The EU AI Act: Application to Open-Source Projects

Orrick, Herrington & Sutcliffe LLP

This update is part of our EU AI Act Series. Learn more about the EU AI Act here.

The EU AI Act only regulates certain covered AI-related technologies — AI systems and General-Purpose AI Models (GPAIMs).

We are often asked whether the AI Act’s definitions and obligations apply to open-source projects and the answer is often “yes.”

Open-Source Exception for AI Systems are Surprisingly Limited

Article 2 of the AI Act states that the regulation does not apply to AI systems released under free and open-source licenses.

However, this exception does not apply to AI systems placed on the market or put into service in the EU as Prohibited AI or High-Risk AI, or AI systems that otherwise interact directly with individuals or expose individuals to AI-generated content (Individual-User-Facing AI). Given that these types of AI systems are collectively subject to most of the obligations under the Act, the open-source AI system exception ultimately has little practical effect.

Open-Source Exception for GPAIMs is Broader, but still Limited

In contrast, the AI Act provides an exception to GPAIMs released under free and open-source licenses that allow for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage are made publicly available. This exception, however, only applies in relation to two obligations imposed on GPAIM providers: (i) drawing up technical documentation on the model, and (ii) making available certain information and documentation to providers of AI systems who intend to integrate the GPAIM into the system. Other obligations remain intact. In addition, the exemption is not available for GPAIMs with systemic risk.

What Does This Mean for Your Open-Source AI Strategy?

Organizations that develop or plan to develop or use open-source AI technologies should consider the following:

  • The open-source exemptions to the AI Act are limited, so compliance with the AI Act may be required even if an AI system or model is licensed under a free and open-source license.
  • An organization may nonetheless still benefit from a lessened compliance burden where AI systems it develops or deploys are subject to free and open-source licenses, and are not otherwise monetized (including through the provision of technical support or other services).
  • There can also be other benefits of releasing open-source AI systems and models (including bolstering innovation and deployment, enhancing the provider’s reputation and spotlighting other paid services offered by the provider), as well as using open-source AI systems and models (including potential cost and time savings, ease of availability and heightened insights into model parameters, weights and architecture).
  • However, just like any open-source software, there are also potential drawbacks:
    • Open-source licenses will typically disclaim all warranties and liabilities.
    • An increasing number of providers are releasing models under “open-source” licenses that actually impose a fair number of restrictions uncommon in traditional open-source software licenses (e.g., additional commercial terms for large companies).
    • Open-source AI systems and models are often made available on public websites and repositories, which presents a heightened risk for downloading harmful files.
    • Licenses may include copyleft provisions or quick termination triggers that could impact the long-term viability of the solution or IP rights and configurations.
    • It may be difficult to answer questions regarding the data used to train the AI system or model, or how the AI technology works.

Regardless of the strategy the organization chooses in relation to open-source AI technologies, it will be important to ensure the AI compliance components are properly integrated with other related compliance procedures, including those relating to general open-source software.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Orrick, Herrington & Sutcliffe LLP

Written by:

Orrick, Herrington & Sutcliffe LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Orrick, Herrington & Sutcliffe LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide