EU AI Act — Compliance Calendar and Self-Hosting Impact
Running a model purely internally for research/personal use is generally outside provider scope, but internal deployment in high-risk use-cases (HR screening) can trigger deployer duties.
The AI Act phases in, and the Digital Omnibus on AI (Regulation (EU) 2026/1744, published 24 July 2026, in force 27 July 2026) rewrote several later dates:
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited practices + AI literacy duty |
| 2 Aug 2025 | GPAI model obligations, governance, penalties |
| 27 Jul 2026 | Digital Omnibus enters into force |
| 2 Aug 2026 | Article 50 transparency rules + most remaining provisions; AI Office enforcement powers over GPAI providers |
| 2 Dec 2026 | Ban on NCII/CSAM-generating AI; machine-readable marking grace deadline for pre-2 Aug 2026 generative systems |
| 2 Aug 2027 | Compliance deadline for GPAI models placed on market before 2 Aug 2025 |
| 2 Dec 2027 | High-risk rules, stand-alone Annex III systems |
| 2 Aug 2028 | High-risk rules for AI in Annex I products |
Open-source exemption (Articles 53(2), 54(6)): providers of GPAI models released under a free and open-source licence that allows access, use, modification and distribution without monetisation, with weights/architecture/usage info publicly available, are exempt from maintaining technical documentation for authorities, providing downstream documentation, and (for non-EU providers) appointing an authorised representative. Three critical limits: 1. The exemption does not apply to systemic-risk GPAI models (>10^25 FLOP training compute) — those providers owe full obligations regardless of openness. 2. Even exempt providers still owe the copyright policy and training-data summary duties (Art. 53(1)(c)(d)). 3. Compliance may be demonstrated via an approved code of practice (Art. 56) or harmonised standards; otherwise the Commission assesses "alternative adequate means."
Self-hosting changes your obligations, not just your infra bill. Under the Act, obligations attach to providers and deployers, not to the act of running software on your own machine: - If you fine-tune or materially modify an open-weight model and place it on the EU market, you likely become a provider and inherit the corresponding duties (Art. 53), per Commission GPAI scope guidelines and 2026 legal analysis warning that even models you never sell can be in scope. - If you build an AI system on top of a GPAI model and deploy it, you are a downstream/deployer provider of that system — relevant where the system falls into high-risk categories (employment, education, critical infrastructure, biometrics) or falls under Article 50 transparency duties (chatbots must disclose they are AI). - Running a model purely internally for research or personal use is generally outside provider scope, but internal deployment in high-risk use-cases (e.g. HR screening) can trigger deployer duties once those dates arrive (Dec 2027 / Aug 2028). - Omnibus reliefs relevant to self-hosters: small mid-caps now get SME-style privileges; the bias-detection legal basis for processing special-category data was widened; AI literacy is softened to "take measures to support" development rather than guarantee a level. - Local inference is a strong GDPR lever: it removes the Article 28 data-processor obligation for a model provider entirely — no DPA, no cross-border transfer. But DPIA, disk encryption and telemetry hygiene still apply.
Sources
- https://huggingface.co/docs/hub/en/local-apps — Hugging Face's official "Use AI Models Locally" docs (llama.cpp, Ollama, Jan, LM Studio one-command flows)
- https://huggingface.co/learn/llm-course/en/chapter1/1 — Hugging Face LLM Course overview (structure, prerequisites, prerequisites, notebooks)
- https://huggingface.co/papers — Hugging Face Daily Papers (arXiv ranked by community upvotes)
- https://www.reddit.com/r/LocalLLaMA/ — r/LocalLLaMA, the local-inference community hub
- https://subriff.com/guides/best-subreddits-for-ai — r/LocalLLaMA membership/growth stats (844,249 members, ~60 posts/day, Sep 2026)
- https://prowlo.com/tools/subreddit-stats/localllama — Independent r/LocalLLaMA stats (820,305 members, 9 Sep 2026 crawl)
- https://dupple.com/learn/ai-news-for-developers — 2026 developer AI news reading list (Simon Willison, Latent Space, The Batch, HN, Daily Papers)
- https://aiwiki.ai/wiki/open_weight_license_comparison — Open-weight LLM licence comparison, verified July 2026 (per-model table: Apache-2.0/MIT vs Llama 700M MAU vs Gemma/MRL/OpenRAIL)
- https://opensource.org/ai/open-source-ai-definition — OSI Open Source AI Definition 1.0 (weights + architecture + usage info under OSI terms)
- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53 — EU AI Act Article 53 text incl. the 53(2) open-source exemption
- https://ai-act-service-desk.ec.europa.eu/en/ai-act/faq/how-does-ai-act-apply-general-purpose-ai-models-released-open-source — Official FAQ on the open-source exemption's limits (no systemic-risk models; copyright/training-data duties survive)
- https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers — Commission GPAI guidelines (provider duties, fine-tuning/modification triggers)
- https://corp-intl.com/news/what-is-the-timeline-for-implementing-the-eu-ai-act — Post-omnibus EU AI Act timeline, 16 Sep 2026 (Digital Omnibus 2026/1744, in force 27 Jul 2026; high-risk pushed to Dec 2027 / Aug 2028)
- https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai — Parliament legislative train on the Digital Omnibus on AI (7 May 2026 trilogue agreement)
- https://www.promptquorum.com/local-llms/local-llm-security-privacy-checklist — 12-point local LLM security checklist (telemetry defaults per tool, SHA-256 verification, localhost binding, pf/ufw egress blocking, GDPR/HIPAA/APPI/PIPL notes)
- https://safeguard.sh/resources/blog/model-supply-chain-poisoning-detection-2026 — 2026 model supply-chain threat model (pickle, trust_remote_code, weight backdoors, dataset poisoning, Sigstore signing, MITRE ATLAS, 9 HF takedowns in Q1 2026)
- https://docs.nvidia.com/cuda//cuda-toolkit-release-notes/index.html — CUDA 13.4 U1 release notes (driver no longer bundled since 13.4 Linux / 13.1 Windows; toolkit→R-branch table; minor-version compatibility)
- https://docs.nvidia.com/datacenter/tesla/drivers/latest/pdf/NVIDIA_Datacenter_Drivers.pdf — NVIDIA datacenter driver lifecycle (New Feature Branch vs Production Branch)
- https://rocm.blogs.amd.com/artificial-intelligence/language-models-locally/README.html — AMD's first-party "Practical Guide to Running LLMs on AMD Radeon GPUs" (19 Jun 2026)
- https://localaimaster.com/blog/amd-rocm-local-llm-setup — ROCm 7.2.x state-of-play, supported/unsupported GPU table, HSA_OVERRIDE_GFX_VERSION, ROCm vs CUDA comparison, ~96 tok/s on 7900 XTX
- https://rocm.docs.amd.com/projects/ai-ecosystem/en/latest/inference/vllm.html — Official vLLM-on-ROCm setup (prebuilt Docker image, ROCm 7.x)
- https://d-central.tech/cuda-vs-rocm-local-inference/ — CUDA vs ROCm vs Vulkan backend comparison for local inference
- https://freedom.tech/posts/2026-10-05-llama-cpp-0-6-0/ — llama.cpp 0.6.0 release notes (5 Oct 2026)
- https://machinelearning.apple.com/research/exploring-llms-mlx-m5 — Apple ML research: MLX on M5 Neural Accelerators (TTFT up to 3.97×, generation 1.19–1.27×, macOS 26.2+ requirement)
- https://developer.apple.com/videos/play/wwdc2026/232/ — Apple WWDC26: local agentic AI on the Mac with MLX
- https://codersera.com/blog/apple-silicon-llms-complete-guide-2026/ — Apple Silicon LLM guide (MLX vs vllm-mlx vs oMLX vs Ollama, unified-memory constraints)
- https://www.iunera.com/kraken/enterprise-ai/top-20-tools-to-run-llms-locally-in-2026-ollama-anythingllm-open-webui-lm-studio-vllm-and-every-real-alternative-compared/ — 20-tool local LLM comparison (difficulty, open source, enterprise readiness)
- https://presenc.ai/research/local-llm-vs-cloud-api-cost-2026 — Local vs cloud cost/TCO and breakeven analysis, updated October 2026
- https://www.promptquorum.com/local-llms/local-llms-vs-cloud-apis — Local vs cloud 8-factor comparison (privacy, cost, speed, quality, regional compliance)
- https://opentelemetry.io/blog/2026/genai-observability/index.md — OTel GenAI semantic conventions walkthrough (span attributes, metrics, Aspire Dashboard)
- https://signoz.io/docs/open-webui-monitoring/ — Open WebUI observability with OpenTelemetry
- https://docs.openwebui.com/features/administration/analytics/ — Open WebUI built-in analytics (usage, token consumption, per-model/per-user)
- https://github.com/prove-ai/observability-pipeline/blob/main/docs/guides/vllm-guide.md — vLLM + Prometheus GPU monitoring guide
- https://artificialanalysis.ai/hardware-inference-stack/laptops-workstations — Artificial Analysis local inference benchmark leaderboard
- https://artificialanalysis.ai/articles/aa-agentperf-local — AA-AgentPerf-Local: open-source local agent benchmark tool (29 Sep 2026)
- https://simonwillison.net/tags/local-llms/ — Simon Willison's local-LLM blog archive (165+ posts)
- https://www.turingpost.com/p/tools-for-model-deployment — Turing Post: 2026 open-source model deployment tooling overview
- https://www.datacamp.com/tutorial/gguf-format-a-complete-guide — GGUF quantization and sizing reference (7B FP16 ~14 GB vs Q4_K_M ~4–5 GB)
Date: 2026-10-09