Reglog

← Guides & analysis

If you fine-tune an AI model, do you become its provider under the EU AI Act?

· 12 min read

If your company builds on someone else's model — fine-tuning an open-weights model on your own data, or adapting it for your customers — there is a question worth answering before your next release: have you become the provider of a general-purpose AI model?

It matters because provider status under Chapter V is not a light obligation. It brings documentation duties, a copyright policy, a published summary of training content, and, for models with systemic risk, further systemic-risk duties. All of it is enforced by the Commission itself, with fines up to €15 million or 3% of worldwide annual turnover, whichever is higher.

The good news for most companies: you are probably not there, and the Commission itself says that currently few modifications may meet its indicative criterion.

This is an information service to help you plan, not legal advice. To see which obligations attach to your own AI use, start with the obligation check.

First: is the model even a "general-purpose AI model"?

Article 3(63) defines a general-purpose AI model as one that "displays significant generality and is capable of competently performing a wide range of distinct tasks", and that "can be integrated into a variety of downstream systems or applications". Models used for research, development or prototyping activities before they are placed on the market are excluded.

That wording is not something you can measure, so the Commission's guidelines add an indicative criterion: training compute greater than 10²³ FLOP, together with the ability to generate language (text or audio), text-to-image, or text-to-video. The guidelines put that threshold at roughly "the approximate amount of compute typically used to train a model with one billion parameters on a large amount of data". The Commission reads "text" to include code, and "audio" to include speech.

The criterion is indicative, not the legal test. The guidelines say a model below it that, exceptionally, displays significant generality and can competently perform a wide range of distinct tasks is still a general-purpose AI model, and a model above it that can only competently perform a narrow set of tasks is not.

A narrow classifier, a demand-forecasting model or a small in-house recommendation model is not a general-purpose AI model, whatever your marketing calls it. Chapter V is not your chapter.

The one-third criterion

The AI Act is silent on when someone modifying a model takes over as its provider. The Commission filled the gap:

"the Commission considers a downstream modifier to become the provider of the modified general-purpose AI model only if the modification leads to a significant change in the model's generality, capabilities, or systemic risk." (Emphasis added.)

And the working test for that:

"an indicative criterion for when a downstream modifier is considered to be the provider of a general-purpose AI model is that the training compute used for the modification is greater than a third of the training compute of the original model." (Emphasis added.)

If you cannot know or estimate the original model's training compute, the guidelines substitute a fixed figure:

Your situation The threshold that applies Roughly
You know, or can estimate, the original model's training compute More than a third of it Depends on the model
Unknown and cannot be estimated, and the original model is a model with systemic risk More than a third of 10²⁵ FLOP ~3.3 × 10²⁴ FLOP
Unknown and cannot be estimated, and the original model is an ordinary general-purpose AI model More than a third of 10²³ FLOP ~3.3 × 10²² FLOP

Two things to take from this. The Commission is candid about it — "while currently few modifications may meet the criterion set out in paragraph 60" — and describes the criterion as "primarily forward-looking". Ordinary supervised fine-tuning, LoRA adapters and instruction tuning on a business dataset typically use far less than a third of the base model's training compute.

And it is an indicative criterion, not a legal test. It is the Commission's stated approach, in non-binding guidelines that say the approach "may change in the future as technology and the market evolve". Document your estimate and your reasoning; do not treat the number as a statutory safe harbour.

Who did the modifying also matters. The guidelines say that whether the original provider or you counts as the modifier must be assessed case by case, and that an important factor may be who controls the model's weights — for example, when fine-tuning happens through a provider's API.

There is also a route to provider status that has nothing to do with compute. If the original provider made the model available to you outside the EU and has excluded, "in a clear and unequivocal way", its distribution and use on the Union market, the guidelines say that a company which integrates it into an AI system and places that system on the EU market or puts it into service in the EU "should be considered the provider of the model". Check the base model's licence for an EU exclusion before you rely on the one-third criterion.

If you do cross the line, what do you owe?

