, justice. If your deployment falls into one of these categories, it applies to you.
August 2027
Extension to AI integrated into regulated products (Annex I: toys, medical devices, vehicles).
!
2026 is not a blank year
Even if your use cases are not “high risk,” the transparency obligations (Article 50) for generated content and chatbots apply starting in August 2026. A customer support agent that does not say it is an AI already violates the regulation.

#The open-source GPAI exemption: what it covers

Article 53(2) of the AI Act provides an exemption for general-purpose models released under a free and open-source license that allows access, use, modification, and distribution. The text calls this the “free and open-source” regime.

For an open-weights model to qualify for the exemption, three conditions must be met:

Accessible weights
The model parameters are publicly published (Hugging Face, Ollama registry, etc.).
Permissive license
The license permits, at a minimum, use, modification, and redistribution. Apache 2.0, MIT, and most "open-weights" licenses qualify. The Llama license (community license with a 700M MAU threshold) is a borderline case that the Commission clarified favorably in 2025.
Disclosed architecture and parameters
Not just the weights: the model architecture must be publicly documented.

When these conditions are met, the model provider (Meta, Mistral, etc.) is exempt from two major obligations: (1) detailed technical documentation for the AI Office and (2) providing downstream deployers with a complete model card. But—and this is the often-overlooked catch—it still has two obligations that flow through to you.

#The obligations that still apply, even with open source

Here’s what the exemption does not cover and what applies to the model provider regardless—therefore indirectly to you through the value chain.

Copyright compliance policy (Art. 53(1)(c))
The provider must publish a policy compliant with Directive 2019/790 on copyright in the Digital Single Market, and in particular honor TDM (Text and Data Mining) opt-outs expressed by rights holders.
Public summary of training data (art. 53(1)(d))
A sufficiently detailed summary of the content used for training, for a model provided by the AI Office. This is the famous “training data summary” that Meta, Mistral, and OpenAI now publish.
→
Why this matters to you
If you fine-tune an open-weight model on your own data, you yourself become a provider of a derived GPAI model. These two obligations pass on to you for the portion of the training you added.

#The "systemic risk" case: the exemption that disappears

Article 51 defines a special category: GPAI models with systemic risk. In practical terms, a model falls into this category if:

Compute threshold
More than 10^25 cumulative FLOPs for training. Llama 3.1 405B and GPT-4 surpass it; Llama 3 70B and most Mistral do not.
Discretionary designation
The AI Office may designate a model as systemic based on other criteria (impact on the internal market, capabilities, number of users).
!
Practical consequence
For an open-weights model classified as systemic risk, the open-source exemption disappears. The provider must then produce the risk assessment, incident monitoring, and model cybersecurity documentation (Art. 55). In 2026, this effectively concerns Llama 3.1 405B, possibly Llama 4 Behemoth and DeepSeek V3.2. If you fine-tune one of these models at scale (>1/3 of the original compute), you inherit the obligations.

#If you use an open-weight model as is

The most common case: you download Mistral Small 24B, Qwen 3.8 27B, or Gemma 4 12B through Ollama, and expose it to your coworkers or customers. You are a “deployer” under the regulation. Here's what you're responsible for.

  1. 01
    Identify the risk level of your use case
    Read Annex III of the regulation. If you filter resumes, score candidates, make credit-granting decisions, or manage access to education or essential services, you are high risk—and the full list of obligations applies (risk management, data quality, traceability, human oversight, logging).
  2. 02
    Apply Article 50 on transparency
    For any conversational or content-generating system: inform the user that they are interacting with AI, and label generated content as such (text, image, audio, video). A clear disclaimer in the UI is sufficient for chat; visual and audio content must be technically labeled (watermark, C2PA).
  3. 03
    Set usage boundaries with an internal policy
    Document which models are authorized, for what data, for which use cases, and with what human oversight. This is also your best defense in the event of a CNIL audit or an inspection by the national AI Act authority.
  4. 04
    Train your users (Art. 4)
    Article 4 requires sufficient AI literacy among people who use the system. A documented 1h session is generally considered sufficient for non-high-risk use; more is needed if you are in the high-risk category.

