The classic trap
Many publishers believe that releasing their model under Apache 2.0 or MIT with weights on Hugging Face exempts them from the AI Act. This is wrong on two precise points. First, as soon as the model crosses the systemic risk threshold (10^25 FLOPs or designation by the AI Office), the exemption falls away entirely. Second, even for a 'standard' open-source model, two obligations remain due: the detailed summary of training content (AI Office template) and the EU copyright compliance policy, notably the opt-out under Article 4(3) of Directive 2019/790. The Brussels AI Office has already indicated it will scrutinise both deliverables, and Luxembourg's CNPD remains competent on the personal data dimension of training datasets.
The open-source exemption eligibility test
To benefit from the transparency relief of Recital 104, the following four cumulative conditions must be met and auditable:
- Genuinely free licence: OSI-approved licence or equivalent, without restrictive field-of-use clauses (open-weight licences like the Llama Community License are contestable).
- Publicly accessible weights without blocking registration or disguised export control.
- Documented architecture: parameter count, layers, activation functions, tokenizer.
- Published usage information: recommended contexts, limitations, performance evaluations.
Crucially, two obligations remain due even when all four conditions are met:
- The sufficiently detailed summary of training content, following the template published by the AI Office (Article 53(1)(d)).
- The copyright compliance policy, including the mechanism to detect and respect machine-readable opt-outs (robots.txt, TDM Reservation Protocol, ai.txt tags).
How Luxgap automates this risk
Our Luxgap Open-Source Model Exemption Auditor settles within 48 hours the question 'does my model truly benefit from the Recital 104 exemption, and if so for which obligations?'. The tool analyses your Hugging Face or GitLab repository, the applied licence, published documentation, the training pipeline (DVC, Weights and Biases, MLflow) and produces a verdict opposable to the AI Office with the exact list of residual obligations that apply to you.
- Automatically scans your model card, licence and configuration files to validate the four cumulative conditions of the exemption.
- Computes total training FLOPs from your MLflow or Weights and Biases logs to detect crossing of the 10^25 threshold and shift to the 'systemic risk' regime.
- Generates the detailed training content summary in the AI Office template format, cross-referencing your declared datasets with Common Crawl, LAION, The Pile and your proprietary sources.
- Verifies compliance with Article 4(3) Directive 2019/790 opt-outs by confronting your crawls with robots.txt, TDM Reservation Protocol and ai.txt tags of scraped sites.
- Produces the documented copyright policy, ready for publication and opposable during an AI Office audit.
- Alerts in real time if a licence or model change causes you to fall outside the exemption regime.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real model, with a free 48-hour blank audit to measure your exposure before any commitment.