Right to Run Local AI: SB 942, EU AI Act, and Self-Hosters

regulationselfhostedopensourceprivacyai

TL;DR: Running open-weight models locally for personal use is legal in the US and EU as of September 2026. California SB 942 and the EU AI Act regulate providers and platforms, not your home lab. The righttointelligence.org campaign argues the regulatory trend still threatens local AI — but the campaign does not disclose who runs it.

righttointelligence.orgCalifornia SB 942 (+AB 853)EU AI Act (GPAI rules)
What it isAdvocacy campaign, surfaced Aug 2026State law, operative Aug 2 2026EU regulation, GPAI duties since Aug 2 2025
Who it targetsLawmakers (asks you to call your state office)GenAI providers with 1M+ monthly usersModel providers placing GPAI on the EU market
Touches private local inference?N/A — it defends itNoNo — personal, non-professional use is excluded

Honest take: Nothing on the books in the US or EU stops you from pulling a GGUF and running it tonight. The realistic risk is upstream — rules that make labs hesitate to release open weights — so archive the models you depend on now.

Since early August 2026, a campaign called “Protect your right to run local AI” has been circulating on Hacker News and r/LocalLLaMA, pointing at righttointelligence.org and urging self-hosters to contact state legislators. The pitch lands because two real regulatory milestones hit in the same month: California’s SB 942 became operative on August 2, 2026, and the EU AI Act’s general-purpose AI obligations passed their first anniversary in force. If you run Ollama, llama.cpp, or vLLM at home, the obvious question is whether any of this reaches you. Short answer: not today, and mostly not by design. The longer answer — including the one genuinely unresolved threat vector — is below.

What is the righttointelligence.org campaign?

Righttointelligence.org is an advocacy site asking visitors to sign a petition and call their state legislature in defense of the right to run AI models locally — and, as of September 27, 2026, we could not verify who operates it. The site’s front page pitches a ten-second sign-up and a two-minute call script targeting state offices. The campaign got broad visibility from an August 2026 Hacker News thread (“Protect your right to run local AI”).

Here is the problem we hit while researching this article, and how we resolved it: neither the site’s public pages nor any search result we could reach names the organization, coalition, or individuals behind the campaign. It is not attributed to the EFF, EleutherAI, the Linux Foundation, or any other group with a track record on open-model advocacy. We are not implying bad faith — new single-issue campaigns often launch before formalizing a nonprofit — but an advocacy site that asks you to contact legislators while not saying who wrote the call script deserves the same skepticism you would apply to an unsigned model card. Our resolution: report what the campaign asks, decline to endorse or condemn it, and evaluate the underlying legal claims against primary sources instead. That evaluation is the rest of this article.

What the campaign gets directionally right is its choice of battlefield. US AI regulation in 2026 is happening at the state level — California, Colorado, Texas, and Utah all have AI statutes in some stage of effect — which is why a call-your-state-office campaign makes more sense than a federal petition.

Does California SB 942 apply to running models at home?

No. California SB 942, the AI Transparency Act, applies to “covered providers” — generative AI systems that are publicly accessible in California and have more than 1,000,000 monthly visitors or users. A private Ollama instance on your LAN fails both prongs: it is not publicly accessible, and unless your home lab is doing something remarkable, it does not have a million monthly users.

What SB 942 actually mandates, for those covered providers:

  • A free public AI-detection tool so anyone can check whether a piece of content came from the provider’s system.
  • Latent (embedded) disclosures in AI-generated image, video, and audio content — provenance metadata baked into the file.
  • Visible manifest disclosures available at the user’s option.
  • Civil penalties of $5,000 per violation, with each day counted as a discrete violation.

Two dates matter. SB 942 was signed in September 2024 with an original effective date of January 1, 2026. AB 853, signed in October 2025, pushed the operative date to August 2, 2026 and extended obligations to “large online platforms,” “generative AI system hosting platforms,” and capture-device manufacturers starting January 1, 2027 (details in the Sources below).

The boundary cases worth knowing:

  • You self-host Stable Diffusion or Flux and post the images publicly. SB 942 does not obligate you — it obligates covered providers. Open-weight image models you run locally have no 1M-user provider standing behind your instance. Platforms you post to may have their own labeling rules, but that is platform policy, not SB 942.
  • You run a public-facing AI service. If your hosted tool ever approaches 1M monthly California-accessible users, you become a covered provider. That is a real business, not a home lab, and at that point you need a lawyer, not a blog post.
  • The January 2027 hosting-platform provisions are the piece self-hosters should actually watch, because “generative AI system hosting platform” is the category that could touch model-distribution sites. How that gets interpreted against a site like Hugging Face is not yet settled.

Does the EU AI Act ban open-weight models for personal use?

No. The EU AI Act (Regulation (EU) 2024/1689) explicitly does not apply to natural persons using AI systems in the course of a purely personal, non-professional activity — that exclusion is written into Article 2 of the regulation itself. Downloading Qwen3 32B and running it on your own hardware for your own use is outside the Act’s scope, full stop.

The obligations that did kick in on August 2, 2025 fall on providers of general-purpose AI models — the labs and companies that place models on the EU market. Those duties include technical documentation, a copyright policy, and a public summary of training data. Models placed on the market before August 2, 2025 have until August 2, 2027 to comply. The European Commission published guidelines clarifying the scope of these GPAI obligations on July 18, 2025.

Open-weight models get meaningful relief. A GPAI model is exempt from most provider obligations if it is released under a genuinely free and open-source license, is not monetized, and publicly discloses weights, architecture, and usage information. Even exempt open-source providers still owe the copyright policy and training-data summary — but the compliance burden is a fraction of what closed commercial providers carry. Licenses that restrict usage or gate access to weights do not qualify for the exemption, which is one more reason license terms matter; our open-weight license breakdown covers which “open” models carry commercial restrictions.

