Fine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.

Ulf Aslak Lai photo Ulf Aslak Lai Published 18 September 2026 Updated 18 September 2026 AI drafted 11 min read
Fine-tuning rarely makes you a model's provider under the AI Act. The threshold is a third of the base model's compute.

Fine-tuning an open-weights model on your own support tickets is a weekend and a few hundred euros of GPU time. Somewhere after that weekend, usually in an enterprise security questionnaire, somebody asks whether you have become the provider of a general-purpose AI model under the EU AI Act. The Act uses provider for two different roles, and they are worth separating before you answer. If your product ships an AI feature under your own name, you are already the provider of that AI system, whichever model sits underneath it 1. That is the role the Article 50 transparency duties attach to, and no vendor carries them for you. The provider of a general-purpose AI model is the other role, normally the lab that trained it, and it comes with technical documentation, a copyright policy and a public summary of the training data to produce. The questionnaire is asking about that second role. The answer is almost always no, and it rests on a number you can work out: the European Commission's indicative criterion is whether the compute you spent on the fine-tune is greater than a third of the compute used to train the original model 3. Almost nothing a SaaS team does comes close.

Knowing the answer is not the same as being able to show it. The questionnaire wants a figure, and without one the honest reply is that you have not checked, which a buyer reads as a no. What follows is the arithmetic, and the two cases where the answer flips.

The dates behind it: obligations for providers of general-purpose AI models have applied since 2 August 2025 4, and the Commission's power to fine those providers, up to 3% of worldwide annual turnover or 15 million euros, whichever is higher, began to apply on 2 August 2026 5. A model already on the market before 2 August 2025 has until 2 August 2027 6. None of this shifted in the Digital Omnibus on AI, which pushed the high-risk deadlines out but left the general-purpose model rules where they were.

What counts as a general-purpose AI model?

Not every model you train or fine-tune is one. The AI Act defines a general-purpose AI model as one that displays significant generality and is capable of competently performing a wide range of distinct tasks 1. That settles very little, so the Commission published an indicative criterion in July 2025: a model qualifies when its training compute is greater than 10^23 FLOP and it can generate language (as text or as audio), text-to-image, or text-to-video 3. FLOP is the unit the AI Act uses to count the arithmetic that went into training (Article 3(67)), and the Commission puts 10^23 of them at roughly what it takes to train a one-billion-parameter model on a large amount of data 3.

A churn model, a recommender, a fraud scorer or a document classifier is not a general-purpose AI model however much data went into it, because it does not generate language, images or video. The criterion also runs in both directions: a model above the threshold may exceptionally not qualify if it lacks significant generality, and a model below it may still qualify if it has it.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.

Try for free

Does fine-tuning make you the provider of the model?

Only if the fine-tune is large relative to the original training run. The Commission's position is that a downstream modifier, its term for anyone other than the original provider who modifies a model, becomes the provider of the modified model only where the modification leads to a significant change in the model's generality, capabilities, or systemic risk 3. The indicative criterion for that is the one in the opening: training compute for the modification greater than a third of the training compute of the original model.

The law asks whether the change is significant. The compute ratio is how the Commission says it will recognise that, and it reserves the right to revise the ratio as the technology moves 3.

Original training compute is often unpublished, so there is a fallback: a third of 10^23 FLOP, borrowed from the threshold for presuming a model general-purpose in the first place. It applies only where you can neither be expected to know the original figure nor estimate it 3.

Question Indicative threshold
Is the model general-purpose? Above 10^23 FLOP
Did my fine-tune make me its provider? A third of the original's compute
Original compute unknowable? A third of 10^23 FLOP

Put numbers on that with a model people actually fine-tune. Meta's Llama 3.1 8B model card reports pre-training on about 15 trillion tokens over 1.46 million H100 GPU hours. Through the guidelines' estimator of six times parameters times tokens, that is roughly 7 × 10^23 FLOP, so the threshold for becoming its provider is about 2.4 × 10^23 3. Your fine-tune runs on the same eight billion parameters, which makes a third of the compute a third of the tokens: about 5 trillion. Fifty thousand support tickets at five hundred tokens each is 25 million tokens, one two-hundred-thousandth of the way there, and that assumes you update every weight rather than train an adapter. In GPU time the gap has the same shape: a third of Meta's run is about 490,000 H100 hours, and eight GPUs for a weekend is under 400. The Commission says as much in the guidelines: "While currently few modifications may meet the criterion set out in paragraph 60, the number of downstream modifiers that become providers of general-purpose AI models may increase over time as the compute used to modify models increases" 3.

