The top tier is some practices which are completely prohibited, a tier below this is high-risk AI systems, which is the heart of the act, and which gets the most attention in terms of what obligations high risk AI systems would have to follow. If a downstream deployer builds on top of a generative AI foundation model, general privacy AI as you want to call it, they might not have access to the source data or the model. We really don't want to have downstream developers building on top of an open source model that was exempt because there's a push from some quarters that have exemptions for open source models in the AI Act.