Summary: AI Act obligations attach to roles, not organisations. Fine-tuning, substantially modifying, or rebranding a system or model can convert a deployer into a provider — with a much heavier compliance burden.
Sources: raw/Laws/Modifying AI Under the EU AI Act...md; raw/Laws/Providers of General-Purpose AI Models...md; raw/Laws/Overview of Guidelines for GPAI Models...md; raw/AI-regulations/Regulation - EU - 2024_1689.md
Last updated: 2026-07-28
Why the role matters
Providers carry the Chapter III Section 2 requirements (risk management, data governance, technical documentation, logging, transparency, human oversight, cybersecurity), conformity assessment, registration, post-market monitoring and incident reporting. Deployers carry a much shorter Article 26 list.
Becoming a provider by accident is therefore the central compliance risk for anyone building on top of someone else’s model.
What triggers the shift
“A shift in compliance responsibilities of the provider is triggered when an AI system gets modified and is high-risk, or when a GPAI model is significantly changed in its generality, capabilities, or systemic risk. This may be the case when a GPAI model is fine-tuned” (source: Modifying AI Under the EU AI Act…md).
Two distinct tests:
- AI systems — substantial modification of a high-risk system.
- GPAI models — significant change in generality, capabilities, or systemic risk.
The compute threshold for GPAI modification
“The European Commission chose to set relatively high compute-based thresholds for what qualifies as substantial modifications of GPAI models, and currently expects only few modifiers to become GPAI model providers” (source: Modifying AI Under the EU AI Act…md).
This is the practically important finding: routine fine-tuning does not make you a GPAI model provider. The Commission’s guidelines include an annex on “Training compute – definitions and estimation Methods” for working out where you sit (source: Overview of Guidelines for GPAI Models…md).
The obligations are bounded by the modification
“Keeping technical documentation and summaries of the GPAI model is limited to the scope of modification. In most cases, these are even required for other purposes than compliance” (source: Modifying AI Under the EU AI Act…md).
A downstream modifier who does cross the threshold documents their changes, not the base model.
Open-source status is losable
The Commission’s guidelines address “Monetisation and loss of open source status” as a distinct section (source: Overview of Guidelines for GPAI Models…md). The Art 53(2) exemption depends on a free-and-open-source licence permitting access, use, modification and distribution, with weights, architecture and usage information public — and never applies to models with systemic risk. See gpai-and-systemic-risk.
Security consequence: the supply chain of responsibility
For an integrator, three things follow:
- You may inherit a defect you cannot see. Art 53(1)(b) requires the upstream provider to give you enough documentation to “have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with [your] obligations.” If that documentation is thin, your own compliance is built on sand.
- You have a formal complaint channel. Downstream providers “may lodge a complaint against GPAI model providers” (source:
raw/Laws/Enforcement of Chapter V...md). See enforcement-and-penalties. - Fine-tuning can undo safety properties. T59 Abliteration includes “fine-tuning away alignment” as a technique. A modification that is below the compute threshold for provider status can still be well above the threshold for removing a safety behaviour. The regulatory line and the security line are in different places.
Practitioner cases in the source
The modification analysis works through two: an enterprise IT service provider, and an agentic AI platform at scale-up stage (source: Modifying AI Under the EU AI Act…md, “GenAI in action: practitioner’s examples and open challenges”). Its general recommendation is that “A proper assessment of the AI system, model and use case is key” and presumes the scope of the system/model and the provider role are already clear.