Module 5 of the AI Act GPAI certification: when modification makes you the provider of a model, what the open-source relief covers, and the Art. 54 authorised representative for third-country providers.
This module answers the question every engineering team eventually asks: we took someone else's model and changed it — what are we now?
Two separate questions, always
The confusion in this area comes from collapsing two questions into one. Keep them apart:
Question 1 — Are we the provider of a MODEL? This is a Chapter V question about what you did to the model artefact.
Question 2 — Are we the provider of a SYSTEM? This is a Chapter II/III question, and if you built a product on the model and put it into service under your own name, the answer is yes regardless of what you did to the model.
An organisation that fine-tunes an open model and ships an assistant is certainly the provider of the system. Whether it is also the provider of a model is the harder question.
Where the line sits
The Regulation does not give a bright-line test for when modification makes you the provider of a modified model, and no honest treatment pretends otherwise. What it gives is a direction of travel, and the direction is about substance.
Factors that push toward provider status:
- The modification materially changes the model's capabilities — what tasks it can competently perform, not just how well it performs one.
- The modification involves substantial additional training compute relative to the original.
- The result is placed on the market or put into service as a model in its own right, rather than embedded in your system.
- You present it under your own name as a model.
- The modification changes the risk profile in a way the original provider did not contemplate.
Factors that push away:
- Light adaptation for a narrow downstream task.
- Adaptation that does not extend generality — the model is not now competently performing a wider range of distinct tasks.
- The adapted artefact never leaves your system.
There is a useful parallel with Art. 25 on the system side: the test there is whether the change was foreseen in the original assessment and whether it affects compliance or alters intended purpose. The instinct is the same — has the thing become, in substance, a different thing.
The practical control is documentation. Record, at the time: the base model and version; what you did — fine-tune, LoRA, continued pre-training, distillation, merge; how much compute; what changed in evaluated capability; and what you concluded about provider status and why. That record is worth more than any general rule, because the question will be asked years later by someone who was not there.
If you are the provider of a modified model
Chapter V attaches to your version:
- Art. 53(1)(a) — Annex XI technical documentation for your model.
- Art. 53(1)(b) — Annex XII information to anyone integrating it.
- Art. 53(1)(c) — a copyright policy. Note this covers your additional training data; you inherit no shelter from the base model provider's policy.
- Art. 53(1)(d) — a public summary of the content used for training. In practice this describes your additional data and identifies the base model.
And if the cumulative compute — including what the base model consumed — crosses the Art. 51 threshold, the systemic-risk regime is in play and the Art. 53(2) open-source relief is unavailable.
The open-source relief, precisely
Art. 53(2) relieves providers of models released under a free and open-source licence that allows access, usage, modification and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available, from the obligations in Art. 53(1)(a) and (b).
Read as three cumulative conditions:
- The licence permits access, use, modification and distribution.
- The weights are public — not gated behind an application, not restricted to approved uses.
- Architecture and usage information are public.
A "weights-available" release under a licence restricting fields of use is unlikely to qualify. Neither is an open licence over weights nobody can obtain.
And the two limits again, because they are where organisations get caught:
(c) and (d) survive the relief. Copyright policy and public training-content summary apply to open-source models.
The relief does not apply to systemic-risk models at all. An openly released frontier model owes the full Art. 53 set plus Art. 55.
Art. 54 — authorised representatives
Providers of general-purpose AI models established in third countries shall, prior to placing a model on the Union market, appoint by written mandate an authorised representative established in the Union.
The representative:
- verifies that the technical documentation specified in Annex XI has been drawn up and that all obligations under Art. 53 and, where applicable, Art. 55 have been fulfilled by the provider;
- keeps a copy of the Annex XI technical documentation at the disposal of the AI Office and national competent authorities for ten years after the model has been placed on the market, and the contact details of the provider that appointed it;
- provides the AI Office, upon a reasoned request, with all the information and documentation necessary to demonstrate compliance;
- cooperates with the AI Office and competent authorities on any action they take in relation to the model.
The mandate shall empower the representative to be addressed, in addition to or instead of the provider, by the AI Office or the competent authorities on all issues related to ensuring compliance.
The representative shall terminate the mandate if it considers or has reason to consider that the provider acts contrary to its obligations, and shall immediately inform the AI Office, giving reasons. That is a meaningful safeguard: the representative is not a mailbox.
Art. 54 does not apply to providers of models released under a free and open-source licence meeting the conditions above that do not present systemic risks.
Check yourself
- We applied a small LoRA to an open model for our support product. — Almost certainly not a model provider, but certainly the provider of the system you built. Record what you did and why you concluded that.
- We continued pre-training an open model on a large corpus and released the weights. — Likely the provider of that model, with the full Art. 53 set attaching to your version, including a copyright policy covering your data.
- Our open model is behind an application form. — The relief requires the parameters to be publicly available. Gated weights are unlikely to qualify.
- We are a US company serving a model to EU customers via API. — Art. 54 requires an authorised representative established in the Union appointed by written mandate, unless the open-source, non-systemic-risk relief applies.
Previous: Module 4 — Codes of practice and the standards gap Next: Module 6 — Building downstream →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
It depends on the extent of the modification. Light adaptation for a downstream task generally does not; modification producing what is in substance a different model, or materially changing its capabilities or its risk profile, can. Where it does, the Chapter V obligations attach to your version — and where systemic risk is in play, the compute you added counts toward the assessment.
Art. 53(2) relieves providers of models released under a free and open-source licence — allowing access, usage, modification and distribution, with parameters including weights, architecture information and usage information publicly available — from the Annex XI technical documentation and the Annex XII downstream-information duties. It does not relieve them of the copyright policy or the public training-content summary, and it does not apply at all to models with systemic risk.
Yes. Art. 54 requires providers of general-purpose AI models established in third countries to appoint, by written mandate, an authorised representative established in the Union before placing the model on the Union market. The representative keeps the technical documentation at the disposal of the AI Office and national competent authorities and cooperates with them. There is a corresponding relief for open-source models that do not present systemic risk.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.