There’s a ton of bad information going around about the EU AI Act, especially what it means for private LLMs. People think it only applies to public apps, or that if their model is proprietary, they’re off the hook. The truth is a lot messier, with some serious consequences that companies need to get a handle on right now.
Key Takeaways
- The AI Act calls LLMs “general-purpose AI models,” and even your private ones will have to meet transparency and risk management rules.
- If you build private LLMs, you’re on the hook for solid data governance, model documentation, and human oversight to stay compliant.
- Using LLMs for high-risk stuff like hiring or credit scoring? Get ready for tougher rules, like mandatory fundamental rights impact assessments.
- To comply, you’ll need to run a full internal audit of every single LLM you use, public or not.
- Fail to comply and you’re looking at massive fines, up to 7% of global annual turnover or €35 million, whichever is bigger.
Myth 1: The EU AI Act Only Targets Public-Facing AI Systems
Lots of people think the EU AI Act is only for AI that touches the public, like a customer service chatbot. That thinking completely ignores the Act’s wide definition of an AI system and its risk-based tiers. The law’s text is super broad, defining an AI system as “a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” That definition covers just about any LLM you can think of, no matter how it’s deployed. What about an internal LLM a bank uses for fraud detection, or one a law firm uses to sort through case law? These aren’t public, but their outputs drive huge decisions. The Act pegs LLMs as “general-purpose AI models,” a tag that alone comes with duties for providers, even for models that never leave the company walls. The European Parliament’s press release on the final agreement made it clear that these general-purpose models have transparency requirements, which means even your internal tools now need technical documentation, data governance policies, and a full risk management plan.
Myth 2: Private LLMs Are Exempt from High-Risk Classifications
It’s a common, and frankly, dangerous, misinterpretation of the AI Act to think that just because an LLM is private and internal, it can’t be classified as “high-risk.” The risk level isn’t about public access. It’s about the model’s intended purpose and how it could affect people’s fundamental rights. Annex III of the Act lays out a whole list of things that are automatically high-risk, including AI systems used in employment, worker management, and access to essential private services (like credit scoring or insurance). So if your HR department deploys a private LLM to screen resumes or run performance reviews, that system is squarely in the high-risk category because it directly impacts people’s jobs. It’s internal, but so what? The European Commission’s official site is clear: systems affecting employment are high-risk. That classification kicks off a whole new set of obligations: you’re now required to do fundamental rights impact assessments, build in strong human oversight, and meet tough standards for data quality and cybersecurity. Keeping an LLM behind your firewall does nothing to get you out of these regulatory duties if its application has a major impact on people’s lives.
Myth 3: Compliance is Solely the Responsibility of the LLM Developer
Here’s another myth: the idea that compliance is someone else’s problem, specifically, the problem of whoever built the foundational model. While the original developers do have a ton of responsibility for their general-purpose AI models, the AI Act puts a heavy load on the “deployer” too (that’s you, the company actually using the AI). Article 29 is pretty explicit about the duties for deployers of high-risk systems: you have to ensure human oversight, monitor the system while it’s running, keep records, and deal with any risks that pop up. Let’s say you license a big LLM from a vendor and then fine-tune it for an internal, high-risk job like medical diagnostics. The vendor has to meet their own standards, sure, but you are responsible for making sure *your specific application* of that model is compliant. That includes running your own conformity assessment, making sure your fine-tuning data is clean and unbiased, and monitoring it after launch. A report from the European Union Agency for Cybersecurity (ENISA) really drives home this point about shared responsibility, stating that deployers can’t just assume compliance, they have to actively check it for their specific use case. You can’t just buy a compliant model and wash your hands of it. You are an active participant in the compliance process.
Myth 4: Existing Data Protection Regulations Are Sufficient for Private LLMs
Don’t assume that because you’re GDPR-compliant, you’re all set for the EU AI Act. There’s some overlap, yes, especially around data quality, but the AI Act brings a whole new set of rules that go way beyond data protection. GDPR is all about how you process personal data, think rights of access, correction, and deletion. The AI Act, on the other hand, cares about the outputs and behavior of the AI model itself, even if it never touches a single piece of personal data. For instance, what if your internal LLM is just generating synthetic data for testing, or running sentiment analysis on anonymized public comments? GDPR might not apply, but the AI Act still demands transparency about the model’s capabilities, its biases, and its stability, especially if those outputs feed into a high-risk decision. The Act requires specific technical documentation, logging, and human oversight that GDPR doesn’t touch. It also requires you to handle bias detection and mitigation right from the design phase, which is a much bigger task than just data privacy. Both the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have pointed out that these laws work together, but being compliant with one doesn’t mean you’re compliant with the other.
Myth 5: The Impact of the AI Act on Private LLMs is Minimal for Non-EU Companies
If you’re a non-EU company, don’t make the mistake of thinking the EU AI Act can’t touch you. That thinking ignores the Act’s extraterritorial reach, which works a lot like GDPR’s. The EU AI Act applies to anyone providing or deploying an AI system if that system’s output is meant to be used in the Union. It’s that simple. So, if a US-based multinational uses a private LLM to manage its European employees or to handle customer data from its EU business, it falls under the Act’s rules. It doesn’t matter if the servers are in Ohio. The impact is in the EU, so the law applies. Because of this, any global company with EU customers or operations needs to review its internal LLM use against the Act’s standards. The European Parliament’s own guidance confirms this, telling global firms to get their AI governance strategies in line with EU rules. Blowing this off is a bad idea, as it could lead to massive penalties, we’re talking up to 7% of your global annual turnover. Proactive compliance is critical. The EU AI Act is changing AI governance for everyone, reaching deep inside companies to regulate private LLMs. You have to accept that using a model internally doesn’t give you a free pass, especially for high-risk applications. Auditing all your LLM uses and building strong compliance frameworks aren’t just good ideas anymore. They’re essential to operate in this new regulatory world.
What does the EU AI Act mean by a “general-purpose AI model”?
It’s an AI model, like a large language model, that has a wide range of potential uses and can be built into many other AI systems. Under the Act, the providers of these models have specific transparency and risk management duties, no matter what the model is eventually used for.
What counts as a “high-risk” AI system under the Act?
These are systems that could seriously harm someone’s health, safety, or fundamental rights. The Act lists specific high-risk categories: critical infrastructure, education, employment, law enforcement, migration, and the administration of justice. What determines the risk is the system’s intended purpose, not whether the public can access it.
Can we really get fined for how we use an LLM internally?
Absolutely. You can get hit with huge fines for a non-compliant internal LLM, especially if it’s considered high-risk or you fail to meet your obligations as a provider of a general-purpose model. For the worst violations, like using a prohibited AI, fines can go as high as 7% of your company’s global turnover or €35 million.
What does “human oversight” mean for a private LLM?
For any high-risk system, the Act says you need effective human oversight. In practice, this means a person must be able to review, understand, and override the AI’s decisions. The level of oversight has to make sense for the situation, so people can step in to stop or fix problems before they cause harm.
Does the Act apply to my company if we’re not in the EU?
Yes. The law is extraterritorial. It applies to any company, anywhere in the world, that provides or deploys an AI system whose output is used in the EU. If your business has an impact on people in the EU or you operate there, you have to comply.