Back

Before adopting 'free' AI models: what European and Asian companies should weigh

July 29, 2026

A year ago, running a capable AI model meant paying a frontier provider by the token.

Then a run of open-weight releases changed the maths. DeepSeek showed that a strong model could be trained and given away at a fraction of the usual cost, and this month Moonshot AI's Kimi K3 pushed the point further. For a European business, a capable model you can download and run for nothing is an appealing prospect. It is also where the word "free" starts to do a lot of quiet work.

Free here means free of a licence fee. It does not mean free of responsibility, and in Europe that distinction has teeth.

Free of cost, not free of obligation

Two things travel with any AI model regardless of what it costs to acquire: the EU AI Act, and, the moment personal data is involved, the GDPR. Neither cares whether you paid for the model.

There is a widespread assumption that open-source AI sits outside the AI Act. It does not, at least not in the way people assume. The Act does give open-source general-purpose models a lighter regime. Providers are relieved of some documentation duties and, if they are based outside the EU, of the need to appoint a European representative. But two obligations survive no matter how open the model is. The provider still has to publish a summary of the data the model was trained on, following the AI Office's template, and still has to comply with EU copyright law. The copyright obligation is the one most often missed.

The exemption also has a ceiling. If a model is large enough to count as posing systemic risk, a bar set high enough that most models a business would adopt sit well below it, the full set of obligations applies regardless of the licence. And from 2 August this year the AI Office gains its full enforcement powers, including the ability to request information, order changes to a model, and issue fines. The regime has moved from something on paper to something with a live enforcement arm.

The moment you become the provider

Much of this is the model maker's concern rather than yours. Often that holds. But the Act has a line that reaches adopters, and it is worth knowing where it sits. If you take an open model and fine-tune it using a significant share of the original training compute, currently framed as roughly a third, you are treated as a new provider, with the obligations that follow. Fine-tuning lightly on your own data is one thing. Retraining at scale quietly shifts the legal weight onto you.

Responsibility can land on you a second way. If you embed an open model inside a system the Act classifies as high risk, such as something touching recruitment, credit decisions, or access to essential services, the compliance duty for that system is yours as the deployer, whatever the model's licence says. The openness of the model buys you nothing in that setting.

Where the China question actually bites

Much of the recent momentum in free models has come from China, and that has made some European teams uneasy. Part of that caution is warranted. But it pays to be precise about where the risk actually sits, because the answer changes completely depending on how you use the model.

Using a hosted Chinese service, calling an API at deepseek.com for example, is where European businesses run into difficulty with personal data. China has no adequacy decision under the GDPR, the usual transfer safeguards are not in place, and routing European personal data through such a service is hard to square with the law. Regulators have already moved. Italy's authority blocked the DeepSeek app, Germany's Berlin commissioner pushed Apple and Google to remove it, and investigations opened across a string of member states. The common thread in every one of those actions is the hosted service and where the data ends up.

Running the open weights yourself, on European infrastructure, is a different matter entirely. When you download the model and host it in your own environment, the data never leaves your control and never travels to China. The same weights that are a problem as a hosted foreign service can be perfectly workable when you run them locally. This is the distinction worth holding onto: the risk usually lives in the hosting and the data path, not in the weights themselves.

Self-hosting is not a blanket clearance. You still carry the AI Act duties described above, and you should still satisfy yourself about a model's provenance and how it was trained. But it does mean a capable open model of Chinese origin is not automatically off the table for a European company. It depends on how you run it.

What to weigh before you adopt one

Before committing to a free model, we would work through a short set of questions with a client:

  • Licence. Is it genuinely open, permitting use, modification and redistribution, or a restricted "open-ish" licence with commercial limits? The label affects both your rights and your obligations.
  • Hosting and data path. Will you self-host on infrastructure you control, or call a hosted service? For anything touching personal data in Europe, this is usually the decisive question.
  • Provenance. Do you know who trained the model, on what, and whether the training-data summary and copyright position are documented? Gaps here become your problem once you deploy.
  • Use-case risk. Does the system you are building fall into a high-risk category under the AI Act? If so, plan for the deployer obligations from the start rather than retrofitting them.
  • Scale of modification. Are you fine-tuning lightly, or retraining heavily enough to become a provider in your own right?

None of this is a reason to avoid open models. We use them, and recommend them, wherever they are the better tool for the job. The point is only that "free" describes the price and very little else.

Where we land

The arrival of strong, free models is good news for European businesses. It lowers the cost of building with AI, and when self-hosted it can give you more control over data and sovereignty than a foreign API ever will. What it does not do is remove the need to think. The obligations attached to any AI system still apply, and in Europe they are becoming more concrete by the month.

Adopted deliberately, with attention to licence, hosting and use case, a free model is a real advantage. Adopted casually, on the assumption that open means unregulated, it becomes a liability you discover later. If you are weighing which open models to bring into your stack, and how to do it in a way that holds up in Europe, that is a conversation we are glad to have.

Author

Chairunnisa Irianto

Nisa is a Marketing Manager at Itsavirus, a strategic software development partner working with companies across Europe and Southeast Asia. She writes about AI, application modernisation, and how businesses turn technology into practical results.

Latest insights

A sharp lens on what we’re building and our take on what comes next.

See more
How to build a knowledge base that gets smarter over time with Obsidian and Claude Code
Your AI keeps forgetting. Here's how to stop repeating yourself
OpenClaw is exciting. But, here's what you need to secure before you experiment

Latest insights

A sharp lens on what we’re building and our take on what comes next.

See more
Why the answer is a platform, not another tool
RAG: the key to turning a demo into a dependable process
Continuous modernisation: turning legacy debt into competitive advantage

Latest insights

A sharp lens on what we’re building and our take on what comes next.

See more
Choosing an AI model just stopped being simple, and 25 US tech companies are fighting to keep it that way
Claude Fable 5: Launched, praised, then pulled within 3 days
Dashboard showing wildfire anomaly alerts across Indonesia, generated from NASA satellite data by the open-source WildfireDetect system.
We built an open-source wildfire detection system. Here is what we learned.

Latest insights

A sharp lens on what we’re building and our take on what comes next.

See more
Workshop : From Idea to MVP
Webinar: What’s next for NFT’s?
Webinar: finding opportunities in chaos

Latest insights

A sharp lens on what we’re building and our take on what comes next.

See more
How we helped Ecologies to turn survey results into reliable, faster reports using AI
How to deal with 1,000 shiny new tools
Develop AI Integrations with Itsavirus
No items found.