Blog Post

Fine-Tuning Is Not What Reclassifies an AI Deployer

September 25, 2026

Table of Contents

The concern about fine-tuning is that it quietly converts a deployer into a provider, pulling in conformity assessment, technical documentation and a quality management system nobody budgeted for.

‍

The concern is misdirected. Fine-tuning is among the least likely routes to reclassification, and the route almost nobody worries about requires no training compute at all.

‍

Why Doesn't Fine-Tuning Usually Trigger It?

‍

Because the threshold at the model level is set high enough that most commercial work sits nowhere near it.

‍

The Commission guidelines on general-purpose AI obligations use an indicative threshold of one third of the original model's training compute. A modification below that is generally not treated as substantial, and the Commission has indicated it expects few or no downstream modifications to reach it. Prompt engineering and few-shot approaches are further down the same scale and are generally outside it entirely.

‍

Which Makes the Common Worry the Wrong One

‍

Fine-tuning a model on internal data is the activity most organizations flag as a compliance risk, and on the model-level test it is usually the safest thing they do. The reclassification risk sits in a decision made in a product meeting rather than in a training run.

‍

What Are the Three Routes?

‍

Article 25 sets out three, and they are not equally difficult to trigger.

‍

Vendor risk scoring breakdown showing dimensions for model risk, business importance, regulatory exposure and company risk with the vectors scored under each
A vendor record carrying what a supplier has stated about permitted use is what the reclassification question turns on.
  • Putting your name on it: Placing your own name or trademark on a high-risk system already on the market.
  • Substantially modifying it: A change to a high-risk system that leaves it high-risk.
  • Changing the intended purpose: Using an AI system, including a general-purpose one, for a purpose that makes it high-risk.

‍

The Third Route Needs No Compute

‍

Building an application on a generic model that ranks job applicants, grades exams or triages requests for essential services puts that deployment into a listed high-risk category. You defined the purpose, so you are the provider of the resulting system, and no fine-tuning occurred at any point. It is a product decision with a regulatory consequence attached.

‍

What Counts as Substantial?

‍

A definition that depends on somebody else's paperwork, which is the strangest feature of the whole provision.

‍

A substantial modification is a change that was not foreseen or planned in the initial conformity assessment and that affects compliance with the high-risk requirements, or that modifies the intended purpose the system was assessed for. So whether your change is substantial turns on what the original provider wrote in its assessment and what it anticipated.

‍

You Need the Vendor's Documentation

‍

An organization cannot determine its own status without knowing what the original conformity assessment covered. A change the vendor foresaw is not substantial and the same change unforeseen may be, which makes the vendor's technical documentation a compliance dependency rather than a reference document, and assessing an AI vendor rarely reaches this question.

‍

Can the Obligations Be Contracted Away?

‍

For one route only, which is a distinction with real commercial consequences and almost no coverage.

‍

Assessment intake form with structured sections covering ownership, risk assessment, data handling and compliance context
A record of who defined a system's purpose and when is the artifact a reclassification question rests on.

The name-and-trademark route applies without prejudice to contractual arrangements allocating the obligations otherwise, so parties can agree who carries them. The substantial modification route and the intended purpose route contain no such wording. A contract can organize evidence, testing and access between the parties and it does not move the statutory role away from whoever's conduct triggered it.

‍

What Does the Supplier Owe You?

‍

Cooperation, with a condition attached. The original supplier must provide the information and technical access needed to meet the obligations, unless it has expressly specified that its system is not to be turned into a high-risk one. A vendor that has made that statement has moved the position, and reading terms of use for exactly that language is a short exercise with a large consequence.

‍

When Does This Bite?

‍

Not yet, and the interval is the whole point of raising it now.

‍

Regulation (EU) 2026/1744 deferred the section of the Act containing this provision to December 2027 for standalone high-risk systems and August 2028 for high-risk AI embedded in regulated products. So the provider obligations that follow from reclassification do not currently apply.

‍

Which Puts the Decision Before the Obligation

‍

The architecture and product choices that determine classification are being made now and will be assessed against a regime that starts later. An organization defining a purpose this quarter is choosing its future role, and the deferral means nothing tests that choice for eighteen months, which is long enough for nobody to remember who made it.

‍

What Should Be Recorded Now?

‍

Three things, all cheap while the decision is being made and unreconstructable afterward.

‍

The intended purpose of each deployment as stated at the time, since the purpose is what the third route turns on. Whether the supplier's terms contain a statement restricting high-risk use, since that determines whether cooperation is owed. Then what the vendor's conformity assessment covers, since the substantiality of any later change is measured against it. Whether a model is general-purpose determines which set of tests applies in the first place.

‍

Who Should Hold That Record?

‍

Whoever approves the deployment, because the purpose is defined at approval and by nobody afterward. A record created by a security or compliance function months later is reconstructing an intention rather than documenting one, and an obligation split across functions is how this ends up unowned.

‍

Does Reclassification Cost Anything Before 2027?

‍

Yes, in two places that have nothing to do with the AI Act, which is what makes the interval worth using rather than waiting out.

‍

Provider status changes what a customer can ask of you contractually. An enterprise buyer performing diligence on an AI supplier will ask which role it holds and what documentation exists, and an organization that cannot answer has a commercial problem now rather than a regulatory one later. The second place is acquisition, where an undocumented provider position on a product line is a diligence finding with a price attached.

‍

Which Makes the Record a Commercial Asset

‍

An organization able to state its role per deployment, with the purpose recorded and the supplier terms on file, answers a buyer's questionnaire in an afternoon. One that cannot spends weeks reconstructing intentions, and diligence on something you are about to acquire applies the same reasoning from the buying side.

‍

What Is the Cheapest Version of the Record?

‍

Three fields at deployment approval. The stated purpose, the supplier and the version, and whether the terms restrict high-risk use. None requires legal review to capture and all three are what a classification exercise would otherwise have to infer, which records that survive an audit covers as a general property.

‍

Which Deployments Should Be Checked First?

‍

Anything where a generic model has been pointed at a decision about a person, since that is the route with no technical signal.

‍

Recruitment screening, performance evaluation, credit decisions, access to essential services, education assessment and biometric identification are the categories to search for. A team that built a screening tool on a commercial model has performed the reclassification without a training run, a procurement event or anything else a governance process would notice, and an AI governance record built from observed activity finds those deployments where a survey does not.

‍

Purpose Reclassifies, Fine-Tuning Rarely Does

‍

Fine-tuning sits below an indicative threshold of one third of the original training compute and the Commission expects few or no modifications to reach it, so the activity organizations worry about is usually the safe one. The route that reclassifies without warning is defining a purpose that falls in a listed high-risk category, which is a product decision requiring no compute. Substantiality is measured against the original provider's conformity assessment, making somebody else's documentation a dependency in your own classification. Contractual reallocation is available for the name-and-trademark route and not for the other two. The obligations were also deferred to December 2027, so the decisions being made now will be assessed against a regime that starts later. Kovrr's AI compliance readiness records the purpose and the supplier terms at the point a deployment is approved.

‍

To see which of your deployments have defined a purpose that would reclassify you, book a demo mapped to your own estate.

Yakir Golan

CEO

Article 25 Reclassification FAQs

Speak to an Expert

Does fine-tuning make you a provider under the EU AI Act?

What are the three Article 25 reclassification triggers?

What is a substantial modification under the EU AI Act?

Can you contract out of Article 25 provider obligations?

Does the original model supplier have to help you comply?

When do EU AI Act Article 25 obligations apply?