Less than the original provider does. Recital 109 limits the obligations to the modification itself, and the guidelines spell out the split:

Obligation Article What it covers for a downstream modifier
Technical documentation for the AI Office and authorities 53(1)(a) Information on the modification
Information and documentation for downstream integrators (Annex XII) 53(1)(b) Information on the modification
Copyright policy, including honouring rights reservations 53(1)(c) The data used in the modification
Public summary of training content, on the AI Office template 53(1)(d) The data used in the modification
Authorised representative in the EU 54 Required if you are established outside the EU, unless the open-source exemption in Article 54(6) applies

If the model you modified was a model with systemic risk, the result is heavier: the guidelines say the modified model "is presumed to have high-impact capabilities", so it is itself a model with systemic risk. That brings the Article 55 duties — model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting to the AI Office, and cybersecurity protection — plus notification to the Commission under Article 52(1).

The systemic-risk threshold in Article 51(2) is training compute greater than 10²⁵ FLOP, a presumption the Commission can update by delegated act.

The open-source exemption, and the monetisation trap

Article 53(2) disapplies the technical-documentation duties in 53(1)(a) and (b) — and Article 54(6) the authorised-representative duty — for models released under a free and open-source licence allowing access, use, modification and distribution, where parameters including weights, architecture information and usage information are public. It "shall not apply to general-purpose AI models with systemic risks".

Note what survives even when the exemption applies: the copyright policy and the training-content summary. The guidelines explain that open-source release does not necessarily reveal substantial information on the data used for training or modifying a model, or on how copyright compliance was ensured, so those duties stay.

There is a further condition, set out in recital 103 and developed in the guidelines: the model must not be monetised. Monetisation covers more than charging a price. The Commission's examples include:

  • dual licensing that is free for academic use but paid for commercial use or use above a certain scale;
  • paid technical support or services "indistinguishably linked to the model itself" without which it would not work;
  • requiring users to buy support, training or maintenance to get access;
  • hosting the model exclusively on your own platform that requires payment for access — including where access is free but served with paid advertisements.

The guidelines treat requiring the collection or processing of personal data as a condition of access or use the same way, unless that processing is strictly limited to the model's security with no commercial gain. Recital 103 and the guidelines both carve out transactions between microenterprises: those do not count as monetisation.

The Commission also lists what does not count as monetisation: paid services that are purely optional and do not affect free use of the model, and paid support, tools or premium versions offered alongside it with no purchase obligation, provided free access to and use of the model stay guaranteed. On the Commission's reading, the question is whether paying, buying a service, being served paid ads or handing over personal data is a condition of getting and using the model itself.

These are the Commission's non-binding readings. Recital 103 itself is worded more widely: it says that components "provided against a price or otherwise monetised, including through the provision of technical support or other services" related to them should not benefit from the exceptions. If your paid offer sits close to the model, for example a paid service that most users in practice need, take advice rather than relying on the optional-services examples.

Dates, enforcement and fines

Item Position
Chapter V (GPAI model rules) Applies since 2 August 2025 (Article 113(b))
Commission fines under Article 101 Carved out of that date; live since 2 August 2026
Models placed on the market before 2 August 2025 Must comply by 2 August 2027 (Article 111(3))
Fine ceiling Up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher (Article 101(1))
Who enforces The Commission / AI Office, not your national authority

That last row is the structural point. For general-purpose AI models your regulator is in Brussels — see who enforces the AI Act, and, for how a Commission investigation actually proceeds, the GPAI investigation procedure. Fine amounts across all tiers are in the fine structure.

Being outside the EU does not help by itself: the Act reaches providers placing models on the Union market wherever they are established — see does the AI Act apply outside the EU.

Cite the right guidelines

The guidelines quoted here are the Commission Guidelines on the scope of the obligations for providers of general-purpose AI models, and the operative document is C(2025) 7719 final, dated 19 November 2025.

If a source cites C(2025) 5045 final (18 July 2025), note that it is the internal Communication approving the draft content, not the guidelines themselves; the Commission's library page still shows 18 July 2025 as its publication date, but the English guidelines PDF it links is C(2025) 7719 final. If you are relying on a summary written in mid-2025, check it against the current PDF on the Commission's library page before you rely on a number.

