[{"data":1,"prerenderedAt":155},["ShallowReactive",2],{"seo-verification":3,"blog-ai-act-auto-heberger-ia-obligations-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"id":7,"slug":8,"title":9,"excerpt":10,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":15,"categories":20,"featuredImage":22,"bgImage":23,"posterImage":24,"relatedSolution":22,"intro":25,"sections":26,"ctaTitle":114,"ctaBody":115,"ctaButton":116,"ctaUrl":117,"relatedPosts":118},231,"ai-act-auto-heberger-ia-obligations","The AI Act: what applies to you if you self-host AI","Since 2 August 2026 the rest of the AI Act applies. Who carries the obligation when you deploy an LLM on your own server.",8,0,false,"2026-08-07T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":18},10,"Compliance & Regulation","conformite","bg-amber-500\u002F10 text-amber-400",[21],{"id":16,"name":17,"slug":18,"color":19,"icon":18},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fai-act-auto-heberger-ia-obligations-poster.svg","On 2 August 2026, almost all of the European AI regulation came into application. If you run a model on your own server, the first question to settle is not «what must I do» but «am I even concerned». The answer turns on a word the regulation defines precisely, and that many articles use loosely.",[27,31,34,43,46,49,52,74,105,108,111],{"type":28,"title":29,"body":30},"h2","What actually changed on 2 August 2026","The regulation applies in phases. Two milestones matter for anyone deploying AI today. On 2 August 2025, the Chapter V obligations — those aimed at general-purpose AI models — began to apply. On 2 August 2026, meaning now, **the remainder of the regulation** comes into application, with one exception: Article 6(1), deferred to 2 August 2027. In practice this covers the high-risk regime and the transparency obligations, which touch the greatest number of people. Worth noting for later: general-purpose models already placed on the market **before** 2 August 2025 get extra time and must be compliant by 2 August 2027.",{"type":28,"title":32,"body":33},"Who carries the obligation — and why it is not your host","This is the point most shortcuts miss. The regulation imposes nothing on «whoever hosts»: it names precise roles, two of which probably concern you. The **provider** develops an AI system, or has it developed, and places it on the market or into service **under its own name**. The **deployer** uses an AI system under its own authority in the course of a professional activity. Renting a server makes nobody either one: your host supplies infrastructure, not an AI system. On the other hand, if you install a conversational agent on that server and your customers talk to it, **you are the deployer** — and if you distribute it under your brand, you also become a provider. Self-hosting does not shift responsibility onto the supplier: it concentrates it on you.",{"type":35,"title":36,"items":37},"ul","The four situations where transparency obligations apply to you",[38,39,40,41,42],"**A system that talks to humans** — the user must know they are addressing an AI, unless it is obvious to a reasonably well-informed person.","**Generated synthetic content** — audio, image, video or text must be marked in a **machine-readable** format and detectable as artificial.","**Emotion recognition or biometric categorisation** — exposed persons must be informed, on top of GDPR obligations.","**Manipulated deepfake-type content** — its artificial nature must be disclosed; artistic or satirical works fall under a lighter regime.","**Generated text published on matters of public interest** — disclosure required, **unless** the content underwent human review with assigned editorial responsibility.",{"type":28,"title":44,"body":45},"Is your assistant a «high-risk» system?","This is the most common worry, and the answer is usually no — but it must be demonstrated, not assumed. Two routes lead to high-risk classification. The first covers systems that are a safety component of a product already covered by Union harmonisation legislation and subject to third-party assessment; that provision, Article 6(1), is the one deferred to 2 August 2027. The second covers systems listed in Annex III, high-risk by principle. A classic support assistant falls under neither. And even for an Annex III system there is a way out: it escapes classification if it poses no significant risk to health, safety or fundamental rights, **and** performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing human judgement, or performs a preparatory task. Two caveats, and they are strict: a system carrying out **profiling of natural persons** stays high-risk regardless, and whoever claims an exemption must **document that assessment before** placing on the market or into service. An unwritten exemption does not exist.",{"type":28,"title":47,"body":48},"The most common case: an assistant answering your customers","This is the setup most self-hosting teams end up with: a chat interface wired to a local model, opened to support or sales. You are its deployer. The obligation is unspectacular — it is about informing, not asking permission. The regulation specifies **when**: the information must be given clearly and distinguishably, at the latest **at the time of the first interaction or exposure**. A discreet footer mention is therefore not enough if the conversation starts elsewhere. In practice, an opening line stating what the interlocutor is, plus a persistent reminder in the interface, meets the requirement without degrading the experience. The «it is obvious» exception exists, but leaning on it is a gamble: what seems obvious to you is not necessarily obvious to someone discovering your service.",{"type":28,"title":50,"body":51},"Published content: the nuance that changes everything","For generated text published on a matter of public interest, the regulation offers a way out worth understanding rather than enduring: disclosure is not required where the content underwent **human editorial control** and a person or entity **assumes editorial responsibility** for its publication. In other words, the line does not run between «written by a machine» and «written by a human», but between **reviewed and owned** and **published as-is**. That distinction is useful well beyond compliance: it describes exactly what separates content you can defend from content you merely inherit. If your publishing chain already includes a named review, you are probably