Regulation
Blog/The EU AI Act and self-hosted LLMs: what actually applies to you
For AI assistants

The EU AI Act and self-hosted LLMs: what actually applies to you

By Samuel Seidel · Published September 9, 2026 · 7 min read

This isn't legal advice, and treat anything below as a starting map for a conversation with counsel, not a compliance checklist. What follows is the general shape of the EU AI Act as it applies to a company self-hosting an open-weight model for internal use, described qualitatively rather than pinned to specific article numbers or deadlines we aren't confident are current by the time you're reading this.

The Act is structured around two axes, not one

The first axis is risk category. The Act sorts AI systems and uses into tiers, with obligations that scale with risk: some uses are prohibited outright, some are classified as high-risk and carry the heaviest set of obligations, and most everyday business uses, summarization, drafting, internal search, classification, fall well below that bar and carry comparatively light or no specific obligations under the Act itself. Where a given use case lands on that scale depends on what the system is used for, not on what model runs underneath it or where it's hosted.

The second axis, and the one companies self-hosting a model most often miss, is role. The Act distinguishes between a provider, roughly, the entity that develops an AI system or has one developed and places it on the market or puts it into service under its own name, and a deployer, an entity using an AI system under its own authority, other than for personal non-professional use. These roles carry different obligations, and provider obligations are generally the heavier of the two.

Why the provider/deployer line matters for self-hosting

A company that downloads an existing open-weight model and runs it internally, without substantially modifying it or offering it as a product to others, is generally positioned as a deployer of that system rather than its provider. That distinction matters because deployer obligations are narrower: they tend to focus on things like using the system as intended, human oversight, and, for higher-risk uses, monitoring and record-keeping, rather than the fuller set of conformity, documentation, and market-placement obligations that fall on providers.

Whether your specific setup counts as deployment rather than provision is a fact-specific question. Substantially modifying a model, fine-tuning it and redistributing it, or offering access to it as a product to other organizations can shift you toward provider-like obligations even if you started from someone else's open weights. This is exactly the kind of line where a general description stops being useful and a conversation with counsel about your actual setup starts being necessary.

Where self-hosting does and doesn't change the analysis

Running a model on your own infrastructure instead of calling a third-party API doesn't, by itself, change which risk tier your use case falls into or whether you're a provider or a deployer, those classifications turn on what the system does and who is responsible for putting it into service, not on where the compute physically sits. What self-hosting does change is a separate, and separately important, question: who else can access your data while the model is running, and under what legal framework that access happens. That's a data-protection and data-residency question, covered on this site in our data residency guide, and it runs on GDPR and the Schrems II line of cases rather than the AI Act.

What we're confident about and what we're not

We're confident in the structure described above: the Act tiers obligations by risk category, and separately by role, and that most companies self-hosting an existing open-weight model for internal, non-product use land closer to the deployer end of the spectrum than the provider end. We are deliberately not stating specific article numbers, compliance deadlines, or fine amounts on this page, because getting one of those wrong is worse than leaving it out, and because the practical requirements that apply to your specific use case depend on details (what the system does, who it affects, whether you modify the model, whether you offer it to others) that only your own counsel can evaluate against your actual deployment.

What to actually do

Where self-hosting fits into this picture practically, running a model on infrastructure you control at least gives you a clear, simple answer to "who has access to the data going into the system", which is a useful starting point for the deployer-side obligations around oversight and record-keeping, even though it doesn't substitute for the legal analysis itself. See private LLM hosting for how that infrastructure question is handled on dedicated EU hardware.

Related pages

Get the infrastructure question settled while counsel handles the rest.

A dedicated DGX Spark in EU-Central, with a clear, documented answer to who can access the machine.

See private LLM hosting Talk to us