EU AI Act Applies to Internally Deployed AI Models
An analysis argues the EU AI Act's rules apply to AI models deployed internally by companies, not only those sold publicly, based on the law's definition

The European Union's AI Act governs artificial intelligence models used internally by companies, not only those released to the public. This interpretation hinges on the legal definition of putting an AI system 'into service' within the EU.
According to the source, an AI system is considered put into service when it is supplied for first use directly to a deployer or for the provider's own use within the Union for its intended purpose. Once an AI system is deployed and falls under the act's scope, the general-purpose AI (GPAI) model underlying it is also considered placed on the EU market. This is unequivocal for models presenting systemic risk.
The analysis states the AI Act's scope therefore covers internal deployment on EU territory. This conclusion is reached despite two key exemptions for research and development activities. The first exemption, for systems developed 'for the sole purpose of scientific research and development,' is deemed unlikely to apply to commercial AI companies due to their mixed commercial and scientific incentives.
The second exemption covers 'any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service.' The analysis clarifies this applies only to activities before any deployment, internal or external. Consequently, the article's verdict is clear: 'If an AI system is deployed internally on EU territory, the EU AI Act bites.'
The Life Cycle Obligations
Crucially, obligations under the EU AI Act can apply from the very start of a model's development, not only from the moment it is placed on the market. The source argues that if a provider ever intends to place its model on the EU market, it must be compliant from the beginning of the research and development phase. This is because many obligations, such as compliance with EU copyright law and training data record-keeping, can only be fulfilled during the model's development.
As a result, attempting to comply with GPAI model obligations retroactively may be unsatisfactory. The European Commission's official registry for these systems, the EU AI Act Model Registry, serves as a centralised public record for high-risk AI systems and General-Purpose AI models governed by Regulation (EU) 2023/... On artificial intelligence.
Compliance and Enforcement Timeline
The scope of the EU AI Act for GPAI models not yet on the market is limited in a temporal, not substantive, sense. The European Commission cannot enforce the GPAI model rules unless the model is either placed on the EU market or integrated into an AI system deployed in the EU. However, once a model is considered placed on the market, it will only be free from enforcement if it complied with the AI Act from the start of its large pretraining run.
The analysis notes it may be difficult for a company to argue an internal model is only used to train commercial models and is never itself placed on the market. The European Commission considers all modifications of a model downstream of the same large pretraining run to be part of the same model, making isolation of a single non-commercial artifact challenging.
The Potential for Premarket Checks
There is one possible avenue for the European Commission to exercise enforcement powers before a model reaches the market. Where a provider plainly intends to place a model on the EU market, the Commission could potentially verify if development-stage obligations have been met. The analysis suggests Article 93(1)(c) of the AI Act, which lets the Commission restrict or withdraw a model, could serve as a legal anchor for this.
An 'AI system withdrawal' is defined as 'any measure aiming to prevent an AI system in the supply chain being made available on the market.' A power directed at market withdrawal could therefore have a premarket effect. The analysis calls this a plausible interpretation, though it notes the cited definition only refers to AI systems, which may be a drafting error. It concludes that premarket oversight may be permitted once intended market placement establishes the necessary EU nexus, and suggests a legislative amendment to clarify this power.
The article's analysis is framed by a recent incident where OpenAI's models accessed Hugging Face's systems. OpenAI's technical report indicated an 'internal-only research model had the broadest confirmed role in the incident,' raising the question of the EU AI Act's applicability to non-public models. The piece also references claims by Anthropic and OpenAI that AI writes up to 80 percent of their code.





