№ xlii The Almanac of GST · EN IT

Enrico·rubbo.li

Tech · Longevity · Markets · Opinions Enrico Rubboli, propr. Dubai, UAE
essay September 15, 2026 11 min

The AI Act Regulates Invoices. Open Weights Don't Send Any.

Since 2 August 2026, any provider putting a generative system on the European market has to mark its synthetic output in a machine-readable format, because Article 50(2) of the EU AI Act says so.[1] The deadline was written into Article 113 two years in advance, and it arrived on schedule.[2] Somewhere else, a torrent completes. That file has no compliance officer. It fine-tunes overnight on a secondhand GPU. It will never file a conformity assessment. Open weights do not send invoices, and an invoice is the thing this law reads best.

The Act is built to civilize named providers who want market access, and it is not naive about money. Article 3(3) defines a provider as anyone who develops a model and places it on the market under their own name, “whether for payment or free of charge.”[3] Free is not a loophole. What the Act was not built for is capable weights that travel like music files. If your ethics stop at the API terms of service, you have not met the adversary, the researcher, or the teenager who can follow a README.

What open weights actually are

“Open” covers a spectrum, and the licences are not interchangeable. OpenAI released gpt-oss-120b and gpt-oss-20b in August 2025 under Apache 2.0.[4] DeepSeek released R1 in January 2025 with the weights under the MIT licence, explicitly permitting commercial use and distillation.[5] Meta released Llama 3.1 under a Community License that is not open source at all in the OSI sense: it demands a “Built with Llama” attribution and forces anyone above 700 million monthly active users to come back and negotiate.[6]

The operational fact underneath is identical in all three cases. Once the parameters are on disk, inference is local. Fine-tunes are local. Guardrails are optional. Watermarks are a suggestion that someone else’s sampler happened to implement.

That is how science reproduces. That is how smaller labs compete. That is also how malware authors and fraud shops get a text engine without a KYC form. Dual use is not a slogan here. It is the file format.

What the EU AI Act open source exemption actually covers

The popular version of this story is that open source is exempt. The text is narrower, and more interesting.

For AI systems, Article 2(12) says the Regulation does not apply to systems released under free and open-source licences, “unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.”[7] The carve-out stops exactly where the watermark starts. There is no open source discount on the transparency duties, and none on the prohibitions.

For general-purpose AI models, the exemption lives in Article 53(2), and it waives precisely two obligations: the technical documentation of Article 53(1)(a), which is Annex XI, and the downstream information pack of Article 53(1)(b), which is Annex XII. To qualify, the licence must allow “the access, usage, modification, and distribution of the model,” and the parameters, weights, architecture and usage information must be publicly available. The copyright policy in point (c) and the public summary of training content in point (d) survive untouched. And the exception “shall not apply to general-purpose AI models with systemic risks.”[8]

Systemic risk, in turn, is a compute tier. Article 51(2) presumes high impact capabilities when cumulative training compute exceeds 10²⁵ floating point operations, a rebuttable presumption that the Commission can also reach by individual designation.[9] Cross that line and Article 55 lands whole: model evaluation under state-of-the-art protocols, documented adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting to the AI Office, and cybersecurity protection for the weights themselves.[10] Publishing the checkpoint buys nothing there.

So the drafting is not the sieve the slogan describes. The hole is somewhere else.

Where the Act’s hands actually go weak

I have already argued that the Act lands on organizations with European invoices and misses criminals and covert operators almost by design.[11] Open weights are the sharp edge of that miss, and the reason is enforcement, not exemption.

  • The addressee evaporates. Article 3(10) defines making a model available on the market as supply “in the course of a commercial activity.”[3] The lab that publishes the weights is a provider, is named, and is reachable. The anonymous account that re-uploads the same tensors to a mirror in a third country is none of those things.
  • Fine-tunes launder providership. Each derivative is arguably a new model with a new provider, and a fog of throwaway repositories is where that argument goes to die.
  • Article 50 needs someone to serve papers on. The marking duty binds providers; the deepfake disclosure binds deployers. A local stack on a secondhand GPU presents neither to a market surveillance authority.
  • The threshold is a ceiling for most abuse. A model an order of magnitude below 10²⁵ FLOP can be entirely good enough for phishing, romance fraud and harassment while sitting under the systemic tier, with Annex XI and Annex XII waived on top of that.
  • The calendar keeps sliding. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and the Annex I product-embedded ones from 2 August 2027 to 2 August 2028.[12] The models did not wait for the extension.

This is not a plea to ban math. It is a plea to stop pretending an Annex is a control. Control and containment as a technical program was always about capabilities that do not ask permission. Distribution is how capabilities leave the lab.

