Navigating Open-Source AI: A Foundation for Research?
This article investigates how AI systems provided as free and open-source software fit within the Act’s framework and what this means for the research community. It's the second part of the series "Unpacking the EU AI Act", by Patrick Brunner.
Building on the framework of the EU AI Act, we now examine how the provision of AI systems, particularly as free and open-source software, is navigated within this regulatory environment.
Following the introduction of AI systems and General-Purpose AI (GPAI) models in the previous blogpost, it is important to now explore how the provision of these systems is regulated under the AI Act, particularly when they are made available as free and open-source software. This part looks into the role of the provider, key definitions, and the regulatory boundaries for open-source AI systems.
Defining the Role of a Provider
The concept of a "provider" under the AI Act is central to understanding the regulation of AI system provision. According to Article 3(3):
"‘Provider’ means a natural or legal person, public authority, agency, or other body that develops an AI system or a GPAI model or has an AI system or GPAI model developed and places it on the market or puts it into service under their own name or trademark, whether for payment or free of charge."
Notably, the provider is not always the system's developer. Instead, the role is tied to the activities of placing the AI system on the market or putting it into service.
These terms are further clarified:
- Placing on the Market (Article 3(9)):
Refers to the first-time availability of an AI system on the EU market. - Making Available on the Market (Article 3(10)):
Refers to the supply of an AI system for distribution or use as part of a commercial activity, whether for payment or free of charge.
For the research community and proponents of open science, these distinctions are critical. The release (Article 2 (11)) of an AI system under a free and open-source license does not fall under the AI Act unless:
- The system is placed on the market or put into service as a high-risk AI system.
- The system is placed on the market or put into service as an AI system that falls under prohibited AI practices (Article 5) or transparency obligations (Article 50).
What Does "Release" Mean Under the AI Act?
While the AI Act does not explicitly define "release," several interpretations help clarify its scope:
- The French version of Article 2(12) uses the term “publiés” (published), suggesting public availability through open repositories.
- The German version of recital 102 uses the term “freigegeben” (released), emphasizing the licensing under non-proprietary, open-source terms.
In practice, this means the provision of an AI system under a free and open-source license—allowing users to freely access, modify, and redistribute the software—can qualify as a "release." This remains valid even if the release is limited to a small group of recipients. Importantly, such releases are exempt from the AI Act’s obligations unless monetized or tied to regulated use cases.
Releasing vs. Placing on the Market
A key distinction under the AI Act is that placing on the market inherently involves a commercial activity. While the Act does not fully define what constitutes a commercial activity, Recital 103 specifies that:
- Monetizing an AI system or its surrounding services constitutes a commercial activity.
- Non-commercial distribution, such as making AI systems available on repositories like GitHub, does not qualify as monetization.
For instance, the EU Commission's "Blue Guide" defines commercial activity as providing products in a business context.[1] Whether this applies depends on specific factors, such as how regularly the product is supplied, its characteristics, and the supplier's intentions, even for non-profit organizations. [2]
Analogies with the Cyber Resilience Act (CRA)
To address these ambiguities in the AI Act, insights from the Cyber Resilience Act (CRA) can be helpful. Recital 15 of the CRA clarifies that commercial activity includes:
- Charging for access to software or related services,
- Monetizing through data collection for non-security purposes,
- Accepting donations exceeding the actual costs of development or provision.
In contrast, free and open-source software that is not monetized is explicitly excluded from being considered commercial under the CRA. This principle aligns with the AI Act’s approach.
Free and Open Software Needs To Exclude Commercial Activity
The conclusion about commercial activity is clear: under the AI Act, the benefits for free and open-source software do not apply if the software is monetized. Similarly, the CRA states that free and open-source software provided without monetization is not considered a commercial activity. The EU Commission’s "Blue Guide" supports this, emphasizing that a business-related context is required to classify an activity as commercial. For example, releasing an AI system on an open repository like GitHub under a free and open-source license without monetization is not considered commercial because it lacks economic benefit. However, if services around the system are monetized, this counts as commercialization. Additionally, how the development of the AI system is funded does not determine whether its provision is classified as commercial.
To benefit from the AI Act’s exemption for free and open-source AI systems, the following conditions should be met:
- The system qualifies as an AI system under the AI Act.
- It is licensed under a free and open-source license.
- It is made available on an open repository.
- It is provided free of charge and is not monetized in any way.
If all these conditions are satisfied, the release of the AI system is exempt from the Act’s regulations. However, the exemption does not apply to a monetized provision of an AI system or the use of an AI system, which is specifically regulated under the risk classification of the AI Act. The Act’s approach to distinguishing between commercial and non-commercial activities highlights its potential to support open science and collaborative research, however it needs to remain aligned with regulatory requirements when used for commercial purposes.
[1] EU Commission, The ‘Blue Guide’ on the implementation of EU product rules 2022, 2022/C 247/01, Chapter 2.2.
[2] EU Commission, The ‘Blue Guide’ on the implementation of EU product rules 2022, 2022/C 247/01, Chapter 2.2.


