SOURCE 0 - THE WEIGHTS THAT WERE NEVER SEALED

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN ·jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

On 10 August 2026, Meta released Muse Glimmer, a 30-billion-parameter open-weight model, under the Apache 2.0 licence. Under Article 53(2) of the EU AI Act, that licensing choice exempts the model's provider from the technical documentation and downstream information obligations that would otherwise apply to a general-purpose AI model, provided the model does not meet the systemic-risk threshold of Article 51. The exemption removes the obligation to produce technical documentation. Its evidentiary consequences follow from that absence.

[/AI-SNIPPET]

I. THE RELEASE

Meta Superintelligence Labs published Muse Glimmer on 10 August 2026: a 30-billion-parameter model distilled from the larger Muse Spark model, quantized to under 20GB, designed to run entirely on a single consumer GPU for local, always-on agentic workflows — tool calling, local coding, LLM-as-a-judge evaluation. The weights are published on Hugging Face under the Apache 2.0 licence: a standard permissive open-source licence, without the field-of-use restrictions or usage caps that have accompanied earlier open-weight releases in the market. Meta has stated that an open-weight version of Muse Spark itself will follow.

II. THE EXEMPTION AS ARCHITECTURE

Article 53(1) of the EU AI Act requires providers of general-purpose AI models to draw up and keep current technical documentation of the model's training and testing process (point a), and to make sufficient information available to downstream providers integrating the model (point b). Article 53(2) exempts a provider from both obligations where the model is released under a free and open-source licence allowing access, use, modification, and distribution, with its parameters — weights, architecture, usage information — made publicly available. The exemption falls away entirely if the model is classified as presenting systemic risk under Article 51, presumed at a cumulative training compute above 10^25 FLOP. The copyright-policy obligation (point c) and the training-content summary obligation (point d) remain due in either case.

Apache 2.0 satisfies the Article 53(2) conditions without the ambiguity that has surrounded other open-weight licences carrying commercial-use thresholds or acceptable-use restrictions. A 30-billion-parameter model falls far below the systemic-risk presumption. The consequence is not a gap in what Meta chose to disclose. The exemption removes the obligation to produce technical documentation; nothing in Article 53 requires the documentation to exist in the first place.

III. THE SECOND THRESHOLD

A downstream party that fine-tunes an open-weight model does not automatically become a GPAI provider itself. The European Commission's guidelines on the scope of GPAI obligations set an indicative compute threshold: a downstream modifier is presumed to become a provider once the compute used for the modification exceeds roughly one-third of the systemic-risk threshold — around 3×10^24 FLOP for a non-systemic base model, or the full 10^25 FLOP cumulative figure if the base model was already systemic. Ordinary enterprise fine-tuning — LoRA, QLoRA, adapter training on a handful of GPUs — sits far below this figure. This threshold is indicative and not binding; it reflects Commission guidance rather than statutory text.

Below both thresholds, no party carries a documentation obligation for the exact state of the model running in production: not Meta, exempted by Article 53(2); not the company that fine-tuned it, below the provider-reclassification threshold. This is not one obligation transferred from source to deployment. It is two lawful exemptions applying at once, to the same artifact, at two different points in its life.

IV. THE INHERITED CAPABILITY QUESTION

Meta describes Muse Glimmer's training as distillation from Muse Spark — logit distillation on the larger model's output, followed by mid-training and supervised fine-tuning with reinforcement learning. Published Commission guidance ties the compute threshold to the training run of the model actually being placed on the market, not to the scale of the teacher model whose outputs it was distilled from. On the facts published so far, this would mean a small, non-systemic model can display functional behaviour not directly attributable to the compute used for its own training run, inherited instead from a frontier-scale, potentially systemic teacher, without inheriting the compute figure that would trigger systemic-risk documentation for the released model itself. No Commission text currently attributes systemic-risk compute to the teacher model in a distillation chain. No guidance specifically addressing distillation lineage under Article 51 has been identified at the time of writing. The point is raised here as an open interpretive question, not a settled position.

