The AI Act does include an open source exemption, but it protects model providers, not the companies using those models. If your SME runs an open model in-house, that exemption changes almost nothing about your obligations.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
The AI Act does include an exemption for open source AI, but it protects model providers, not the companies using those models. If your SME runs an open model in-house or calls it through an API, that exemption changes almost nothing about your obligations. Here is where the line actually falls.
Regulation EU 2024/1689 places AI systems released under free and open source licences outside its scope, with three major carve-outs. Article 2(12) restricts the exemption to systems that are not placed on the market as high-risk systems, do not fall under the prohibited practices of Article 5, and are not subject to the transparency obligations of Article 50.
Put differently, the exemption disappears the moment the system does something sensitive. An open source model used to screen job applications is still a high-risk system under Annex III: the licence does not change the classification. An open source conversational agent facing your customers still has to disclose that it is an AI.
This is the first misreading that shows up in audits: executives convinced that picking an open model takes them out of the regulation. The test the legislator chose is not the licence, it is the use case. For the broader picture, who the AI Act applies to covers the scope, and the AI Act compliance guide for SMEs walks through the full chain of obligations.
The open source exemption is written for model providers, meaning the organisations that develop and release a model. An SME that installs or calls that model is a deployer, and the deployer regime carries no open source exemption at all.
The distinction shapes everything downstream:
In practice, if you run an open model on a server rented from a European host to summarise your meeting notes, you are not a provider. No licence-based exemption applies to you, and you remain bound by the AI literacy duty in Article 4, by the GDPR, and by transparency rules whenever the system interacts with people.
Plenty of models marketed as open source publish only their weights, under a licence that restricts use. In its guidelines on general-purpose AI models published on 18 July 2025, the European Commission states that the licence must allow access, use, modification and distribution of the model, and that the original provider must not use its intellectual property rights to restrict use or charge for it.
| Situation | Weights published | Usage restrictions | Reading against the exemption |
|---|---|---|---|
| Model under a permissive licence such as Apache 2.0 | Yes | No commercial restriction | Meets the licence criterion on its face |
| Model under a vendor-specific community licence | Yes | User thresholds, acceptable use policy | Needs case-by-case assessment, the open source label is not enough |
| Proprietary model accessed through an API | No | Commercial contract | Outside the exemption |
This is not an academic point. If you build a product on a model whose licence carries commercial restrictions, you inherit those restrictions, and you cannot claim an open source status the model does not have under the regulation. The practical rule fits on one line: read the licence, not the marketing page. See also the definitions of open source and of an LLM.
For general-purpose AI models, the Article 53 exemption is partial and conditional. It relieves the provider of two obligations only: drawing up the technical documentation for the model, and supplying certain information to downstream system providers. Four conditions must all be met:
Two obligations survive in every case: putting in place a policy to comply with Union copyright law, and publishing a sufficiently detailed summary of the content used for training.
On monetisation, the Commission takes a broad view. Charging for access to an essential feature, or to security patches, is enough to break the exemption. A free-on-the-surface package with mandatory paid support does not qualify.
If you fine-tune an open source model and place the result on the market under your own name or brand, you may become a provider under the regulation, with the obligations that follow.
The typical case: a services firm runs a fine-tuning pass on its own business data, then sells the resulting assistant to its clients. That is no longer internal use. Depending on the intended purpose given to the system, the company can shift into the provider regime, and if the use case falls under Annex III, into the high-risk regime described in Article 6.
The habit worth building before any project of this kind: write down in plain terms who places the system on the market, under which brand, and for which declared purpose. Five lines of classification save months of internal arbitration. The method is set out in mapping your AI systems, and the financial consequences of getting the classification wrong are quantified in AI Act sanctions.
The Digital Omnibus package pushes the high-risk obligations to 2 December 2027 for stand-alone Annex III systems, and to 2 August 2028 for AI embedded in already regulated products. Article 4 on AI literacy and Article 50 on transparency are not deferred.
For an open source project, that means more room on the heavy documentation work, but no reprieve on the two duties that hit SMEs hardest day to day: training the people who use AI, and telling their counterparts that they are dealing with a machine. The full AI Act timeline lists every applicable date.
Running an open model on European infrastructure settles much of the data transfer question, not the AI Act compliance question. The two texts pursue different aims, as the AI Act vs GDPR comparison explains.
Self-hosting gives you control over where processing happens, no data sent to a third party outside the Union, and fine-grained access logging. It does not give you a waiver on training, on transparency, or on risk classification. Be wary too of the hosted in Europe therefore sovereign shortcut: a cloud provider subject to a third-country legal regime can remain subject to it even when the servers sit in Europe, a point to settle with your legal counsel before choosing. See also the GDPR entry and the article on AI Act conformity assessment.
At GrowthPerf, a Qualiopi-certified training provider, we treat the open source question as a question of use, not of licence. That translates into three deliverables: a map of the AI systems actually in use across the company, including tools installed by teams without approval, a provider-or-deployer classification for each system, and team training that satisfies the Article 4 duty.
Our AI awareness and operational AI programmes are eligible for French OPCO funding. If you would rather move on your own, the GrowthPerf newsletter covers regulatory developments and concrete SME use cases every week. The AI Act guide for SMEs remains the place to start.
Is an open source model exempt from the AI Act? No, not as such. The Article 2(12) exemption falls away as soon as the system is placed on the market as high-risk, falls under the prohibited practices of Article 5, or comes within the transparency obligations of Article 50. Use decides, not the licence.
My SME uses an open source model internally. Am I concerned? Yes, as a deployer. You need to ensure a sufficient level of AI literacy among the people using the system, comply with the GDPR on the data processed, and inform people when the system interacts with them.
What is the difference between open source and open weights? An open weights model publishes its parameters, but its licence may restrict use, modification or redistribution. An open source model in the sense of the regulation must allow access, use, modification and distribution, without the provider using its intellectual property rights to restrict or charge for use.
Does an open source model with systemic risk keep the exemption? No. Once a general-purpose model is classified as presenting systemic risk, the exemption no longer applies, whatever its licence.
Can I charge for a service built on an open source model? Yes. The non-monetisation condition applies to the model released by its provider, not to the services you build on top. That said, check the model licence, which may carry its own commercial restrictions.
Does the high-risk deferral leave me free until 2027? No. The deferral covers the obligations specific to high-risk systems. The Article 4 AI literacy duty and the Article 50 transparency obligations continue to apply on the original schedule.
Where should I start from scratch? List the AI systems in use across the company, including free tools installed by teams, then classify each one: provider or deployer, sensitive use or not. That map drives everything else in the compliance plan.