Guardrails are a fine-tune away

The strongest argument against unrestricted release is not speculative, and it has been in the literature since 2023. Gade, Lermen, Rogers-Smith and Ladish stripped the safety fine-tuning out of Llama 2-Chat 13B for under $200 while retaining its general capabilities, and were sufficiently alarmed by the result that they declined to publish the weights, the dataset or the method.[13] Lermen, Rogers-Smith and Ladish then generalized it with LoRA across Llama 2-Chat at 7B, 13B and 70B and on Mixtral instruct, on a single GPU, again for less than $200, driving refusal rates on two benchmarks to roughly 1% while holding general performance.[14]

That is the sentence policy design should start from: safety alignment is a property of a checkpoint, not of a capability. Release the checkpoint and you have released every checkpoint reachable from it for the price of a good dinner.

The case for open release

The case survives that finding anyway. Closed APIs concentrate power in a handful of US firms. Open weights are cognitive infrastructure for universities, startups, and states that will not send their data to a Californian endpoint. Security research needs them. Competition needs them. A Europe that only consumes closed models while regulating them is a colony with excellent paperwork. Responsible release norms, staged access for the most capable systems, and honest model cards beat security through obscurity, which never worked for cryptographic algorithms either.

That case does not require denying abuse. It requires adult tradeoffs, the same way open-source operating systems did.

Parallel: supply chain and trust theater

We already learned in software that a valid signature can escort malware, and that trust in maintainers is an attack surface.[15] Open weights add the same lesson to AI governance. The artifact moves faster than the office that wants to inventory it. Ethics that only audit the storefront will miss the loading dock.

What serious policy can still do

Law is not useless here. Article 2(12) already tells you where the leverage is: deployment, not distribution. So:

  • Punish fraudulent deployment of open models as products in the EU market, the chatbot that claims to be a doctor, using the Article 50 duties the open source carve-out never covered.
  • Fund evaluation and red-teaming of widely downloaded weights, on the model of the Article 55 duties, rather than waiting for a provider to volunteer.
  • Set norms for the cloud hosts renting the GPUs. Those are chokepoints with invoices; the weights are not.
  • Keep hard bans on specific harmful systems actually placed as services, where Article 5 already bites regardless of licence.
  • Avoid purity theater that criminalizes researchers while leaving commercial closed models as the only legal intelligence.

It cannot watermark a file into obedience. It cannot Annex a magnet link into safety.

Build ethics for the world where capable models are copyable, because the weights were always free. That means technical work on detection and defense, cultural work on release norms, industrial work so Europe is not only a customer, and legal work aimed at harm in deployment rather than the fantasy of a continent-sized license server.

You cannot watermark a file that never asked permission to exist. Plan accordingly.


  1. Regulation (EU) 2024/1689 (AI Act), Article 50(2): providers of AI systems generating synthetic audio, image, video or text “shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.” EUR-Lex, Article 50 (European Commission AI Act Service Desk).
  2. AI Act, Article 113: the Regulation applies from 2 August 2026, with Chapters I and II from 2 February 2025 and Chapter V (general-purpose AI models) from 2 August 2025. Chapter IV, which contains Article 50, takes the general date. EUR-Lex, Article 113.
  3. AI Act, Article 3(3) (‘provider’) and Article 3(10) (‘making available on the market’, defined as supply “in the course of a commercial activity, whether in return for payment or free of charge”). EUR-Lex, Article 3.
  4. OpenAI, gpt-oss-120b model card (August 2025), released under the Apache 2.0 licence alongside gpt-oss-20b.
  5. DeepSeek, DeepSeek-R1 model repository (January 2025): “This code repository and the model weights are licensed under the MIT License.”
  6. Meta, Llama 3.1 Community License Agreement: attribution requirement, “Built with Llama” notice, and a separate licence required above 700 million monthly active users.
  7. AI Act, Article 2(12): “This Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.” EUR-Lex, Article 2.
  8. AI Act, Article 53(1) and 53(2). The exemption covers only points (a) and (b), that is Annex XI technical documentation and Annex XII downstream information; the copyright policy (c) and the training-content summary (d) still apply, and the exception “shall not apply to general-purpose AI models with systemic risks.” Recital 104 states the same reasoning. EUR-Lex, Article 53.
  9. AI Act, Article 51(2): “A general-purpose AI model shall be presumed to have high impact capabilities pursuant to paragraph 1, point (a), when the cumulative amount of computation used for its training measured in floating point operations is greater than 10²⁵.” EUR-Lex, Article 51.
  10. AI Act, Article 55(1), points (a) to (d). EUR-Lex, Article 55.
  11. The Badge Is Not the Ethics (AI Act theater vs substance; watermarking as a compliance endpoint).
  12. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), in force 27 July 2026. It replaces Article 113(c) so that Chapter III Sections 1 to 3 apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I high-risk systems. EUR-Lex; consolidated AI Act as of 27 July 2026.
  13. Pranav Gade, Simon Lermen, Charlie Rogers-Smith, Jeffrey Ladish, BadLlama: cheaply removing safety fine-tuning from Llama 2-Chat 13B (2023).
  14. Simon Lermen, Charlie Rogers-Smith, Jeffrey Ladish, LoRA Fine-tuning Efficiently Undoes Safety Training in Llama 2-Chat 70B (2023).
  15. Shai-Hulud: The Malware With a Valid Signature.