JournalAI Policy

Field guide / 6

Open weights do not erase the EU AI Act's training-summary duty

EU enforcement now reaches general-purpose AI providers, while the open-source exemption leaves copyright and training-content duties in place.

Sep 7, 20266By ISH Team
Open weights do not erase the EU AI Act's training-summary duty
Advertisement

Open weights do not erase the EU AI Act's training-summary duty

Publishing model weights is a meaningful act of transparency. Under the EU AI Act, however, it is not the same thing as disclosing what went into training the model.

That gap matters because the Act gives certain general-purpose AI models released under free and open-source licences a narrower compliance route, not a blanket exemption. Two duties remain: the provider needs a policy for complying with EU copyright law, and it must publish a summary of the content used for training. If the model presents systemic risk, the open-source exemption disappears altogether.

These are live obligations. They began applying on August 2, 2025, and the European Commission's enforcement powers began applying on August 2, 2026. A permissive licence, a downloadable checkpoint, and a detailed README may answer important questions. They do not answer every question the law asks.

Start with the model, the provider, and the route to market

The Commission's GPAI guidelines give teams an indicative technical test. A model may count as general purpose if training used more than 10^23 floating-point operations and the model can generate language, text-to-image, or text-to-video output. This is not a hard automatic threshold. A model above it may not be general enough, while one below it may still qualify if it competently performs a wide range of tasks.

The next question is who the provider is. An organization becomes a provider when it develops, or has developed, a qualifying model and places it on the EU market under its own name or trademark. The market route can be an API, a download, a cloud service, a product integration, or internal use essential to a service offered to third parties or affecting people in the EU. A provider does not need to be based in the EU to fall within scope.

Nor does every fine-tune create a new provider. In its questions and answers, the Commission uses more than one-third of the original model's training compute as an indicative threshold for a modification significant enough to create provider responsibilities. Where that happens, the expected documentation covers the modification and its new training data. The modifier is not expected to reconstruct the original provider's full development history.

These guidelines describe how the Commission intends to enforce the rules, but they are not legally binding. The Court of Justice of the European Union has the final authority to interpret the law. A team therefore needs a case-specific scope record, not a FLOP threshold turned into a yes-or-no automation.

The exemption is real, but narrow

Article 53 can remove three duties for a qualifying open-source GPAI model that does not present systemic risk. Its provider may be exempt from maintaining technical documentation for authorities, giving model documentation to downstream system providers, and appointing an authorized representative in the EU.

That route has precise entry conditions. The licence must permit access, use, modification, and distribution without monetisation. The provider must publicly release the parameters, including weights, plus information about the architecture and use of the model. A hosted API described as open, or a research paper without model access, does not meet that test.

Even a release that does qualify still needs the Article 53 copyright policy. The provider must have a policy for identifying and respecting rights reservations under EU copyright law. It also needs the public training-content summary.

The Commission's training summary template is mandatory, including for free and open-source models. When a downstream modifier becomes the provider of a new GPAI model, its summary needs to cover only the training content used for that modification.

Open weights let researchers inspect parameters and run independent tests. They do not identify the web crawls, licensed collections, synthetic corpora, or curated datasets that shaped those parameters. Model access and training-content disclosure answer different questions, and the Act treats them as separate obligations.

Systemic risk changes the whole calculation

The consolidated AI Act presumes that a GPAI model presents systemic risk when cumulative training compute exceeds 10^25 floating-point operations. A provider can argue against that classification. The Commission can also designate a model below the threshold based on its capabilities or impact.

Once a model is classified as presenting systemic risk, an open release no longer waives the Article 53 documentation requirements. Article 55 also brings duties for model evaluation, systemic-risk assessment and mitigation, serious-incident reporting, and cybersecurity. Providers must notify the Commission when the systemic-risk condition has been met or is expected to be met.

This does not make openness the problem. It reflects a property of weight releases: safeguards added to a hosted product can be changed centrally, while published weights cannot be recalled in the same way. The higher-risk duties follow the model's classification rather than its licence.

Enforcement has an intake path now

The AI Office can request information, conduct model evaluations, and seek measures from GPAI providers. The Commission's enforcement framework also gives downstream providers a complaints channel when they integrate another provider's GPAI model.

That channel turns missing documentation into more than a difficult vendor conversation. If a system provider cannot obtain the information needed to understand a model's capabilities, limits, or compliance position, it can take the issue to the AI Office.

Article 101 permits fines for intentional or negligent breaches of GPAI obligations of up to EUR 15 million or 3% of the preceding financial year's worldwide annual turnover, whichever is higher. The law requires proportionality and gives the provider procedural rights, including an opportunity to respond before a decision.

Models placed on the market before August 2, 2025 must comply by August 2, 2027. That extension does not postpone the general enforcement start for newer releases.

What a release team should keep on file

Before publishing a checkpoint or offering an API in the EU, write down the scope analysis. Record training compute, modalities, generality, provider identity, market route, release date, and any fine-tuning compute. If the release relies on the open-source exemption, preserve the exact licence and the public locations of the weights, architecture information, and usage information.

Make the two surviving duties part of the release checklist. Name owners for the copyright policy and the mandatory training-content summary. Maintain source inventories, dataset categories, collection periods, and modification data in a form that can populate the Commission template. If the model may cross the systemic-risk line, begin notification and evaluation work before release rather than after a regulator asks.

Our Article 50 guide deals with disclosures to people interacting with AI systems and generated content. The data-worker provenance article examines the people who often disappear from dataset records. GPAI provider duties sit earlier in the chain. They concern the model itself, its training sources, and the information downstream builders need.

The practical rule is simple: a public checkpoint is not a public account of its training material. For a model release reaching the EU, the copyright policy and training-content summary belong beside the weights, not in a backlog for later.

#EU AI Act#open-weight models#GPAI#training data#AI regulation
Advertisement

Keep reading

Related stories

Browse the archive