EU AI Act open-source exemption guidance clarifies rules for self-hosted models
The European Commission published guidance on April 10 clarifying which open-weight AI models qualify for lighter regulatory treatment under the AI Act. The exemption applies to models released under approved open-source licenses that meet specific transparency requirements.
The European Commission published guidance on April 10 clarifying how the AI Act's open-source exemption works in practice. The guidance answers questions that developers and organizations across Europe have been asking since the Act was finalized.
The key clarification is that open-weight models released under approved open-source licenses qualify for lighter regulatory treatment when they meet specific transparency requirements. These requirements include publishing the training methodology, documenting the data sources, and providing model cards with performance characteristics and known limitations.
Models like Llama (Meta), Qwen (Alibaba), Mistral, Codestral, Gemma (Google), and OLMo (AI2) generally qualify under the exemption, assuming their release documentation meets the transparency bar. This matters because it means self-hosting these models carries a lighter compliance burden than using proprietary, closed-source models via API. The regulatory distinction between open and closed models is now formalized.
The guidance also addresses fine-tuned models, which is relevant for anyone customizing open-weight models for specific tasks. If you take an exempt base model and fine-tune it, the exemption can carry forward as long as your fine-tuning process and data are also documented. This is important for organizations that customize models for domain-specific work.
There are limits to the exemption. Models used in high-risk applications (medical diagnosis, legal decision-making, law enforcement, critical infrastructure) face additional requirements regardless of their license. And the exemption does not cover models above a certain compute threshold during training, though this threshold is set high enough that most self-hosted deployments are well below it.
For European builders running AI agents on their own infrastructure, this guidance provides regulatory clarity that has been missing. You can continue self-hosting open-weight models with confidence that the compliance requirements are manageable and well-defined.
The practical next step is to review your model deployments against the guidance. Make sure your documentation covers the training methodology, data sources, and performance characteristics for each model you run. This documentation is both a regulatory requirement and a good operational practice that helps with debugging and maintenance.