Most teams never touch a GPU for this and fine-tune through a vendor's API instead, which the guidelines treat separately. Whether the original provider or the downstream actor did the modifying is a case-by-case assessment, and an important factor may be who controls the model's weights 3. In hosted fine-tuning the weights stay with the vendor throughout, so my reading is that the vendor did the modifying and the question does not reach you. The guidelines stop short of saying so outright, so record which it was.

What do you owe if the fine-tune does cross the threshold?

Documentation of the modification rather than of the whole model, plus a representative in the EU if you are established outside it.

Recital 109, one of the numbered explanatory paragraphs in the Act's preamble, limits a downstream modifier's obligations to the modification itself, and the Commission applies that to all four duties in Article 53(1) 2, 3. The technical documentation you hold for the AI Office, the Commission body that supervises these models, and the documentation you hand to developers building on your model both describe what you changed rather than the whole model. The copyright policy and the public summary of training content cover the data you added, not the base model's corpus.

If you are established outside the EU, you also have to appoint an authorised representative in the Union, someone established in the EU who answers to the authorities on your behalf, under Article 54 7.

Models the Act presumes to carry systemic risk, above 10^25 FLOP of training compute (Article 51(2)), sit under a heavier regime in Article 55, and anyone whose fine-tune comes anywhere near a third of that should be talking to a lawyer rather than reading a blog post 3.

Releasing the model under a free and open-source licence drops the two documentation duties 2 and the authorised representative 7, but the exemption requires that you do not monetise the model, which the Commission reads broadly enough to catch paid commercial licences, paid support tied to the model, and exclusive hosting on your own paid platform 3. Most commercial teams fail that, and the copyright policy and training-content summary survive the exemption regardless.

If you do end up owing the documentation, the General-Purpose AI Code of Practice carries a Model Documentation Form built for these duties. Signing it is voluntary, and the Commission treats it as an adequate way to show compliance.

Can you become the provider without training anything?

Yes, in one narrow case, and it turns on a licence clause rather than on compute.

Start with the ordinary case, because almost everybody is in it. Supplying a model through a public API, a cloud service, or a public download is itself a placing on the Union market, which the Act defines as the first time a model is made available there (Article 3(9)) 1. So when you call a hosted model or pull weights from a public repository, the upstream developer has already placed it on the Union market and is its provider 3.

The narrow case runs differently. Where an upstream developer makes a model available to you outside the Union market, and you then integrate it into a system you place on the Union market, the model counts as placed on the Union market at that later moment. The upstream developer is still normally its provider, with one exception: where that developer has excluded, in a clear and unequivocal way, the distribution and use of the model on the Union market, including its integration into systems intended for that market, then you are the provider of the model 3.

So the clause I look for is one that keeps the model off the Union market altogether. A clause restricting who may take the licence is a different thing. Meta's Llama 4 Acceptable Use Policy withholds the licence grant for the multimodal models from "an individual domiciled in, or a company with a principal place of business in, the European Union", then says the restriction "does not apply to end users of a product or service that incorporates any such multimodal models". That governs who may take the licence, not whether the model may reach the EU, so it does not move provider status onto a non-EU company shipping into Europe. For an EU-based company the problem is worse but simpler: the grant is not there at all, so the question is not who provides the model but whether you may use it. That is a licence problem, not an AI Act one.

What should you check before your next fine-tune?

Three things, all cheap while the fine-tune is fresh and expensive to reconstruct a year later.