#If you fine-tune the model

As soon as you substantially modify the model (fine-tuning, distillation, or adding substantial LoRA adapters), you move from "deployer" to "provider of a derived GPAI model." Recital 109 of the regulation and the 2025 AI Office guidance clarified what "substantial" means:

Indicative threshold
Fine-tuning that represents more than one-third of the base model's initial training compute triggers derived-provider classification. Below that threshold, you generally remain a deployer.
LoRA and lightweight adapters
As long as you do not modify the base weights and the adapter is trained on little data (a few thousand examples), you remain in deployer territory.
Full fine-tuning on a large corpus
You become a provider. The obligations under Art. 53 (copyright policy + training summary) apply to your training layer.
→
The benefit of staying open source
If you publish your fine-tuned weights under a permissive license with documented architecture, you also benefit from the open-source exemption for technical documentation and the model card. That is another argument for publishing fine-tunes rather than keeping them closed.

#Documentation to produce in 2026

Whether you are a deployer or a derived provider, here are the documents that must exist in your files in 2026 (paper or digital, it makes no difference—the important thing is that they are up to date and accessible in case of an inspection).

AI systems registry
List of all deployed models, version, use case, assessed risk level, deployment date, internal owner.
Impact assessment (DPIA + AI risk assessment)
For every high-risk system or system processing sensitive personal data. The GDPR DPIA and AI Act assessment can be combined into a single document.
Internal model sheet
For every model used: provenance, license, download date, weight hash, quantization used, performance evaluated on your use cases, and known biases. Practical note: for a Ollama model, the blob’s sha256 hash is available via `ollama show`.
Internal AI usage policy and charter
Document signed by internal users: what is allowed, what is prohibited, which data may be submitted, and which may not.
Incident log
Any malfunction, serious bias identified, or inappropriate output. Used both for the AI Act (high-risk traceability) and to guide your improvements.
If derived provider: training data summary
Public summary of the data used for fine-tuning, in AI Office format. This document must be publishable.
Verify the hash of a Ollama model (proof of origin)
# Récupère le hash du modèle pour preuve d'audit
ollama show qwen3.8:27b --modelfile

# Localiser le blob et vérifier son intégrité
ls -la ~/.ollama/models/blobs/
sha256sum ~/.ollama/models/blobs/sha256-*

#Express compliance checklist

Checklist before putting an open-weight model into production in 2026:

Properly sourced model
Downloaded from the official registry (verified HuggingFace org, registry Ollama), license read and archived.
Evaluated use case
Not on the list of prohibitions (Art. 5), documented risk level (Annex III).
Transparency in place
Visible AI disclaimer, watermark for image/audio generation, user training completed.
Signed DPIA / AI assessment
For any personal or high-risk processing.
Training data (if fine-tuning)
Copyright policy followed, TDM opt-outs honored, training summary prepared.
Logging enabled
Inference logs retained according to your statutory retention period (typically 6 months, longer for high-risk cases).
Audit plan
A designated representative capable of responding to a request from the national authority within the required timeframe (generally 15 days).
i
French authority
In France, oversight of the AI Act will be coordinated by the CNIL (for the personal-data dimension) and the DGCCRF/ANSSI, depending on the sector. The final designation decree is expected sometime in 2026. In the meantime, the CNIL already accepts AI Act questions through its AI help desk.

#Go further

Three related guides for deeper exploration: the local LLM and GDPR guide covers personal-data obligations alongside the AI Act; the small-business internal chatbot guide covers the practical setup of a compliant deployment from the start; and for regulated practices (law firms, healthcare), the French local LLM contract-analysis guide details an end-to-end high-risk use case.

Did this guide help you?

Feedback, an error, or a clarification? Let us know—it improves the guide for everyone.