What to do now

  1. Measure before you worry. Estimate the training compute of your modification and, where you can, of the base model. The guidelines' Annex sets out hardware-based and architecture-based estimation methods.
  2. Write the estimate down. A one-page note showing you are far below a third of the base model's compute is your evidence that, on the Commission's indicative criterion, you have not become the provider of the modified model. Add a line confirming that the base model's licence does not exclude its distribution and use on the EU market (the route described above), because that route makes the company that integrates the model its provider whatever compute it used. The note does not cover your duties as the provider or deployer of the AI system you build on the model; see point 5.
  3. Watch the weights question. The guidelines say that whether you or the original provider counts as the modifier must be assessed case by case, and that an important factor may be who controls the model's weights, for example when you fine-tune via a provider's API. Record who holds the weights in your note.
  4. If you publish models, check the monetisation test honestly. The Commission treats hosting an otherwise open model exclusively on your own paywalled or ad-served platform as monetisation, which takes it outside the exemption. Purely optional paid extras offered alongside a freely available model do not count, in its view.
  5. Do not confuse this with your system-level duties. Whatever happens at model level, as the provider or deployer of an AI system you have the Article 4 AI-literacy duty, and your product may still carry the Article 50 transparency duties and, later, high-risk duties — check whether your system is high-risk and which obligations apply to your company. Separately, Article 25(1) can make you the provider of a high-risk AI system at system level if you put your name or trademark on one, make a substantial modification to one, or change the intended purpose of an AI system, including a general-purpose AI system, so that it becomes high-risk — see EU AI Act deployer obligations.

To see which obligations apply to you, sorted by deadline, answer a few questions about your AI use. To be told if the Commission revises the one-third criterion or the compute thresholds — both of which it has said may change — join the waitlist. If you are a small company, the SME rules set out what relief exists for AI systems. One limit matters here: the SME 'whichever is lower' fine cap in Article 99(6) applies only to fines under Article 99. Article 101, which governs the Commission's fines on general-purpose AI model providers, contains no SME reduction, so the ceiling stays €15 million or 3% of worldwide annual turnover, whichever is higher.

The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.

Frequently asked questions

Does fine-tuning a model make you a provider under the EU AI Act?

Usually not. The AI Act does not say when a downstream modifier becomes the provider of a modified general-purpose AI model, so the Commission's guidelines fill the gap: they consider that you become the provider only if the modification causes a significant change in the model's generality, capabilities or systemic risk, and their indicative criterion for that is training compute used for the modification greater than one third of the original model's training compute. The Commission itself notes that currently few modifications may meet it. Separately, the guidelines say that if the original provider made the model available to you outside the EU and clearly and unequivocally excluded its distribution and use on the EU market, a company that integrates it into an AI system placed on the EU market or put into service in the EU is considered the provider of the model, whatever compute it used.

What counts as a general-purpose AI model in the first place?

Article 3(63) defines it as a model displaying significant generality, capable of competently performing a wide range of distinct tasks and able to be integrated into downstream systems. The Commission's indicative criterion is training compute greater than 10²³ FLOP together with the ability to generate language (as text or audio), text-to-image or text-to-video. That is roughly the compute typically used to train a one-billion-parameter model on a large amount of data. The criterion is indicative, not the legal test: the guidelines say a model below it that, exceptionally, displays significant generality and can competently perform a wide range of distinct tasks is still a general-purpose AI model, while a model that can only competently perform a narrow set of tasks is not.

What do you owe if you do become the provider of a modified model?

The Article 53(1) duties, but limited to your modification, as recital 109 says. The Commission's guidelines spell out the split: technical documentation and downstream information covering the modification, and a copyright policy and public training-content summary covering the data you used for it. If you are established outside the EU you must also appoint an authorised representative under Article 54, unless the open-source exemption in Article 54(6) applies. If the original model had systemic risk, the Commission's guidelines presume the modified model has it too, which brings the Article 55 duties and notification to the Commission under Article 52(1).

Does the open-source exemption cover a fine-tuned model?

It can, but the conditions are strict and it never covers models with systemic risk. The licence must allow access, use, modification and distribution, the parameters including the weights, the information on the model architecture and the information on model usage must be public, and, under recital 103, the model must not be monetised. The Commission's examples of monetisation include dual licensing that is free for academic use but paid for commercial use or use above a certain scale, requiring users to buy support, training or maintenance to get access, and hosting the model exclusively on your own platform that requires payment or serves paid advertisements. Optional paid services, support or premium versions that leave free access to and use of the model intact do not count, in the Commission's view. Even when the exemption applies, the copyright policy and training-content summary obligations remain.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.