What is a foundation model?
A foundation model is a large AI model — usually transformer-based — trained on broad data at scale and designed to be adapted: fine-tuned, instruction-tuned or simply prompted into thousands of downstream tasks it was never explicitly trained for. GPT-class language models, image generators and multimodal models are all foundation models. The term, coined at Stanford in 2021, describes the engineering pattern; EU law regulates the same object as a general-purpose AI model.
How the pattern works
One expensive training run produces a general substrate; everything after it is adaptation. A large language model becomes a contract-review assistant through fine-tuning or prompting, not retraining. That economy is the point of the pattern — and the source of the legal problem: capability, data provenance and defects all flow downstream into products from a model whose insides the downstream builder never sees.
The legal dimension
- Value-chain allocation: one company trains the model, another fine-tunes it, a third deploys the product. AI Act duties split across that chain, and provider status can transfer with significant modification;
- Inherited risk: downstream products inherit training-data provenance issues — copyright, TDM opt-outs, personal data — that they cannot fully audit, which is why vendor contracts carry the weight;
- Concentration: most of the market builds on a handful of models, making model-provider terms de facto industry regulation.
Turkish context
Turkish startups are almost always adapters rather than trainers: they build on foreign foundation models and sell into Türkiye and the EU. Türkiye has no AI-specific statute in force, so the domestic questions run through KVKK, FSEK and general contract law, and the AI Act enters the picture when the product reaches the EU market. The leverage point is procurement: warranties on training-data provenance, documentation flow-down and indemnities do the work that statute does not. Where the provider’s standard terms are closed to negotiation, the residual risk is managed through liability caps in the customer contract instead.
Do: record which model and which version sits under each product, and negotiate documentation flow-down before launch. Don’t: substantially modify a model without re-checking your provider status, or promise customers provenance guarantees your own vendor has not given you.
Related guides: The AI Vendor Contract, You Didn’t Train the Model, but You Still Have AI Act Obl….
Working on this? Vircon Legal advises on Startup & Scaleup Advisory and Startup Law in Türkiye guide. Talk to us →
Related terms
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call