  1. Write down the training compute of your modification in FLOP, next to the original model's figure. Where the vendor has not published that figure, estimate it before reaching for the fallback: the guidelines carry an estimator of roughly six times the parameter count times the number of training tokens, and the fallback applies only where the original can neither be known nor estimated 3. Epoch AI's data on AI models publishes training-compute estimates in FLOP for several thousand models under a Creative Commons licence, which is the closest thing to a public reference for it.
  2. Read the model licence for a clause excluding the Union market, and keep a copy of the version you accepted.
  3. Keep all of this apart from your duties as the provider of the AI system you built. They are separate tests and both can land on the same company: where you provide a model and put it inside your own system, the model obligations apply on top of the system obligations 3. The Article 50 transparency duties are their own question, and whether the feature is high-risk is a third.

Write it down now rather than later, because the answer moves as the product does. A second fine-tune on a larger base, a switch to a different upstream model, a licence updated under you: each can change the answer, and none of them announces itself. A file in the repository next to the training script does the job, as long as somebody owns it and somebody notices when the model underneath changes. Noticing is the harder half, and it is the half Lawcel, the product I work on, exists for: it reads a codebase's pull requests and flags the ones that affect what a company's published legal documents say, for someone on the team to review.

Do the arithmetic once and keep it where the next person can find it. It is cheap to produce while the fine-tune is in front of you, and awkward to reconstruct with a customer waiting on the answer.

FAQ

Almost never. The Commission's indicative criterion is that the compute used for the modification is greater than a third of the compute used to train the original model, and it says few modifications may currently meet that.
Estimate it first. The fallback, a third of 10^23 FLOP, applies only where the original figure can neither be known nor estimated.
Almost certainly not. The Commission's criterion covers models that generate language, images or video, so a churn model, a fraud scorer or a document classifier falls outside it unless it displays significant generality anyway.
Documentation of the modification rather than of the whole model, a copyright policy and a training-content summary covering the data you added, and an EU authorised representative if you are established outside the Union.
The Commission can fine providers of general-purpose AI models up to 3% of worldwide annual turnover or 15 million euros, whichever is higher. That power began to apply on 2 August 2026.
It moves the date. Providers of general-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 to comply.

References

  1. Regulation (EU) 2024/1689 (AI Act), Article 3: Definitions - accessed 18 Sept 2026
  2. Regulation (EU) 2024/1689 (AI Act), Article 53: Obligations for providers of general-purpose AI models - accessed 18 Sept 2026
  3. European Commission, Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act), C(2025) 5045 final, 18 July 2025 - accessed 18 Sept 2026
  4. Regulation (EU) 2024/1689 (AI Act), Article 113: Entry into force and application - accessed 18 Sept 2026
  5. Regulation (EU) 2024/1689 (AI Act), Article 101: Fines for providers of general-purpose AI models - accessed 18 Sept 2026
  6. Regulation (EU) 2024/1689 (AI Act), Article 111: Transitional provisions - accessed 18 Sept 2026
  7. Regulation (EU) 2024/1689 (AI Act), Article 54: Authorised representatives of providers of general-purpose AI models - accessed 18 Sept 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
AI Act

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.

Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into, a product covered by EU product-safety law, or it sits in one of the eight areas in Annex III, such as hiring, education or credit scoring. If yours is, Article 6(3) can still take it out, but you then owe a written assessment and an EU database entry.

AI Act

Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

Article 50 of the EU AI Act applies from 2 August 2026. The delay you read about in June covered high-risk uses such as hiring and credit scoring, not this. If your product has an AI feature that ships under your own name, the law treats you as its provider even though the model belongs to your vendor, so telling users about it and marking what it generates are your duties. You may use whatever marking your vendor builds, but the Commission's guidelines say that demonstrating compliance stays with you.

GDPR

Adding AI to your app? Add these three disclosures to your privacy policy.

Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient of personal data, wherever it runs the prompt is probably a transfer out of the EEA, and if the output decides something about a person you may owe the automated-decision disclosure too. AI Act Article 50 then adds two duties to the product itself.

Data Act

A connected device sold in the EU after 12 September 2026 must export its data to the user

For a connected device first sold in the EU after 12 September 2026, and the software it needs to work, the readings it produces have to reach its user by default: free of charge, in a machine-readable format, and directly accessible where feasible. Small companies get an exemption, but lose it if a larger company owns a quarter of them, or if they were paid to build somebody else's product.