Compliance & governance: Local AI model sovereignty within the framework of the EU AI Act

The selection of specific model architectures as well as the optional fine-tuning or complete training of your own AI models are essential instruments for meeting the regulatory requirements of Regulation (EU) 2024/1689 (AI Act) and minimizing liability risks. The following text makes no claim to legal completeness, but is intended to provide interested readers with a good introduction to the topic.

EU AI Act: avoiding systemic risks and strict GPAI obligations with legal certainty

A major advantage of the model selection option is the option to control the classification as a general purpose AI(GPAI) model provider in accordance with Art. 51. By opting for specialized, more compact models whose training effort is below the threshold of 10 to the power of 25 FLOPS, the far-reaching obligations for models with systemic risk, as defined in Art. 52a to 55, can be avoided.

The selection of architectures tailored precisely to the use case reduces the complexity of training, operation and conformity assessment. From a legal perspective, this approach ensures that the responsible company does not unintentionally fall into the strictest regulatory category, which would require, among other things, extensive coordination and notifications to, for example, the Federal Network Agency as the central body for the German state (Art. 52b).

EU AI Act Art. 10 & 15: Compliance through AI fine-tuning and curated data

AI Model fine tuning

Fine-tuning the language and vision models as well as other AI models enables the implementation of the governance requirements according to Art. 10. While public standard models (OpenAI, Gemini, etc.) are often based on heterogeneous, potentially biased public data, local fine-tuning allows the use of curated, proprietary data sets.

The aim of selecting, fine-tuning or training specific models is to significantly increase accuracy and robustness in accordance with Art. 15. Fulfilling these requirements is essential, especially for high-risk AI systems in accordance with Annex III.

By accessing the weights of the model during fine-tuning and using bias detection algorithms, distortions can be minimized or avoided in a targeted manner. This level of control is technically impossible when using external cloud APIs. The operator of an AI application bears the residual risk for violations under the AI Act and cannot pass this on to the respective provider for a language model, for example.

EU AI Act Art. 10 & 15: Compliance through AI fine-tuning and curated data

Auswahl eines KI-Modells in DookuSense

The AI Act requires detailed information on the training methods, computing resources and validation processes. With regard to the technical documentation in accordance with Art. 11 and Annex IV, the combination of model selection and local fine-tuning, in contrast to closed models, offers the possibility of almost complete traceability (“chain of custody”).

The implementation of human supervision in accordance with Art. 14 is also simplified by the choice of model, etc. A fine-tuned model can be trained in such a way that it issues explicit warnings in the event of uncertainties or shows alternative results with corresponding confidence intervals.

This methodology makes it easier for the human observer/supervisor to critically scrutinize results and calculations, intervene and provide feedback, thus raising the level of transparency towards the user required by Art. 13 to a very high level. An example of implementation within the DookuSense application from Open Logic Systems (Open LS) is shown inside the screenshot.

Questions about the AI Act?