Skip to main content
Category: EU AI Act & GPAI

Open-Source Model Exemption

Also known as: Open-Source AI Exemption, Free and Open-Source AI Exemption
Simply put

The open-source model exemption refers to provisions in the EU AI Act that relieve providers of certain openly licensed AI systems and models from some—but not all—of the law's obligations. It is a partial and limited carve-out, not a blanket exclusion, so compliance may still be required even when a model is released under a free and open-source license. The exemption is scoped to the EU AI Act specifically and does not represent a general or universal rule across other frameworks.

Formal definition

As commonly discussed in relation to the EU AI Act, the open-source model exemption denotes limited relief from specified obligations for providers of AI systems and general-purpose AI (GPAI) models made accessible under a free and open-source license, a concept the Act reportedly references in recital 89 as 'free and open source AI.' In practice the exemption is partial: reporting suggests providers of open-source GPAI models are exempt from some obligations (for example certain documentation and disclosure requirements) but not all, and that the relief does not extend to models presenting elevated risk (for instance, GPAI models with systemic risk) and, per one source, would not apply to foundation models. The scope is contested and evolving, in part because there is no generally accepted definition of 'open-source' in this context; practitioners should note that release under an open-source license does not, by itself, exempt a provider from AI Act compliance. This entry is scoped to the EU AI Act and does not describe treatment under other regimes such as the NIST AI RMF, ISO/IEC 42001, or U.S. model risk guidance.

Why it matters

The open-source model exemption matters because open licensing is often assumed—incorrectly—to place an AI system outside the reach of regulation. Under the EU AI Act, releasing a model under a free and open-source license does not by itself remove a provider's compliance obligations. As reporting on the Act notes, the exemptions are limited, and compliance may still be required even when a system or model is openly licensed. Treating an open-source release as a blanket exclusion is a common and consequential misreading that can leave a provider exposed to obligations it assumed did not apply.

The stakes are heightened by the exemption's boundaries. Available reporting suggests the relief does not extend to models presenting elevated risk—for instance, general-purpose AI (GPAI) models with systemic risk—and, per one source, would not apply to foundation models. For organizations building on or distributing open models, the practical question is therefore not whether a model is open-source, but which specific obligations are relieved and which continue to apply. Misjudging that line has direct governance and legal consequences, particularly for providers whose models could fall into higher-risk categories.

The scope is also unsettled because there is currently no generally accepted definition of 'open-source' in this context. That ambiguity means the exemption's edges are contested and evolving, and reasonable parties may disagree about whether a given release qualifies. Practitioners should treat the exemption as a partial, jurisdiction-specific carve-out under the EU AI Act rather than a settled or universal principle, and should not assume comparable treatment under other frameworks such as the NIST AI RMF, ISO/IEC 42001, or U.S. model risk guidance.

Who it's relevant to

Providers and developers of open-source AI models
Teams releasing AI systems or GPAI models under free and open-source licenses need to determine which specific EU AI Act obligations are relieved and which continue to apply. Because reporting indicates the exemption is partial and does not extend to models with systemic risk or, per one source, to foundation models, developers should not treat an open license as a blanket exclusion from compliance.
Compliance officers and legal professionals
Those advising on EU AI Act obligations must scope the exemption carefully, particularly given that there is currently no generally accepted definition of 'open-source' in this context. Legal teams should assess qualification on a case-by-case basis rather than by license label, and should flag that the exemption's boundaries are contested and evolving.
Organizations building on or distributing open models
Enterprises that integrate, fine-tune, or redistribute openly licensed models should understand that upstream open-source status does not automatically remove their own potential obligations, and that documentation and disclosure relief for open-source GPAI providers is partial. Governance teams should map where residual obligations may fall within their own use.
AI governance and policy specialists
Professionals designing internal AI governance frameworks need to reflect the exemption's limited, jurisdiction-specific nature. This entry is scoped to the EU AI Act and does not describe treatment under the NIST AI RMF, ISO/IEC 42001, or U.S. model risk guidance, so cross-framework policies should avoid implying equivalent open-source carve-outs elsewhere.

Inside Open-Source Model Exemption

Scope of the exemption
A provision, discussed most prominently in the context of the EU AI Act (an instrument issued by EU institutions), under which certain obligations that would otherwise apply to general-purpose or other AI models may be reduced or disapplied when a model is released under a free and open-source license. The precise contours are defined by the relevant legal text and, as commonly understood, are conditional rather than absolute.
Typical qualifying conditions
Exemptions of this kind are generally tied to criteria such as public availability of the model's parameters, weights, or architecture and release under a genuinely open license. Where conditions are not met, the exemption typically does not apply. Practitioners should confirm the exact conditions against the governing text rather than assuming any open release qualifies.
Common carve-outs and limits
Even where an open-source exemption exists, it is frequently narrowed so that it does not cover models placed on the market for a fee, models that meet thresholds triggering heightened obligations (for example those characterized as posing systemic or high-impact risk in some frameworks), or uses that fall within high-risk or prohibited categories. The exemption is best understood as partial rather than a blanket release from all obligations.
Relationship to governance and model risk management
A legal or regulatory exemption from specific statutory obligations is distinct from an organization's internal AI governance and model risk management responsibilities. Adopting an exempt open-source model does not, in itself, remove the deploying organization's own oversight, validation, and monitoring duties, which are driven by internal policy and, in regulated sectors, by separate supervisory expectations.

