Introducing the ORC AI SIG
By Dave Russo and Rachel Foucard
EU regulatory frameworks have not always accounted for the unique ways open source software is developed and maintained. The EU AI Act represents progress in recognising open source, but adapting the EU’s regulatory framework to open source in practice remains an ongoing process.
Large parts of EU AI Act are already in force, and the standards that will define how it will be implemented are being written right now. That’s exactly why the Open Regulatory Compliance (ORC) Working Group launched the AI Policy & Compliance Special Interest Group (AI SIG), and why we’re sharing the AI SIG’s scope this week.
Why open source needs a seat at the table
The AI Act primarily targets companies that provide AI models and systems, and it classifies certain uses as high-risk while placing different obligations on general-purpose models. But open source is not exempt from scrutiny. As open models gain visibility, and as organisations across Europe and beyond look to reduce reliance on proprietary technology, projects that produce these models face the same questions about transparency, data provenance, and security controls, when they enter the market.
We saw a similar pattern with the Cyber Resilience Act (CRA): the people writing technical standards need to understand how open source actually works, or the results won’t be workable for the community. The AI SIG exists to make sure that happens for AI regulation, too.
What the AI SIG will do
The AI SIG supports open source stakeholders in two ways:
- Inform: Helping members understand and implement regulatory requirements, starting with the EU AI Act and expanding to other regulations as member interest grows.
- Influence: Engaging with the regulatory bodies to help shape upcoming standards, so they are compatible with how open source is actually developed and used.
Beyond act-specific work, the group plans to tackle a few broader, recurring problems: clarifying technical definitions (such as the distinction between an AI model and an AI system), documenting the reasoning behind past positions so we’re not relitigating the same questions every time they resurface, and looking at how overlapping regulations can be addressed with a more unified compliance approach.
The Cyber Resilience SIG continues to lead general CRA work. The two SIGs will work together where AI and cybersecurity requirements intersect, including questions about the CRA’s applicability to AI components and systems.
A global concern, not just a European one
The AI Act is EU legislation but open source is global by nature, so the impact isn’t confined to Europe. Any organisation putting AI systems on the market in the EU needs to comply if its use case falls into a regulated category, regardless of where that organisation is based. And the EU AI Act isn’t the only regulation on the horizon. The Cloud and AI Development Act (CADA), part of the EU’s technical sovereignty package, is currently open for feedback, and several U.S. states have draft AI legislation in progress. The SIG’s scope is deliberately written to cover whichever regulations impact the open source community.
How to get involved
If you work with or on AI models and systems, we’d like your input. Getting involved is simple:
- Subscribe to the AI SIG mailing list
- Join a biweekly SIG call, held on Mondays. No preparation required; check the community calendar and drop in to listen before you contribute.
- Register to join us at Code & Compliance on 27 October 2026, where we will have a block on the “AI Act: Safe integration of open source models”.
None of this works without a broad range of voices at the table. You don’t need to be an expert to contribute; your experience, questions, and perspective can help shape the work. We hope you’ll get involved as the AI SIG evolves.