within the exemption — but document who reviews, otherwise you cannot demonstrate it.",{"type":53,"title":54,"steps":55},"steps","What there is to put in place",[56,59,62,65,68,71],{"title":57,"body":58},"Inventory your AI systems","List what actually runs: local models, chat interfaces, external APIs called from your applications, content generators. An incomplete inventory makes everything else theoretical.",{"title":60,"body":61},"Qualify your role for each","Deployer, provider, or both. The answer changes depending on whether the system is used internally or distributed under your brand. Write down the qualification you settled on and why.",{"title":63,"body":64},"Display the nature of the system","In every interface where a human talks to the AI, from the first interaction. The message must be understandable without jargon.",{"title":66,"body":67},"Mark synthetic outputs","Marking must be machine-readable, not merely visible to the eye. Metadata on generated files and watermarking mechanisms fall under this requirement.",{"title":69,"body":70},"Document editorial review","If you publish generated content, record who reviews and who owns it. That trace is what activates the exemption — not the intention.",{"title":72,"body":73},"Date it and revisit","Record the date of each compliance decision. Obligations arrive in waves — the 2027 one for older models will reopen the file.",{"type":75,"title":76,"headers":77,"rows":81},"comparison","Self-hosted or third-party API: what changes",[78,79,80],"Aspect","Self-hosted model","Third-party API",[82,85,89,93,97,101],[83,84,84],"Deployer role","You",[86,87,88],"Where entered data goes","On your server","To the API provider",[90,91,92],"Control over output marking","Total, and on you","Depends on what the provider exposes",[94,95,96],"Traceability of model versions","You choose when to change","The provider may change without notice",[98,99,100],"Model provider obligations","Borne by the model publisher","Borne by the API provider",[102,103,104],"What the host is responsible for","Infrastructure, never the AI system","Not applicable",{"type":28,"title":106,"body":107},"What you risk, and the misreading going around","The regulation sets three tiers of penalty. The heaviest targets prohibited practices: up to 35 million euros or 7 % of total worldwide annual turnover. Breaches of provider and deployer obligations, including the Article 50 transparency duties — the ones most likely to concern you — fall in the second tier: up to 15 million euros or 3 %. The third, up to 7.5 million or 1 %, covers inaccurate information supplied to authorities. For an undertaking, the **higher** of the two applies. And that is where the misreading creeps in: for **SMEs, start-ups included**, the regulation retains the **lower** figure instead. The «7 % of turnover» you read everywhere therefore describes a large company's ceiling on the gravest category, not the everyday exposure of a team deploying an assistant without stating its nature.",{"type":109,"body":110},"tip","Do not conflate the deadlines. General-purpose models placed on the market before 2 August 2025 must be compliant by 2 August 2027: if you run an older model, the obligation on its publisher has not yet matured — which changes nothing about your own deployer obligations, applicable since 2 August 2026.",{"type":28,"title":112,"body":113},"What self-hosting makes easier, and what it does not excuse","Hosting the model yourself genuinely simplifies part of the file: you know where entered data sits, you decide when the model version changes, and you can produce that information without depending on a third party. Three recurring questions thus get a verifiable answer rather than a declaration. But it excuses nothing: transparency obligations rest on the deployer whatever the infrastructure, and controlling everything mainly means nobody else will do it for you. Finally, a clarification that is not a figure of speech: the above describes the text, not your situation. Qualifying a system depends on its actual use, and a borderline case is settled with a lawyer, not a blog post.","Infrastructure whose location you control","Models, entered data and logs stay on your server — you know where they are, and you can prove it.","Our security commitments","\u002Fpourquoi\u002Fsecurite",[119,130,140],{"id":120,"slug":121,"title":122,"excerpt":123,"readTime":124,"views":12,"isPinned":13,"publishedAt":125,"category":126,"categories":127,"featuredImage":22,"bgImage":23,"posterImage":129,"relatedSolution":22},211,"nis2-hebergement-obligations-clients-2026","NIS2: what the directive requires from your hosted clients","NIS2 applies from October 2026 across the EU. Clients in essential sectors must choose providers that meet the same security standards.",4,"2026-08-02T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":18},[128],{"id":16,"name":17,"slug":18,"color":19,"icon":18},"\u002Fblog\u002Fcovers\u002Fnis2-hebergement-obligations-clients-2026-poster.svg",{"id":131,"slug":132,"title":133,"excerpt":134,"readTime":124,"views":12,"isPinned":13,"publishedAt":135,"category":136,"categories":137,"featuredImage":22,"bgImage":23,"posterImage":139,"relatedSolution":22},200,"cyber-resilience-act-ce-qui-change-pour-vos-clients","Cyber Resilience Act: what changes for your clients","The CRA requires vulnerability disclosure in 24 h from September 2026. What it means in practice for agencies and developers.","2026-08-01T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":18},[138],{"id":16,"name":17,"slug":18,"color":19,"icon":18},"\u002Fblog\u002Fcovers\u002Fcyber-resilience-act-ce-qui-change-pour-vos-clients-poster.svg",{"id":141,"slug":142,"title":143,"excerpt":144,"readTime":124,"views":12,"isPinned":13,"publishedAt":145,"category":146,"categories":152,"featuredImage":22,"bgImage":23,"posterImage":154,"relatedSolution":22},216,"deployer-ollama-vps-llm-local","Deploying Ollama on a VPS in 2026: Local LLM, No GPU Required","Ollama has surpassed 176,000 GitHub stars and 52M downloads per month. Learn how to deploy a local LLM on your VPS without a GPU, running Phi-3-mini or Llama 3.2 at 8-12 tok\u002Fs.","2026-08-03T00:00:00+00:00",{"id":147,"name":148,"slug":149,"color":150,"icon":151},7,"Self-hosting","self-hosting","bg-indigo-500\u002F10 text-indigo-400","cloud",[153],{"id":147,"name":148,"slug":149,"color":150,"icon":151},"\u002Fblog\u002Fcovers\u002Fdeployer-ollama-vps-llm-local-poster.svg",1786136453046]