Common questions

Answers to the questions practitioners most commonly ask about Open-Source Model Exemption.

Does using an open-source model mean my organization is exempt from AI governance and model risk obligations?
No. Any exemption language associated with open-source or free and open-source AI components is typically narrow and directed at specific obligations under a particular framework, not a blanket release from organizational accountability. Where a deployer or user integrates an open-source model into its own systems and outcomes, obligations arising from that use—such as internal validation, monitoring, and oversight under model risk management practices—generally still apply regardless of the model's licensing status. Treat any exemption as scoped to the instrument that grants it rather than as a general safe harbor.
Is an 'open-source model exemption' the same across the EU AI Act, the NIST AI RMF, and prudential model risk guidance like SR 11-7?
No, and these instruments should not be treated as interchangeable. They are issued by different bodies, differ in legal character—ranging from binding law to voluntary framework to supervisory guidance—and address different obligations. An exemption or accommodation described in one does not carry over to another, and voluntary frameworks and supervisory guidance may not use the concept of a formal 'exemption' in the same way. Scope any claimed exemption to the specific framework and jurisdiction that defines it, and confirm the exact conditions rather than assuming parity across regimes.
How should we determine whether a given model actually qualifies for an open-source treatment under an applicable framework?
Qualification typically turns on the precise definitional criteria and conditions set by the relevant framework, which may address matters such as licensing terms, availability of components, and whether the model is placed on a market or monetized. Because these criteria vary and can be contested, organizations commonly document the specific license, the source and provenance of the model, and how the intended use maps to the framework's stated conditions. Where the definition is ambiguous or evolving, qualified legal and compliance review is advisable rather than a self-assessed conclusion.
What governance controls remain appropriate even if an open-source model falls within an exemption?
Even where a specific documentation or disclosure obligation may be reduced, organizations typically retain internal responsibilities such as validation and verification of the model as used, ongoing performance monitoring, oversight structures, and clear lines of accountability. These controls reduce and manage risk rather than eliminate it. Because an exemption generally addresses obligations toward a regulator or standard rather than internal risk, most model risk management and AI governance practices around fitness for purpose, monitoring, and change management remain relevant.
How does fine-tuning or modifying an open-source model affect its exemption status?
Modification can change the analysis, because altering or building on a model may shift who is treated as responsible for the resulting system and which obligations attach. Whether an exemption continues to apply after fine-tuning depends on the specific conditions in the applicable framework and how it characterizes downstream modification and deployment. Given this uncertainty, organizations commonly document what was changed and re-assess the applicable obligations after material modification rather than assuming the original status carries forward.
What documentation should we maintain to support reliance on an open-source exemption?
As a practical matter, organizations often retain evidence of the model's license and provenance, the rationale mapping the use to the exemption's conditions, records of any modifications, and the internal validation and monitoring performed on the model as deployed. This documentation supports both an audit trail and the ability to demonstrate accountability across the relevant lines of defense. The appropriate level of detail depends on the framework and sector, and firms in regulated environments such as banking may face expectations that are more extensive than general enterprise settings.

Common misconceptions

An open-source model is exempt from all AI regulatory requirements.
Where such exemptions exist, they are typically scoped to particular obligations and subject to conditions and carve-outs. As commonly framed, they do not extend to high-risk or prohibited uses, and downstream deployers may still face obligations regardless of the model's licensing status.
The exemption removes an organization's need to validate, monitor, and govern the model.
A statutory or regulatory exemption addresses external legal obligations, not internal accountability. Model risk management and AI governance responsibilities—including validation, ongoing monitoring, and oversight—generally remain with the organization deploying the model, particularly in regulated sectors where separate supervisory guidance applies.
Any model whose weights are publicly downloadable automatically qualifies.
Qualification typically depends on defined criteria such as the license terms and the absence of commercial monetization, and specific thresholds or use cases may disqualify a model. Whether a given model qualifies is a fact-specific determination against the governing legal text.

Best practices

Verify the exact conditions and carve-outs of the applicable exemption against the current governing legal text and its jurisdiction, rather than relying on general summaries or the assumption that all open-source releases qualify.
Assess the intended use case separately, since exemptions commonly do not extend to high-risk or prohibited applications; confirm the deployment context before concluding an obligation is disapplied.
Maintain internal AI governance and model risk management controls—validation, ongoing monitoring, and oversight—independently of any external exemption, treating the exemption as relief from specific statutory obligations rather than from organizational accountability.
Document the basis for relying on an exemption, including the license terms, qualifying conditions met, and any thresholds evaluated, to support auditability and supervisory review.
Obtain qualified legal review before treating a model as exempt, especially where commercial use, systemic-risk thresholds, or evolving regulatory interpretation may affect eligibility.
Reassess exemption status when the model, its license, its use case, or the governing requirements change, since the exemption's applicability is condition-dependent and may lapse.