The boundaries, stated plainly:

  • Personal, non-professional local inference: excluded from the Act.
  • Using a local model inside your business in the EU: you become a deployer, and deployer duties apply based on the use case’s risk class. Running a local coding assistant is minimal-risk; using a model to screen job applicants is high-risk and regulated regardless of where the model runs.
  • The Act’s prohibited-practices list (social scoring, certain biometric uses) bans uses, not model weights. It applies to a cloud API and a local GGUF equally.

Yes. As of September 2026, running open-weight models locally for personal use is legal in the United States and the European Union. No US federal law, no US state law we could identify (including SB 942), and no provision of the EU AI Act prohibits private local inference on open weights. The same is true for personal use in the UK, which has no equivalent statute in force.

The uncertainty sits at the edges, not the center:

ActivityLegal status, Sep 2026
Personal local inference (US/EU)Legal, unregulated
Publishing locally generated images/videoLegal; platform labeling policies may apply
Local models in an EU business workflowLegal; deployer duties scale with use-case risk
Operating a public GenAI service, 1M+ users in CASB 942 covered provider — detection tool + disclosures required
Distributing/hosting models at platform scaleWatch AB 853’s Jan 2027 hosting provisions

If someone tells you that self-hosting is about to become illegal, ask them for a bill number. We looked; the bills that exist regulate providers, platforms, and specific harmful uses.

Where does the real pressure on local AI come from?

The realistic threat to self-hosters is not a ban on inference — it is regulatory friction that makes labs stop releasing open weights. This is the strongest steelman of the righttointelligence.org campaign’s position, whoever runs it.

The mechanism: every obligation attached to “placing a model on the market” raises the cost of releasing weights publicly versus keeping the model behind an API. An API can be geofenced, filtered, and monitored for compliance; released weights cannot be recalled. The EU’s open-source exemption softens this substantially, and the visible evidence from the past year cuts against panic — Meta, Alibaba (Qwen), DeepSeek, Z.ai, and Moonshot all shipped open or open-weight releases after the GPAI rules took effect in August 2025. But the incentive gradient is real, and it is the thing worth watching in 2027 as the pre-2025 model compliance deadline arrives.

There is a practical hedge, and it costs one evening: archive the weights you depend on, locally, now. A model on your disk is beyond the reach of any future upstream decision — a license change, a regional gate, a takedown. Weights already downloaded are yours to run.

$ ollama pull qwen3:32b
pulling manifest
pulling 6f96... 100% ▕████████████████▏ 20 GB
verifying sha256 digest
success

Ollama stores blobs under ~/.ollama/models (or /usr/share/ollama/.ollama/models on Linux service installs) — back that directory up like any other data you cannot re-download. For raw GGUF archives from Hugging Face, keep the checksum alongside the file; the Hugging Face breach in July 2026 already made checksum verification a baseline practice for reasons that have nothing to do with regulation. Disk is the cheap part of this hedge even in 2026’s inflated market — a 20 GB Q4 quant is pocket change against the DRAM prices currently reshaping home-lab builds.

When is this the wrong thing to spend your attention on?

If you are a hobbyist running models on one machine for yourself, monitoring AI legislation is close to a zero-return activity — nothing in force or pending targets you, and the compliance-newsletter treadmill is a tax on your attention. Set a yearly reminder, re-check the landscape, done.

Spend the attention instead if any of these apply:

  • You are building a product on open weights. License terms and provider/deployer classification are now core due diligence, not fine print.
  • You operate in the EU in a professional capacity. Deployer obligations attach to use cases, and the high-risk categories (hiring, credit, education, essential services) are broad.
  • Your threat model is privacy, not legality. Then the useful work is technical, not legislative — a self-hosted privacy stack addresses the risks you actually face. Legal right-to-run was never the binding constraint; hardware cost and maintenance time are.

And a note on the campaign itself: calling your legislator is a legitimate lever, but do it over a specific bill you have read, not a call script from an unattributed website. Unsigned advocacy that borrows your credibility is asking for trust it has not earned — the same standard this site applies to unsigned benchmarks.

FAQ

Does SB 942 require me to label images I generate with a local Stable Diffusion or Flux install?

No. SB 942’s disclosure and detection-tool obligations fall on covered providers — publicly accessible generative AI systems with more than one million monthly users in California. A locally run open-weight model has no covered provider standing behind your instance, and you as an individual are not one. Platforms where you post the images may impose their own AI-labeling policies by terms of service.

Do I owe anything under the EU AI Act if I run Ollama at home in Europe?

No. The AI Act excludes natural persons using AI in a purely personal, non-professional activity. The general-purpose AI obligations that took effect August 2, 2025 apply to providers who place models on the EU market — not to individuals downloading and running them. Using the same model inside a business makes you a deployer, with duties that depend on the use case’s risk classification.

Could open-weight releases actually stop because of these laws?

It is the right thing to worry about, but the 2025–2026 evidence says no so far: Meta, Alibaba, DeepSeek, and Z.ai all released open or open-weight models after the EU’s GPAI obligations took effect, and the Act’s open-source exemption removes most provider duties for genuinely free, non-monetized releases. The 2027 compliance deadline for pre-August-2025 models is the next real test. Archiving the weights you rely on costs one evening and removes your exposure either way.

Sources

Was this article helpful?

What self-hosting actually costs

Real cost breakdowns for self-hosted AI: hardware floors, power, maintenance hours, and the honest comparison against paying for it. No spam, unsubscribe anytime.