The EU AI Act and local, open models
What the EU AI Act actually means if you run open models on your own hardware: whether you are a provider or a deployer, the open-source carve-outs, and their limits.
This guide is general information, not legal advice. How the Act applies depends on your specific role, model, and use. For decisions that carry legal or financial weight, read the official sources and consult a qualified professional. The European Commission has published guidelines for GPAI providers that are the authoritative reference here.
What you’ll learn
How the EU AI Act’s obligations fall on someone running open models locally: whether you count as a provider or a deployer, what the open-source exemptions cover, and, importantly, what they do not.
Provider or deployer? The question that decides most of it
The Act treats the organisation that develops or places an AI system or model on the market (a provider) very differently from the one that merely uses it (a deployer). For most people running open models locally, this distinction is reassuring.
If you download an open model like Qwen3 8B or Llama 3.3 70B and run it, you are generally a deployer, not the provider of that model. The provider is whoever placed the model on the market, the lab that released it. The heavy general-purpose-model obligations, technical documentation, copyright policy, training-data summary, sit with them, not with you.
Where it gets more involved is if you substantially modify a model or place your own version on the market. Significant fine-tuning and distribution can, in some circumstances, make you a provider of a general-purpose model in your own right, with the obligations that brings. Running a model internally is very different from releasing a modified one to the world.
The open-source carve-outs, and their limits
The Act gives providers of models released under a free and open-source licence some relief, but it is partial, and the limits matter.
Open-source general-purpose models that do not carry systemic risk are exempt from certain obligations, notably drawing up and maintaining detailed technical documentation, and providing information to downstream integrators.
However, even open-source providers are not exempt from two obligations that are often misunderstood as covered:
- A policy to comply with EU copyright law, applied across the model’s life cycle.
- A public summary of the training data used for the model.
And the exemption falls away entirely for models judged to carry systemic risk, the most capable models, which face the full set of obligations regardless of licence. So “open source” reduces the burden on a model provider; it does not remove it.
Obligations that can apply to you as a deployer
Being a deployer rather than a provider does not mean no obligations at all. Two areas are worth watching:
- Transparency. If you use AI to interact with people or to generate content, transparency duties can apply: telling users they are dealing with an AI, and labelling AI-generated or manipulated content such as deepfakes. These apply to how you use the model, wherever it runs.
- High-risk use. If you deploy a model in a high-risk context, screening job applicants, say, or making decisions about access to essential services, you take on deployer obligations for high-risk systems. This is driven by the use case, not by whether the model is open or local. A permissively licensed model running on your own server in a high-risk use is still a high-risk use.
The practical picture
For most people and small teams running open models locally for internal or personal purposes, the direct regulatory burden under the Act is currently light: you are a deployer, using models whose providers carry the model-level obligations, and you are not in a high-risk use case. That can change quickly if you start making consequential decisions about people with the model, generating content for the public, or distributing your own modified models. The moment your use touches those areas, the obligations follow, local and open or not.
What can go wrong
- Assuming open source means exempt. Open-source providers still owe copyright and training-data-summary duties, and systemic-risk models get no exemption at all.
- Overlooking the use case. Regulation attaches to what you do with a model. Deploying any model in a high-risk use brings high-risk obligations.
- Becoming a provider without realising. Heavily modifying and distributing a model can shift you from deployer to provider. If you plan to release fine-tunes, take advice first.
Next steps
Revisit the EU AI Act explained for the overall structure, and why local AI for data protection for how this sits alongside your GDPR obligations. This is the first jurisdiction we have covered in depth; others will follow as their AI-specific rules mature.