The Core Question
France and Germany have disrupted what seemed like a settled agreement. After extensive negotiations on the EU AI Act, these two countries have challenged the European Parliament's approach to regulating foundation models. The Spanish presidency is now tasked with finding a compromise. The key question remains: Should foundation models have their own regulatory tier, or should they be governed by the same risk-based framework that applies to all AI systems?
This isn't just political theater. How the EU resolves this will shape your compliance strategy for the next decade, especially if you're working with large language models, multimodal systems, or other General-Purpose AI Models.
Why Foundation Models Might Need Special Rules
The Parliament's stance reflects a practical issue: foundation models don't fit neatly into the EU AI Act's risk tiers. A GPT-class model isn't inherently high-risk or low-risk. Its risk level depends on its downstream use.
Supply Chain Visibility
If you're deploying a chatbot built on a third-party foundation model, the EU AI Act's high-risk obligations fall on you. But without transparency from the foundation model provider, you can't fully assess compliance. You need documentation on training data, limitations, and evaluation results. The Parliament's approach would mandate this disclosure.
Systemic Risks
Foundation models can enable prohibited practices at scale. A model trained on biometric data could be used for widespread surveillance. Addressing risks at the model level makes more sense than waiting for each application to be deployed.
Technical Documentation
Article 11 and Annex IV require high-risk system providers to document training data and model performance. If you're fine-tuning a foundation model, you often lack this information. The foundation model provider has it. Special rules would ensure this documentation is passed down.
The Case for Risk-Based Governance
France and Germany's objection focuses on regulatory coherence and economic strategy.
Existing Framework Sufficiency
The EU AI Act classifies systems by their deployment context, not technical architecture. A foundation model used for email autocomplete isn't high-risk, but the same model used for loan decisions is. Creating a separate category for foundation models undermines this logic.
Innovation Concerns
European AI research labs lag behind the U.S. and China. Adding compliance requirements before a model reaches the market could widen that gap. A restrictive framework could push foundation model development outside Europe.
Enforcement Challenges
How do you regulate an open-sourced model? If a foundation model is released under a permissive license, who's responsible for compliance? Special rules could create jurisdictional issues that the risk-based approach avoids.
Duplication of Requirements
If a foundation model is used in a high-risk application, it already faces Article 9 risk management and Article 10 data governance obligations. Adding another compliance layer means duplicating efforts.
Where Practitioners Stand
Most governance teams seek clarity over a specific outcome. You can build a compliance program around either approach, but not while regulations are still unsettled.
In practice, your governance strategy should account for both scenarios. If you're a foundation model provider, anticipate transparency obligations. If you're a deployer, prepare to validate foundation model characteristics, regardless of explicit legal requirements. The real distinction is between general-purpose and specific-purpose systems.
Our Take
The Parliament's instinct is correct, but the mechanism is flawed. Foundation models need transparency requirements, but these should come from existing supply chain provisions, not a new regulatory category.
Article 16 already requires high-risk AI system providers to cooperate with deployers and provide necessary information. Strengthen this. Make it explicit that foundation model providers must disclose training data characteristics, evaluation results, and known limitations if their models are used in high-risk systems. This approach supports the risk-based framework without creating a separate compliance regime for foundation models.
France and Germany are right that foundation models shouldn't be regulated as inherently high-risk. The Parliament is right that deployers need information. Balancing these positions can lead to a workable compromise without forcing either side to abandon their core stance.



