Jump to

“It’s Open Source” Is Not a Compliance Strategy: What the AI Act’s Open-Source Exemption Actually Covers

“It’s Open Source” Is Not a Compliance Strategy: What the AI Act’s Open-Source Exemption Actually Covers

“We use an open-source model, so the AI Act doesn’t apply to us.” We hear a version of this sentence in half of our AI diligence calls, and it is wrong in both directions: the exemption is narrower than founders think, and it protects the model publisher, not the company shipping a product on top.

What the open-source exemption actually says

The AI Act carves out AI released under free and open-source licences from parts of the regulation, but with hard edges. The carve-out does not apply where the system is a prohibited practice, qualifies as high-risk, or falls under Article 50 transparency duties. For GPAI models, open-weight publishers escape some documentation duties only if the model is genuinely open (parameters, architecture and usage information publicly available) and not monetised; and even then, models with systemic risk get no exemption at all. Translation: the exemption mostly relieves people who publish models, not companies that deploy them.

“Open” licences that are not open

Most popular “open” models ship under bespoke licences with acceptable-use restrictions and commercial conditions, which is exactly why regulators and lawyers refuse to treat them as free and open-source in the statutory sense. Before relying on the label, read three clauses: the acceptable-use policy (does your use case live inside it?), redistribution and derivative terms (can you ship a fine-tuned variant? see fine-tuning), and the indemnity vacuum; community licences give you nobody to sue when the model misbehaves, which shifts the whole risk onto your own product insurance and contracts.

Your obligations don’t shrink; your control grows

Running open weights on your own infrastructure genuinely improves the data-protection posture: no prompts leave your perimeter, no cross-border transfer machinery, no vendor telemetry. But every product-level duty; transparency notices, risk classification, incident response, KVKK bases; lands on you exactly as it would with a closed API. The honest framing for a Turkish startup: open weights trade vendor risk for operational responsibility, and the AI Act charges the same toll at the product gate either way.

Licence families and what you may rely on

Family Examples AI Act open-source treatment Commercial reality
True FOSS licences Apache-2.0, MIT-licensed weights Exemption can apply at the model layer (unless systemic risk / monetised) No indemnity, no support; risk rests with you
Community licences Acceptable-use restricted “open-weight” releases Usually NOT free and open-source in the statutory sense Contract restrictions bind your product roadmap
API terms Hosted closed models Exemption irrelevant Negotiable enterprise terms, indemnities available

The provider-drift check, in four questions

Whether you have drifted from deployer to provider is answerable with four questions applied honestly. Did you change the model’s intended purpose as documented by the publisher? Did you fine-tune in a way that materially changes capabilities or risk profile; new domain, new modality, removed safety behaviour? Do you market the system under your own name or trademark as your product? Would a reasonable buyer think the AI is yours? Two or more “yes” answers put you in provider territory for planning purposes, which means documentation, transparency and, in Annex III contexts from December 2027, the full high-risk stack. Write the answers down with dates; the memo costs an hour and anchors every later conversation with buyers, insurers and authorities.

If we self-host an open model, do we become a “provider”?

Deploying unmodified weights for your own product typically makes you a deployer at the system level and a provider of the system you place on the market; substantial modification or your own branding can push you into provider territory for the model layer too. Classify before you launch, not after.

Can we build on a model whose licence bans our sector?

No; acceptable-use clauses are contract terms; breaching them stacks contractual liability on top of your regulatory exposure and can poison your IP chain in diligence.

This week’s homework

For every model in production, file three artefacts: the exact licence text (versioned), a one-paragraph classification memo (prohibited/high-risk/transparency/minimal), and the answer to “who do we call when it fails?”. If the third answer is “nobody,” check your insurance covers that silence.

Related: AI Office · AI Compliance Hub.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on AI and algorithm law, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 24 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.