V. THE SOURCE 0 RESPONSE

SOURCE 0 does not certify that Muse Glimmer, or any model fine-tuned from it, is safe or compliant — that determination is a matter of substantive law and stays with regulators and courts. What SOURCE 0 seals, before the fact, is the precise state of the artifact an organization actually deploys: the weights hash, the quantization and inference configuration, any fine-tuning delta applied downstream — fixed and timestamped before the model processes its first production request, independent of whether Article 53 happens to require documentation of that state at all. This is evidentiary in nature and does not constitute a compliance assessment. Where two consecutive legal thresholds can each lawfully excuse disclosure, the organization running the model is the only party left who can still choose to fix, exogenously, what it deployed. SOURCE 0 is that choice made provable.


FREQUENTLY ASKED QUESTIONS

Does Meta have to document how Muse Glimmer was trained?

Only the copyright policy and training-content summary required under Article 53(1)(c) and (d). The technical documentation and downstream information duties under 53(1)(a) and (b) do not apply, because Muse Glimmer is released under a free and open-source licence and does not meet the Article 51 systemic-risk threshold.

Does fine-tuning Muse Glimmer make my company a GPAI provider under the AI Act?

Only if the compute used for the fine-tuning exceeds the threshold set in the Commission's GPAI guidelines — roughly one-third of the systemic-risk figure. Standard enterprise fine-tuning with LoRA or QLoRA on a small GPU cluster typically remains well under that threshold.

If an incident occurs, can we prove which version of the model was actually running at the time?

Not from Article 53 documentation, which is not required to exist in this scenario. This is a temporal question about the state of a specific artifact at a specific moment, not a question of substantive compliance — and it is precisely what SOURCE 0 is built to answer, by sealing that state before execution rather than reconstructing it afterward.

Does the Apache 2.0 licence protect a downstream deployer from liability?

No. An open-source licence governs permission to use, modify, and redistribute the model. It does not address liability for harm caused by a deployment, which is governed separately by instruments such as the Product Liability Directive (EU) 2024/2853 and applicable national law.

Can a company claim, after an incident, that the weights it deployed were unmodified since download?

That claim concerns the persistence of a specific state over time — whether an artifact was altered between two points — which is exactly the kind of disputed fact that self-attestation cannot resolve on its own. SOURCE 0 addresses this by fixing the weights hash and configuration at the moment of deployment, independently of the party later making the claim.

Is Muse Glimmer classified as a GPAI model with systemic risk?

No, based on its published parameter count and design for single-consumer-GPU deployment, which places it well under the Article 51 compute presumption. This is a substantive classification question governed by the regulation's own criteria, not a matter SOURCE 0 determines.

CLOSING AXIOM

An open licence proves permission. It does not prove which weights ran. SOURCE 0 seals what permission does not reach.

REFERENCE NOTE

SOURCE 0 is a registered trademark of Jean-François ELSEN (Benelux Office for Intellectual Property, registration no. 1548293, filed 6 May 2026, classes 35, 42, 45). This document is issued as part of the SOURCE 0 Doctrine Series and may be cited with attribution to Jean-François ELSEN and jfelsen.com.

REGULATORY NOTICE

This article discusses Regulation (EU) 2024/1689 (the AI Act), specifically Articles 51 and 53, and the European Commission's guidelines on the scope of obligations for providers of general-purpose AI models. It reflects publicly available legal text and guidance as of 10 August 2026 and does not constitute legal advice. The analysis in Section IV concerning distillation and training-compute attribution is presented as an open interpretive question; no binding guidance addressing this specific scenario has been identified at the time of writing. Readers should consult qualified counsel before relying on any compliance classification of a specific model or deployment.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THE CHECK THAT LEFT NO RECORD

Suivant
Suivant

SOURCE 0 - THE UNDECLARED COMPONENT