Chinese open-weight models such as Qwen and DeepSeek can be used in the EU, since the EU AI Act regulates AI systems based on their risk classification and the obligations of whoever places them on the market, not based on the nationality of the organization that originally trained the model. Self-hosting the model weights on infrastructure located in an EU datacenter, with no calls back to any external service, means no personal data crosses a border regardless of where the underlying model came from, which addresses the GDPR transfer question independently of any AI-specific regulation. Practical considerations still matter: the company deploying the model, not the original developer, generally takes on the relevant EU AI Act provider or deployer obligations for that deployment, including documentation duties if the use case is high-risk, and license terms, typically Apache 2.0 for Qwen or DeepSeek's own license, need to be checked for usage restrictions. Enterprises should also run their own security and output review on any open-weight model, a step that applies equally regardless of origin. This is general regulatory information and specific deployments should be checked against current guidance. Nanobase AI self-hosts open-weight models of any origin, including Qwen and DeepSeek, entirely within EU infrastructure when that is the requirement.

The law regulates the deployment, not the model's origin

A common misconception is that the EU AI Act or GDPR treats a model differently based on which country its developer is based in; in fact, both frameworks regulate the entity placing the AI system on the market or deploying it, and the specific risk classification of the use case, regardless of where the underlying model was trained. A company self-hosting Qwen or DeepSeek inside an EU datacenter takes on the same EU AI Act provider or deployer obligations it would take on for any other model, no more and no less because of where the model originated. This is general regulatory information, not a legal opinion on a specific deployment, and current guidance should be confirmed before relying on it.

Obligations checklist by category

Every row below applies the same way to a model trained in the EU, the US, or China; the obligation attaches to the deployment, not to the flag on the developer's headquarters.

CategoryObligationApplies regardless of model origin
EU AI ActRisk classification, technical documentation, human oversight for high-risk use casesYes, based on the use case, not the model's country
GDPRLawful basis, data minimization, transfer analysis if any processing crosses a borderYes, though self-hosting in the EU removes the transfer question specifically
License termsUsage restrictions under the model's specific license (commonly Apache 2.0 for Qwen, DeepSeek's own license)Depends on the specific license, needs individual review
Security reviewOutput vetting, checksum verification, network isolationYes, the same technical vetting applies to any open-weight model

A four-step adoption process for any foreign open-weight model

  1. Confirm the license permits the intended commercial use, since terms differ meaningfully between models and some carry restrictions on certain use cases or downstream redistribution.
  2. Self-host on infrastructure physically located in the required jurisdiction, with no outbound calls to the model publisher's own servers, which resolves the GDPR cross-border transfer question independently of any AI-specific regulation.
  3. Classify the use case under the EU AI Act's risk tiers, since the company deploying the model, not its original developer, generally carries the resulting provider or deployer obligations for that specific deployment.
  4. Apply the standard technical vetting used for any open-weight model, covered in more depth in the DeepSeek enterprise safety comparison, including output review and network isolation.

Where geopolitics still matters practically

While the legal framework is largely origin-agnostic, practical considerations remain: some organizations, particularly in the public sector or in industries with government contracts, face procurement policies or customer expectations that go beyond what regulation strictly requires, restricting the use of models from specific countries regardless of deployment mode. These are contractual or policy decisions layered on top of the legal analysis, not requirements imposed by the EU AI Act or GDPR themselves, and they are worth checking separately against any sector-specific procurement rules that may apply.

Frequently asked questions

Does the EU AI Act treat open-weight models differently from proprietary ones?

The Act's general-purpose AI provisions apply obligations based on factors like model capability and systemic risk, largely independent of whether the model is open-weight or proprietary, though open-weight models below certain risk thresholds have historically received somewhat lighter documentation obligations than the largest frontier models.

Do license terms for Qwen or DeepSeek restrict enterprise use?

Qwen is generally released under an Apache 2.0 or similarly permissive license, while DeepSeek uses its own license terms; both should be reviewed directly against the intended use case, since permissive licensing for most uses does not guarantee unrestricted use for every scenario.

Is a data protection impact assessment needed when adopting a new open-weight model?

If the model will process personal data, the same DPIA considerations apply as for any other AI system; the model's country of origin does not change whether a DPIA is required.

How Nanobase AI helps

Nanobase AI, an NVIDIA Inception Program member, self-hosts open-weight models of any origin, including Qwen and DeepSeek, entirely within EU infrastructure when that is the requirement, running the license review and technical vetting steps above before deployment.

Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.